Patch brace-expansion vulnerability - #291
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
💤 Files with no reviewable changes (1)
📝 WalkthroughWalkthroughThis PR removes the pnpm enforcement preinstall hook and updates the brace-expansion dependency override constraint in the workspace configuration. The preinstall script that prevented non-pnpm package managers from being used is deleted, and the brace-expansion version override is adjusted to target ChangesPackage Manager Configuration
Possibly related PRs
Suggested reviewers
Poem
🎯 1 (Trivial) | ⏱️ ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
brace-expansion@>=5.0.0 <5.0.6so vulnerable5.0.5resolves to patched5.0.6.pnpm-lock.yamlfor the patched transitive dependency path.npx only-allowpreinstall guard now that pnpm enforcement is handled through package manager metadata.Validation
pnpm audit --audit-level moderate- no known vulnerabilities foundpnpm run lint- passed with existing warningspnpm build- passed with existing warningspnpm run lint:check- passed with existing warningspnpm run test:unit- passed, 191 suites / 2482 testscoderabbit review --agent --base develop- 0 findingsFull
pnpm run testwas not run locally because this worktree has no.envand noALCHEMY_API_KEY;shell/test_all.shsources.envbefore running fork tests.Summary by CodeRabbit
brace-expansion.