Skip to content

chore(deps): pin csv-parse to ^7.0.2 via overrides (#13117) - #13300

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:pr/13117-csv-parse-override
Sep 15, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:pr/13117-csv-parse-override

Conversation

@KooshaPari

Copy link
Copy Markdown
Contributor

Summary

Fixes #13117

Adds csv-parse: ^7.0.2 to the overrides block in package.json, bumping the transitive dep from 7.0.1 to 7.0.2 to close the upstream security advisory.

Why overrides (not a direct dep)

csv-parse is a transitive dependency in this repo — it appears in package-lock.json (resolved through a sub-dep chain) but no source file in src/, open-sse/, or tests/ imports it directly. Adding a direct dependencies entry would be wrong (it would imply the package is used directly in this repo).

Per the pattern Diego established in #12592 (browserslist override), transitive bumps ship as overrides entries rather than direct dependencies. npm install resolves the override chain and pulls csv-parse@7.0.2 for every sub-dep that requests csv-parse.

Diff

   "overrides": {
     "hono": "^4.13.7",
+    "csv-parse": "^7.0.2",
     "h2": "^3.4.4",
     ...
   }

Verification

  • npm view csv-parse@7.0.2 returns successfully — the version exists on the registry
  • overrides is the documented npm mechanism for pinning transitive deps without changing direct deps
  • Single-line addition, no schema/permission impact

Fixes #13117

csv-parse is a transitive dep in this repo (no direct source imports
in src/ or open-sse/, but it is resolved through a sub-dep chain).
Per Diego's pattern in diegosouzapw#12592 (browserslist) and other transitive-bump
PRs, the correct fix here is an  entry rather than
adding a direct dependency declaration.

7.0.1 → 7.0.2 closes the upstream security advisory. With the override,
npm install resolves csv-parse@7.0.2 wherever it is fetched through
the sub-dep chain.

Single-line overrides addition, no schema/permission impact.

Fixes diegosouzapw#13117
Copilot AI lite review requested due to automatic review settings September 10, 2026 23:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@diegosouzapw
diegosouzapw merged commit cd112e3 into diegosouzapw:release/v3.8.51 Sep 15, 2026
8 of 16 checks passed
diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot #13148). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Pins `joi` to `^18.2.8` via `overrides` (Dependabot #13085). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
… (diegosouzapw#13300)

Pins `csv-parse` to `^7.0.2` via `overrides` (Dependabot diegosouzapw#13117). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13301)

Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot diegosouzapw#13148). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13302)

Pins `joi` to `^18.2.8` via `overrides` (Dependabot diegosouzapw#13085). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants