Skip to content

chore(deps): pin joi to ^18.2.8 via overrides (#13085) - #13302

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:pr/13085-joi-override
Sep 15, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:pr/13085-joi-override

Conversation

@KooshaPari

Copy link
Copy Markdown
Contributor

Summary

Fixes #13085

Adds joi: ^18.2.8 to the overrides block in package.json, bumping the transitive dep from 18.2.3 to 18.2.8 to close the upstream security advisories.

Why overrides (not a direct dep)

joi is a transitive dependency in this repo — it appears in package-lock.json (resolved through sub-deps) but no file in src/, open-sse/, or bin/ imports it directly. Adding a direct dependencies entry would be wrong (it would imply the package is used directly here, generating noise in dep-check tooling and the published-tarball surface).

Per the overrides-pin pattern established by Diego in #12592 (browserslist), #13148 (hono), and #13117 (csv-parse), transitive bumps ship as overrides entries rather than direct dependencies. npm install resolves the override chain and pulls joi@18.2.8 for every sub-dep that requests joi.

Diff

   "overrides": {
     "browserslist": "^4.28.8",
+    "joi": "^18.2.8",
     "onnxruntime-node": "1.24.3",
     ...
   }

Inserted alphabetically after browserslist. No other sort changes — every other key retains its original order to keep the diff minimal and reviewable.

Verification

  • npm view joi@18.2.8 returns successfully — the version exists on the registry
  • overrides is the documented npm mechanism for pinning transitive deps without changing direct deps
  • Single-line addition, no schema/permission impact

Fixes #13085

joi is a transitive dep in this repo (resolved through sub-deps but
not imported directly in src/, open-sse/, or bin/). Per the
overrides-pin pattern used for hono (diegosouzapw#13148), csv-parse (diegosouzapw#13117),
and browserslist (diegosouzapw#12592), the correct fix here is an overrides
entry rather than adding a direct dependency declaration.

18.2.3 → 18.2.8 closes the upstream security advisories. With the
override, npm install resolves joi@18.2.8 wherever it is fetched
through the sub-dep chain.

Single-line overrides addition (inserted alphabetically after
browserslist, no other sort changes). No schema/permission impact.

Fixes diegosouzapw#13085
Copilot AI lite review requested due to automatic review settings September 11, 2026 00:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Pins `csv-parse` to `^7.0.2` via `overrides` (Dependabot #13117). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot #13148). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
@diegosouzapw
diegosouzapw merged commit 93a398f into diegosouzapw:release/v3.8.51 Sep 15, 2026
8 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
… (diegosouzapw#13300)

Pins `csv-parse` to `^7.0.2` via `overrides` (Dependabot diegosouzapw#13117). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13301)

Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot diegosouzapw#13148). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13302)

Pins `joi` to `^18.2.8` via `overrides` (Dependabot diegosouzapw#13085). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants