fix(security): patch Cuabot dependencies - #2718
Conversation
📦 Publishable packages changedThis comment is status-only. Editing it or adding task-list checkboxes cannot authorize a release.
Ask the release owner to apply |
b35b069 to
d332f3c
Compare
📦 Publishable packages changedThis comment is status-only. Editing it or adding task-list checkboxes cannot authorize a release.
Ask the release owner to apply |
📦 Publishable packages changedThis comment is status-only. Editing it or adding task-list checkboxes cannot authorize a release.
Ask the release owner to apply |
|
This dependency graph is now included in draft #2719. That draft keeps each graph independently validated while giving reviewers one dependency-only change instead of several overlapping drafts. Nothing was merged or marked ready, and this branch is preserved. |
What users see
Cuabot's lockfile can still install several vulnerable JavaScript packages. These alerts share one Cuabot override and lockfile, so they belong in one review.
What changed
tar7.5.21 andbrace-expansion5.0.8 fixes.fast-urito 3.1.5,honoto 4.12.34, andip-addressto 10.3.1.Definition of Done
Validation
pnpm@10.11.0 install --lockfile-only --ignore-scriptsgit diff --checkImpact
This changes only Cuabot's dependency overrides and lockfile. Human review should focus on the Node 20 requirement and the existing direct Dependabot overlap.