Skip to content

fix(deps): resolve critical and high security vulnerabilities - #37

Merged
intech merged 1 commit into
mainfrom
fix/security-overrides
Mar 4, 2026
Merged

intech merged 1 commit into
mainfrom
fix/security-overrides

Conversation

@intech

@intech intech commented Mar 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

All vulnerabilities are transitive — direct dependency updates don't resolve them. pnpm overrides force the patched versions.

Test plan

  • pnpm install — lockfile updated
  • pnpm build — 10/10 tasks successful
  • pnpm typecheck — no errors
  • pnpm test — pre-existing flaky tests only (unrelated to overrides)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Resolved critical and high severity security vulnerabilities through dependency updates.

…m overrides

- basic-ftp >=5.2.0 (CVE-2026-27699, CRITICAL)
- rollup >=4.59.0 (CVE-2026-27606, HIGH)
- minimatch >=10.2.3 (CVE-2026-26996, CVE-2026-27903, HIGH)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added the type:bug Bug report: something is not working as documented label Mar 4, 2026
@coderabbitai

coderabbitai Bot commented Mar 4, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 484f32f2-16f0-4ee7-afb4-d86ba0811c9d

📥 Commits

Reviewing files that changed from the base of the PR and between afaee1d and e05ed60.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • .changeset/security-overrides.md
  • package.json

📝 Walkthrough

Walkthrough

This pull request updates package.json pnpm overrides to resolve critical and high severity vulnerabilities (CVE-2026-27699, CVE-2026-27606, CVE-2026-26996, CVE-2026-27903) affecting basic-ftp, rollup, and minimatch. A corresponding changelog entry documents the security fix.

Changes

Cohort / File(s) Summary
Security Changelog Entry
.changeset/security-overrides.md
New changelog documenting resolution of four critical/high severity CVEs via pnpm dependency overrides.
Dependency Overrides
package.json
Updates pnpm.overrides to pin patched versions: minimatch@<10.2.3 → "10.2.3", basic-ftp@<5.2.0 → "5.2.0", rollup@>=4.0.0 <4.59.0 → "4.59.0".

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

Suggested labels

dependencies

Poem

🐰 A hoppy fix for security's sake,
Overrides pinned to patch the break,
CVEs quashed with versions new,
Minimatch, rollup, and ftp too!
Dependencies secured, no more at stake!

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: applying pnpm overrides to resolve critical and high security vulnerabilities in transitive dependencies.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/security-overrides

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-new Bot commented Mar 4, 2026

Copy link
Copy Markdown

Open in StackBlitz

@connectum/auth

npm i https://pkg.pr.new/@connectum/auth@37

@connectum/cli

npm i https://pkg.pr.new/@connectum/cli@37

@connectum/core

npm i https://pkg.pr.new/@connectum/core@37

@connectum/healthcheck

npm i https://pkg.pr.new/@connectum/healthcheck@37

@connectum/interceptors

npm i https://pkg.pr.new/@connectum/interceptors@37

@connectum/otel

npm i https://pkg.pr.new/@connectum/otel@37

@connectum/reflection

npm i https://pkg.pr.new/@connectum/reflection@37

commit: 19fa03f

@intech intech self-assigned this Mar 4, 2026
@intech intech added dependencies Pull requests that update a dependency file priority:high Critical: blocking users or breaking type:chore Maintenance: refactoring, dependencies, CI/CD and removed type:bug Bug report: something is not working as documented labels Mar 4, 2026
@intech
intech merged commit 602f02c into main Mar 4, 2026
9 checks passed
@intech
intech deleted the fix/security-overrides branch March 4, 2026 16:03
@coderabbitai coderabbitai Bot mentioned this pull request May 4, 2026
10 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file priority:high Critical: blocking users or breaking type:chore Maintenance: refactoring, dependencies, CI/CD

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant