Repository navigation
fix(deps): resolve critical and high security vulnerabilities - #37
Conversation
…m overrides - basic-ftp >=5.2.0 (CVE-2026-27699, CRITICAL) - rollup >=4.59.0 (CVE-2026-27606, HIGH) - minimatch >=10.2.3 (CVE-2026-26996, CVE-2026-27903, HIGH) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThis pull request updates package.json pnpm overrides to resolve critical and high severity vulnerabilities (CVE-2026-27699, CVE-2026-27606, CVE-2026-26996, CVE-2026-27903) affecting basic-ftp, rollup, and minimatch. A corresponding changelog entry documents the security fix. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Possibly related PRs
Suggested labels
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs). Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
@connectum/auth
@connectum/cli
@connectum/core
@connectum/healthcheck
@connectum/interceptors
@connectum/otel
@connectum/reflection
commit: |
Summary
basic-ftp>=5.2.0 for CVE-2026-27699 (CRITICAL)rollup>=4.59.0 for CVE-2026-27606 (HIGH)minimatch>=10.2.3 for CVE-2026-26996, CVE-2026-27903 (HIGH)All vulnerabilities are transitive — direct dependency updates don't resolve them. pnpm overrides force the patched versions.
Test plan
pnpm install— lockfile updatedpnpm build— 10/10 tasks successfulpnpm typecheck— no errorspnpm test— pre-existing flaky tests only (unrelated to overrides)🤖 Generated with Claude Code
Summary by CodeRabbit