Repository navigation
fix(deps): lift source-map-js to 1.2.2 for the audit gate - #69
Merged
Merged
Conversation
CVE-2026-93749 (high, event-loop denial of service) affects source-map-js >=1.0.0 <1.2.2; the lockfile held 1.2.1 in two places, so `pnpm audit --audit-level=high` failed CI on main and on every open PR from 6 Oct. 1.2.2 is the patched release; an override moves both paths to it, the way 61d9bec handled the previous batch. The other new advisories are moderate and below the gate: sprintf-js has no patched release, and postcss-selector-parser <7.1.6 is moved for the site by Dependabot's #61.
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the Dependency vulnerability scan that has failed on
mainsince 6 Oct (the #65 merge), and on every open PR since then.Cause: CVE-2026-93749 (high), an event-loop denial of service in
source-map-js>= 1.0.0 < 1.2.2. The lockfile held 1.2.1 in two places. 1.2.2 is the patched release (published 30 Sep), and apnpm.overridesentry moves both paths to it. That's the same approach 61d9bec used for the previous batch.Not changed, because they're moderate and below the
--audit-level=highgate:sprintf-js(CVE-2026-97058): no patched release exists.postcss-selector-parser< 7.1.6 (CVE-2026-104844): Dependabot's chore(deps-dev): bump postcss-selector-parser from 6.1.4 to 7.1.6 #61 moves the site's direct dependency.The two high advisories already on
ignoreCves(http-cache-semantics, braces) are unchanged.Verification
pnpm audit --audit-level=highexits 0. Before this change it exited 1.TURBO_FORCE=true pnpm testpasses,pnpm type-checkpasses, and the site's Vite build passes, which exercises source maps through postcss.After merging: the open Dependabot PRs need a rebase to pick this up. Dependabot rebases its own. #63 and #68 carry my commits, so Dependabot won't rebase them; I'll merge
maininto those two.🤖 Generated with Claude Code