Skip to content

fix(deps): lift source-map-js to 1.2.2 for the audit gate - #69

Merged
rcsarv merged 1 commit into
mainfrom
fix/dependency-audit
Oct 6, 2026
Merged

rcsarv merged 1 commit into
mainfrom
fix/dependency-audit

Conversation

@rcsarv

@rcsarv rcsarv commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Fixes the Dependency vulnerability scan that has failed on main since 6 Oct (the #65 merge), and on every open PR since then.

Cause: CVE-2026-93749 (high), an event-loop denial of service in source-map-js >= 1.0.0 < 1.2.2. The lockfile held 1.2.1 in two places. 1.2.2 is the patched release (published 30 Sep), and a pnpm.overrides entry moves both paths to it. That's the same approach 61d9bec used for the previous batch.

Not changed, because they're moderate and below the --audit-level=high gate:

The two high advisories already on ignoreCves (http-cache-semantics, braces) are unchanged.

Verification

  • pnpm audit --audit-level=high exits 0. Before this change it exited 1.
  • TURBO_FORCE=true pnpm test passes, pnpm type-check passes, and the site's Vite build passes, which exercises source maps through postcss.

After merging: the open Dependabot PRs need a rebase to pick this up. Dependabot rebases its own. #63 and #68 carry my commits, so Dependabot won't rebase them; I'll merge main into those two.

🤖 Generated with Claude Code

CVE-2026-93749 (high, event-loop denial of service) affects source-map-js
>=1.0.0 <1.2.2; the lockfile held 1.2.1 in two places, so `pnpm audit
--audit-level=high` failed CI on main and on every open PR from 6 Oct.
1.2.2 is the patched release; an override moves both paths to it, the way
61d9bec handled the previous batch.

The other new advisories are moderate and below the gate: sprintf-js has
no patched release, and postcss-selector-parser <7.1.6 is moved for the
site by Dependabot's #61.
@rcsarv
rcsarv merged commit eb11572 into main Oct 6, 2026
7 checks passed
@rcsarv
rcsarv deleted the fix/dependency-audit branch October 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant