-
Notifications
You must be signed in to change notification settings - Fork 419
renovate/42.82.3 package update #78217
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
octo-sts
wants to merge
4
commits into
main
Choose a base branch
from
staging-update-bot/renovate.yaml
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
+6
−2
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
4fe0e6c to
157581c
Compare
b3c4e24 to
14cd5b2
Compare
a86fc1e to
fcf6d71
Compare
0cf0b54 to
a4010c1
Compare
Add pnpm overrides to fix CVE scan failures: - diff 8.0.3 fixes GHSA-73rr-hh4g-fpgx - undici 7.18.2 fixes CVE-2026-22036 These overrides force the vulnerable transitive dependencies to use patched versions. <!--staging-autofix:turn: 1-->
Add diff package version 8.0.3 as a direct dependency in addition to the pnpm override to ensure the CVE fix (GHSA-73rr-hh4g-fpgx) is applied to all instances of the package including nested dependencies within npm. <!--staging-autofix:turn: 2-->
Add specific pnpm override for npm>diff to ensure the diff package within npm's dependency tree is updated to 8.0.3. This fixes CVE GHSA-73rr-hh4g-fpgx which was found in diff 8.0.2 as a transitive dependency of npm@11.6.4. <!--staging-autofix:turn: 3-->
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
approver-bot/manual-review-needed
automated pr
bincapz/pass
bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages.
manual/review-needed
P1
This label indicates our scanning found High, Medium or Low CVEs for these packages.
renovate
request-version-update
request for a newer version of a package
staging-approver-bot/manual-review-needed
staging-autofix
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Commit: 6397b19f77ece24fa5e65cb40b74b8c14c6ad239