Skip to content

fix: remediate high-severity Dependabot security alerts#47

Merged
antoniomtz merged 1 commit intomainfrom
antoniomtz/fix-high-severity-dependabot-alerts-2
Apr 2, 2026
Merged

fix: remediate high-severity Dependabot security alerts#47
antoniomtz merged 1 commit intomainfrom
antoniomtz/fix-high-severity-dependabot-alerts-2

Conversation

@antoniomtz
Copy link
Copy Markdown
Collaborator

@antoniomtz antoniomtz commented Apr 2, 2026

Summary

Test plan

  • pnpm install succeeds with updated overrides
  • pnpm run build passes
  • Verify Dependabot alerts are resolved after merge

🤖 Generated with Claude Code

Add pnpm overrides for picomatch (>=4.0.4), flatted (>=3.4.2),
minimatch (>=3.1.3), and update tar (>=7.5.11) to resolve 6 open
high-severity vulnerabilities including ReDoS, prototype pollution,
and path traversal issues.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@antoniomtz antoniomtz self-assigned this Apr 2, 2026
@antoniomtz antoniomtz merged commit a41054b into main Apr 2, 2026
4 of 5 checks passed
@antoniomtz antoniomtz deleted the antoniomtz/fix-high-severity-dependabot-alerts-2 branch April 2, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant