Skip to content

fix: resolve 9 audit vulnerabilities via pnpm overrides#112

Merged
viviveevee merged 1 commit intodfinity:mainfrom
q-uint:fix/audit-vulnerabilities
Feb 18, 2026
Merged

fix: resolve 9 audit vulnerabilities via pnpm overrides#112
viviveevee merged 1 commit intodfinity:mainfrom
q-uint:fix/audit-vulnerabilities

Conversation

@q-uint
Copy link
Copy Markdown
Contributor

@q-uint q-uint commented Feb 18, 2026

Resolves all 9 vulnerabilities reported by pnpm audit by adding
pnpm overrides for transitive dependencies that haven't been updated
by their direct parent packages.

High severity (5)

Moderate severity (4)

  • lodash — prototype pollution in _.unset/_.omit
    via @tanstack/vite-config > vite-plugin-dts > @microsoft/api-extractor > lodash
  • markdown-it — ReDoS via docs > typedoc > markdown-it
  • ajv (2 paths) — ReDoS with $data option
    via @tanstack/vite-config > vite-plugin-dts > @microsoft/api-extractor

Override transitive dependency versions to patch known
vulnerabilities in tar, axios, lodash, markdown-it, and ajv.
@q-uint q-uint requested a review from a team as a code owner February 18, 2026 11:10
@viviveevee viviveevee merged commit c7bc48a into dfinity:main Feb 18, 2026
11 checks passed
@viviveevee
Copy link
Copy Markdown
Contributor

Thanks a lot!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants