-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
60 lines (57 loc) · 3.95 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
60 lines (57 loc) · 3.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
packages:
- .
# Supply-chain hardening (https://pnpm.io/settings).
# Block transitive dependencies resolved from non-registry sources (git/tarball URLs).
# A legitimate dependency should always come from the registry.
blockExoticSubdeps: true
# Refuse to install any package version published less than 2 days ago, so a freshly
# compromised release is not picked up before the community can flag it. The committed
# lockfile is verified against this on every install.
minimumReleaseAge: 2880
# Both entries below are **floors, not pins**, and the difference is the whole point of writing them
# this way. An exact version here raises the minimum today and freezes the package forever after.
# Nothing can bump past an override, so Dependabot opens no PR, and `scripts/check-js-advisories.js`
# sees only the resolved tree, which has no *open* advisory precisely because the override pinned it.
# A security gate quietly becomes a security ceiling, and the next advisory on the same package is the
# one nobody hears about. A `>=` raises the minimum and lets later patches in, which is what was
# actually wanted both times.
#
# Each carries the condition under which it should be deleted rather than being left to accumulate.
overrides:
# Floors the transitive qs at the release that fixes CVE-2026-8723 (GHSA/GLAD): a remotely
# triggerable DoS where qs.stringify throws a TypeError on null/undefined entries in comma-format
# arrays when encodeValuesOnly is set, affecting >=6.11.1 <6.15.2. Transitive and dev/build-scope
# like fast-uri below (never shipped in the app). The floor clears the open Dependabot alert.
#
# REMOVE WHEN: every dependent's own range already floors qs at 6.15.2 or later: check with
# `pnpm why qs`, and confirm by deleting this line and seeing what `pnpm install` resolves.
qs: ">=6.15.2"
# Floors the transitive fast-uri (pulled by ajv, itself dev/build-only via Stryker) past two
# separate host-confusion advisories, both about an authority delimiter being misread:
# GHSA-v2hh-gcrm-f6hx / CVE-2026-16221, fixed in 3.1.4, and GHSA-7p8r-x3mc-p8w7, fixed in 3.1.5.
# Bounded to the 3.x line ajv declares, so this stays a patch rather than dragging in a major ajv
# has not been tested against. Never shipped in the app (dev scope), but it clears the alert.
#
# The second advisory is the reason the note at the top of this block is not theory. This entry was
# written as `>=3.1.4` rather than a pin precisely so a later patch could still be resolved, and
# that is what happened. A new advisory landed on the same package four months later, and the fix
# was to raise this floor by one patch. A pin at 3.1.4 would have held the tree *at* the newly
# vulnerable version, with the override reading as though the package were handled.
#
# Raising the floor is still a manual step, though: the range permits a later patch but the
# lockfile keeps whatever it resolved, so `pnpm install` has to be re-run for it to move. The
# range is what makes that a one-line change instead of a decision.
#
# It then happened a third time, and this entry is the record of that. Four more advisories
# landed on the same package, all fixed in 3.1.6. GHSA-5jgf-p345-68v8 and GHSA-jqff-g426-hqxp
# are host confusion again, through skipped IDN canonicalization and through percent-encoded
# scheme normalization. GHSA-f65p-4m7j-42xc and GHSA-fph4-wmhf-6fwf are SSRF, through a
# malformed IPv6 literal and through a repeated hostname. The `>=3.1.5` range already permitted
# the fix while the lockfile still sat on 3.1.5, which is the manual step above being exactly as
# manual as it warned.
#
# Three rounds on one package is itself information. If a fourth arrives, the question worth
# asking is whether Stryker's ajv dependency is worth carrying, not whether to raise this again.
#
# REMOVE WHEN: ajv's own range floors fast-uri at 3.1.6 or later.
fast-uri: ">=3.1.6 <4"