From 4045d97d171055a9bf71cefa87e927f70cf09375 Mon Sep 17 00:00:00 2001 From: FJ-Riveros Date: Fri, 14 Aug 2026 15:29:39 +0400 Subject: [PATCH] fix(deps): widen uuid 11.x override for CVE-2026-41907 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Replace uuid@11.1.0 pin with uuid@>=11.0.0 <11.1.1 → 11.1.1. Residual uuid@8 major bump remains deferred. --- pnpm-lock.yaml | 14 +++----------- pnpm-workspace.yaml | 2 +- 2 files changed, 4 insertions(+), 12 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index fc704dd..c8eeac2 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -12,7 +12,7 @@ overrides: axios@1.14.1: '>=1.18.0' axios@0.30.4: 0.30.3 ip-address@<=10.1.0: 10.1.1 - uuid@11.1.0: 11.1.1 + uuid@>=11.0.0 <11.1.1: 11.1.1 ws@>=7.0.0 <7.5.11: 7.5.11 ws@>=8.0.0 <8.21.0: 8.21.0 plain-crypto-js@4.2.1: 0.0.0-security @@ -1288,10 +1288,6 @@ packages: resolution: {integrity: sha512-z0yWI+4FDrrweS8Zmt4Ej5HdJmky15+L2e6Wgn3+iK5fWzb6T3fhNFq2+MeTRb064c6Wr4N/wv0DzQTjNzHNGQ==} engines: {node: '>=10'} - minimatch@10.2.4: - resolution: {integrity: sha512-oRjTw/97aTBN0RHbYCdtF1MQfvusSIBQM0IZEgzl6426+8jSC0nF1a/GmnVLpfB9yyr6g6FTqWqiZVbxrtaCIg==} - engines: {node: 18 || 20 || >=22} - minimatch@10.2.6: resolution: {integrity: sha512-vpLQEs+VLCr1nU0BXS07maYoFwlDAH0gngQuuttxIwutDFEMHq2blX+8vpgxDdK3J1PwjCJiep77OitTZ4Ll1A==} engines: {node: 18 || 20 || >=22} @@ -3230,7 +3226,7 @@ snapshots: fs.realpath: 1.0.0 inflight: 1.0.6 inherits: 2.0.4 - minimatch: 10.2.4 + minimatch: 10.2.6 once: 1.4.0 path-is-absolute: 1.0.1 @@ -3532,10 +3528,6 @@ snapshots: mimic-response@3.1.0: {} - minimatch@10.2.4: - dependencies: - brace-expansion: 5.0.9 - minimatch@10.2.6: dependencies: brace-expansion: 5.0.9 @@ -3894,7 +3886,7 @@ snapshots: dependencies: '@istanbuljs/schema': 0.1.3 glob: 7.2.3 - minimatch: 10.2.4 + minimatch: 10.2.6 text-encoding-utf-8@1.0.2: {} diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 935c118..fcfdd0d 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -46,7 +46,7 @@ overrides: # CVE-2026-13149: no patched 3.x/4.x exists — advisory remediates >=3.0.0 via 5.x "ip-address@<=10.1.0": "10.1.1" - "uuid@11.1.0": "11.1.1" + "uuid@>=11.0.0 <11.1.1": "11.1.1" "ws@>=7.0.0 <7.5.11": "7.5.11" "ws@>=8.0.0 <8.21.0": "8.21.0" "plain-crypto-js@4.2.1": "0.0.0-security"