fix(deps): patch transitive toolchain advisories - #8
Merged
Merged
Conversation
osv-scanner reported 22 advisories in the dev and example lockfiles (15 high). They sit in Storybook, Vitest, tsup, and the non-TS demo, not in the published package. Rollup and Vite still matter: the findings cover build-time file writes and the dev server. Root parents already accepted the patched releases, but the lockfile had kept older copies. pnpm.overrides forces those copies without moving Storybook or Vitest onto Vite 8: - vite 7.2.2 -> 7.3.6 - rollup 4.53.2 (tsup) -> 4.63.5 - @babel/core 7.28.5 -> 7.29.7 (stay on 7; react-docgen accepts ^7.28.0) - browserslist 4.28.0 -> 4.29.1 - picomatch ^4.0.3 -> 4.0.7 - brace-expansion ^5.0.5 -> 5.0.12 The picomatch and brace-expansion selectors match only the vulnerable ranges, so other majors stay put. examples/react-non-ts-demo had vite 8.0.11, which pulled postcss 8.5.14 and nanoid 3.3.11. vite ^8.3.1 requires postcss ^8.5.28, which requires nanoid ^3.3.18. The lockfile resolves vite 8.3.1, postcss 8.5.28, and nanoid 3.3.19. pnpm-workspace.yaml excludes vite@8.3.1 from the minimum release-age check, the same exception vanilla-demo already uses. osv-scanner scan -r . is clean. pnpm run build succeeds. Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pnpm.overrides, staying inside the ranges those parents already allow. Storybook and Vitest stay on Vite 7 (7.2.2→7.3.6) rather than moving to Vite 8. Also: Rollup4.53.2→4.63.5,@babel/core7.28.5→7.29.7(Babel 8 is out of range for react-docgen),browserslist4.28.0→4.29.1,picomatch@^4.0.3→4.0.7, andbrace-expansion@^5.0.5→5.0.12. The picomatch and brace-expansion selectors match only those ranges.examples/react-non-ts-demofromvite@^8.0.11to^8.3.1. That release requirespostcss@^8.5.28, which requiresnanoid@^3.3.18, so the demo lockfile now resolves Vite8.3.1, PostCSS8.5.28, and nanoid3.3.19.pnpm-workspace.yamlexcludesvite@8.3.1from the minimum release-age check, the same exceptionexamples/vanilla-demoalready uses.Test plan
osv-scanner scan -r .reports no issuespnpm run buildsucceeds with the updated Rolluppnpm storybookstill starts on Vite 7.3.6pnpm test-storybookpassespnpm --dir examples/react-non-ts-demo devstarts on Vite 8.3.1Made with Cursor