Skip to content

fix(security): patch pnpm and transitive Vite - #28

Closed
anandpant wants to merge 1 commit into
mainfrom
fix/dependency-security-2026-10-07
Closed

anandpant wants to merge 1 commit into
mainfrom
fix/dependency-security-2026-10-07

Conversation

@anandpant

Copy link
Copy Markdown

Summary

  • Upgrade pnpm 11.2.2 to the patched same-major version 11.11.0.
  • Add a Vite 8.x override to 8.3.3, covering the transitive development-server dependency; regenerate pnpm-lock.yaml.
  • Add only the exact vite@8.3.3 release-age exception for this security fix; retain the existing two-day release-age policy.

pnpm advisories: GHSA-c59q-g84q-2gj5, GHSA-vx52-2968-3vc6.

Vite advisories: GHSA-rq7h-c2jc-7f22, GHSA-9jrq-w75r-8gcw, GHSA-vfpm-58rq-9qcg.

Validation

  • Passed: targeted pnpm lockfile regeneration with lifecycle scripts disabled.
  • Passed: pnpm install --lockfile-only --frozen-lockfile --offline --ignore-scripts, including repository supply-chain policies.
  • Passed: parsed-lock Vite version scan and git diff --check.
  • Not run locally: full application tests, lint, typecheck and builds. This cloud checkout contains dependency/tooling files rather than all app sources and installed dependencies. Repository CI remains the complete verification gate.

Draft for review; no merge or manual deployment.

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nyrra-emulate-web Ready Ready Preview Oct 7, 2026 5:23am UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 0ff648aa Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant