Conversation
`package.json` is untouched. This is a pure re-resolution of transitive dependencies within the ranges already declared, done by deleting `pnpm-lock.yaml` and reinstalling. It clears every open alert on the repository: 1 critical, 23 high, 27 moderate, 5 low. All 56 were npm and all were transitive — not one was a direct dependency. The count is inflated by per-CVE alerts on the same package: `hono` alone accounted for 13 and `undici` for 11. Notable moves: seroval 1.5.1 -> 1.6.7, undici 7.24.7 -> 7.29.1, hono 4.12.23 -> 4.13.7, fast-uri 3.1.2 -> 3.1.7, js-yaml 4.1.1 -> 4.3.2, nanoid 3.3.11 -> 3.3.19, ip-address 10.2.0 -> 10.7.0. **None of these reached anyone.** The Rust workspace has no alerts at all, and of the 18 affected packages only two sat anywhere in the production dependency graph: `@tailwindcss/vite` (build-time; its code is not shipped) and `@tanstack/react-router`, which pulls `seroval` — the one critical. That advisory needs `fromJSON()` to deserialize untrusted input with plugins enabled, which is a server-side SSR path. This console is a plain SPA, and seroval does not appear in the built bundle at all: the sourcemaps name every `@tanstack/router-core` module that made it in and contain no seroval module. It is tree-shaken away. Worth fixing anyway. 56 standing alerts are where a real one goes to hide. Verified with the same steps CI runs: `pnpm install --frozen-lockfile`, `pnpm check:i18n` (1386 keys), `pnpm test` (96 tests), `pnpm build`. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A pure re-resolution of transitive dependencies within the ranges already declared —
pnpm-lock.yamldeleted and reinstalled.package.jsonis untouched, so no declared range moved.It clears every open alert on the repository: 1 critical, 23 high, 27 moderate, 5 low.
Nothing here reached anyone
The Rust workspace has no alerts at all. All 56 were npm and all were transitive — not one was a direct dependency. The count is inflated by per-CVE alerts on the same package:
honoalone accounted for 13,undicifor 11.Of the 18 affected packages, only two sat anywhere in the production dependency graph:
@tailwindcss/vite→ postcss / nanoid / vite. Build-time; that code is not shipped.@tanstack/react-router→seroval, the one critical (GHSA-mv8w-475r-vwqw, CVSS 9.8).That advisory needs
fromJSON()to deserialize untrusted input with plugins enabled, which is a server-side SSR path. This console is a plain SPA (createRouter+RouterProvider, no Start, norenderToString), and seroval does not appear in the built bundle at all — the sourcemaps name every@tanstack/router-coremodule that made it in and contain no seroval module. It is tree-shaken away.Everything else came through dev and build tooling:
shadcn→@modelcontextprotocol/sdk(~28 alerts on its own),vitest/jsdom(~15), and the vite/postcss/eslint/babel toolchain.Fixing it anyway, because 56 standing alerts are where a real one goes to hide.
Notable version moves
seroval 1.5.1 → 1.6.7 · undici 7.24.7 → 7.29.1 · hono 4.12.23 → 4.13.7 · fast-uri 3.1.2 → 3.1.7 · js-yaml 4.1.1 → 4.3.2 · nanoid 3.3.11 → 3.3.19 · ip-address 10.2.0 → 10.7.0
Verification
The same four steps the Frontend Build job runs:
pnpm install --frozen-lockfile,pnpm check:i18n(1386 keys),pnpm test(96 tests),pnpm build.🤖 Generated with Claude Code