fix(deps): override smol-toml to ^1.8.0 to resolve GHSA-7w5x-hrqm-74c2 - #3301
Conversation
Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
@coderabbitai review |
|
✅ Action performedReview finished.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🔇 Additional comments (1)
📝 WalkthroughWalkthroughThe documentation package configuration adds a Merge Risk: ⚪ Minimal · up to The documentation dependency is upgraded to smol-toml 1.8.0 to address the reported vulnerability, with no remaining merge-blocking risk identified. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
"smol-toml": "^1.8.0"to theoverridesfield indocs/package.json.docs/package-lock.json, updatingsmol-tomlfrom 1.6.1 to 1.8.0 without touching any other package.Audit - Docs Dependenciesworkflow to fail onmain.Verification
npm audit --omit=dev --prefix docsreturns 0 vulnerabilities (was exit 1 with 1 high severity vulnerability).docs/scripts/audit-dependencies.shpasses (exit 0).docs/scripts/audit-dependencies.test.shpasses (exit 0).git diff --checkpasses cleanly.