Skip to content

chore(security): prune redundant managed overrides - #497

Open
enyineer wants to merge 1 commit into
mainfrom
chore/security-maintenance
Open

chore(security): prune redundant managed overrides#497
enyineer wants to merge 1 commit into
mainfrom
chore/security-maintenance

Conversation

@enyineer

Copy link
Copy Markdown
Owner

Automated by the daily Security Maintenance workflow.

Redundant overrides removed

These security overrides are no longer needed — the dependency graph
now resolves at/above their safeFloor without the pin:

  • Pruned 2 redundant override(s): fast-uri, sharp

Current CVE state

Fixable vulnerabilities (a patched version exists): 3

Known unfixed (monitoring only)

@changeset-bot

changeset-bot Bot commented Jul 26, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: bfa9463

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions

Copy link
Copy Markdown
Contributor

❌ PR Checks Failed

Check Status
Typecheck ✅ Passed
Lint ✅ Passed
Deps ✅ Passed
Test ✅ Passed
Integration ✅ Passed
Security (deps) ❌ Failed
Security (container) ✅ Passed
E2E ✅ Passed
❌ Security Audit Failures (dependency graph)
🔎 Security Audit (dependency graph, incl. devDependencies)

❌ Fixable vulnerabilities (2) — an upgrade path exists, so these fail the build:
  [MEDIUM] tar 7.5.20 -> fixed in 7.5.21  (GHSA-r292-9mhp-454m)
  [HIGH] brace-expansion 5.0.7 -> fixed in 5.0.8  (CVE-2026-14257)

⚠️  Known unfixed vulnerabilities (0) — surfaced, not gated:
  (none)

How to fix: This gate scans the whole dependency graph (incl. devDependencies) and fails only on findings with an upgrade path (a fixed version exists); unfixed findings are warnings, not gated. Run bun run audit:security locally to reproduce. Bump the affected direct dependency, or for a transitive package add a documented entry to security/managed-overrides.json plus matching overrides/resolutions in package.json (then bun install). Re-run bun run audit:overrides:check to confirm the override is consistent.

@enyineer The above code quality issues were found in this PR. Please fix them before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant