fix: resolve vulnerable transitive dependencies - #298
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 34 minutes. View limit detailsLimit details: You’ve used all 2 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe workspace configuration adds version-range overrides for six dependencies. The PR workflow adds the ChangesDependency Version Overrides
PR Test Output
Priority: ⬆️ High Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The dependency overrides select the intended patched versions, and the PR workflow retains streamed test output. No material change-specific merge risk is evident; the change is ready after normal checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
View your CI Pipeline Execution ↗ for commit edcc844
☁️ Nx Cloud last updated this comment at |
commit: |
Use modern Yarn configuration instead of Classic-only install flags and isolate registry metadata per fixture. Preserve Classic behavior and print CI task output directly in GitHub Actions.
Limit the exemption to @test-intent/*@1.0.0 in generated fixture configuration. Keep hardened mode and the release-age policy for real dependencies enabled.
7d0e9fc to
c407b1e
Compare
Summary
Address all 15 open Dependabot alerts with overrides limited to vulnerable version ranges. Parent packages pin some affected versions, so a normal transitive update does not resolve every alert.
Regenerate the lockfile with pnpm 11.9.0. Keep package manifests, unaffected resolutions, release-age limits, and supply-chain safeguards unchanged. Already safe versions remain unchanged.
Validation
pnpm audit: 23 advisories before; no known vulnerabilities after.pnpm install --frozen-lockfile --registry=https://registry.npmjs.org/: passed.NX_NO_CLOUD=true NX_DAEMON=false NX_SKIP_NX_CACHE=true pnpm test: all eight tasks passed, including types, lint, docs, unit tests, integration tests, and build.pnpm exec prettier --check pnpm-workspace.yaml pnpm-lock.yaml: passed.git diff --check: passed.These are local validation results. Dependabot alerts remain open until the fix reaches the default branch and GitHub processes it.
CI failure and root-cause fix
The integration fixture installer assumed Yarn Classic, while CI runs Yarn 4.18.1. Classic-only flags caused YN0050 failures. After correcting the install configuration, Yarn's 24-hour release-age gate rejected the freshly published local fixtures with YN0016. Both failures were reproduced locally before their fixes.
@test-intent/*@1.0.0in generated fixture configuration. Real dependency policies are unchanged.Verification: 60 Classic/npm/pnpm/bun cases passed. With CI Yarn 4.18.1 and hardened mode enabled, 57 cases passed; three existing Classic-only PnP cases were skipped. A negative control verified the 1440-minute age gate and hardened mode remain enabled, and a fixture outside the approved version remains quarantined. Lint, typecheck, formatting, and diff checks passed.
GitHub Actions run 36669819694 passed both Test and Preview at
7d0e9fc. The separate benchmark was still pending at verification time.Summary by CodeRabbit