Skip to content

fix: resolve pnpm audit vulnerabilities#257

Merged
brendanjryan merged 1 commit intomainfrom
fix/audit-overrides
Mar 27, 2026
Merged

fix: resolve pnpm audit vulnerabilities#257
brendanjryan merged 1 commit intomainfrom
fix/audit-overrides

Conversation

@brendanjryan
Copy link
Copy Markdown
Collaborator

Adds pnpm overrides to patch transitive dependency vulnerabilities:

  • path-to-regexp >= 8.4.0 — fixes ReDoS via sequential optional groups (via express > router)
  • tar >= 7.5.11 — fixes multiple path traversal / symlink poisoning issues (via prool)

pnpm audit now passes clean.

@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 27, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedmppx@​0.4.118010010098100
Updatedvite@​8.0.2 ⏵ 8.0.394 +110082 +199100

View full report

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new bot commented Mar 27, 2026

Open in StackBlitz

npm i https://pkg.pr.new/mppx@257

commit: 8944619

chain,
transport: http(rpcUrl),
})
}) as import('viem').Client<import('viem').HttpTransport, typeof chain, (typeof accounts)[0]>
Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this type is too big to serialize in this test, so we narrow

@brendanjryan brendanjryan merged commit 052a999 into main Mar 27, 2026
7 checks passed
@brendanjryan brendanjryan deleted the fix/audit-overrides branch March 27, 2026 23:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant