Fix undici and brace-expansion audit advisories - #109
Open
Dilusha-Madushan wants to merge 1 commit into
Open
Dilusha-Madushan wants to merge 1 commit into
Dilusha-Madushan wants to merge 1 commit into
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: thunder-id/javascript-sdks/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔀 Cross-SDK feature parity, no ports neededThis pull request is labelled |
Signed-off-by: Dilusha-Madushan <dilushamadushan9912@gmail.com>
Dilusha-Madushan
force-pushed
the
fix/audit-undici-brace-expansion
branch
from
October 2, 2026 07:42
3cfbc85 to
df50a0a
Compare
DonOmalVindula
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
The
pnpm audit --audit-level=highCI step fails onmainwith high-severity findings in four packages:tests/e2eresolved 7.29.0 andnuxtresolved 8.10.0. Patched versions are 7.29.1+ and 8.10.2+.nuxt. Patched in 5.9.3+.nuxt'slisthen. No patched release exists.Approach
tests/e2edepends on it directly, so its range is raised from^7.0.0to^7.30.0.nuxt@4.5.2is already the latest release and declaresundici ^8.10.0, which allows the patched 8.11.2, so a lockfile refresh was enough. No override is added.pnpm-workspace.yamlare raised to the latest patch on each line (1.1.21,2.1.7,5.0.12). The justification comment is updated with the new advisories.5.9.4, with a justification comment. It is transitive vianuxtand@nuxt/nitro-server.auditConfig.ignoreGhsaswith a justification comment. The advisory concerns RSA PKCS#1 v1.5 signature verification, butlisthenonly uses node-forge to generate RSA keys and self-signed certificates for the local HTTPS dev server and never verifies signatures. The entry should be revisited once node-forge publishes a fixed release.pnpm-lock.yaml: regenerated withpnpm installandpnpm update undici -r. The diff only touches the entries for these packages and the snapshot keys that reference them.Related Issues
Related PRs
Checklist
pnpm audit --audit-level=highexits 0 (the remaining high finding is the ignored node-forge entry).pnpm buildpasses, and the nuxt package tests (122) and the nuxt quickstart build pass. Tests pass in every package except@thunderid/vue, which fails in my local environment because of duplicate vue copies. The@thunderid/expresslint errors and the@thunderid/nuxtvue-tsctypecheck failure are identical without this change.breaking changelabel added.parity/prs-raisedorparity/prs-not-neededadded.parity/prs-raised, the port links are posted as a reply on the parity check's comment.Security checks