Skip to content

fix(security): Various security patches; new GitHub release workflow; update to pnpm 12.8.1; release 3.13.11 - #6325

Merged
jbocce merged 3 commits into
release/3.13from
fix/OHIF-2751-security-3.13
Sep 30, 2026
Merged

jbocce merged 3 commits into
release/3.13from
fix/OHIF-2751-security-3.13

Conversation

@jbocce

@jbocce jbocce commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

jbocce and others added 3 commits September 30, 2026 13:24
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* chore(deps): update pnpm to 12.8.1 and i18next to 19.9.2

- Pin packageManager to pnpm@12.8.1 and raise engines.pnpm to >=12 in
  the root, .netlify and the CLI templates.
- Install pnpm 12 in CircleCI and in the Dockerfile.
- Update pnpm/action-setup to v6.1.0, the first release that supports
  pnpm v12.
- Raise i18next from 17.3.1 to 19.9.2. react-i18next 12 has an
  i18next >=19 peer. pnpm 12 otherwise installs i18next 26 for the
  extensions that do not list i18next. An override holds all packages
  on 19.9.2.
- The lockfile change makes the CircleCI security audit run. Raise the
  overrides for brace-expansion, fast-uri and joi, and ignore
  GHSA-hrh2-vp3x-79xf for decompress, which has no fixed version.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps): move the i18next override next to the React 19 pins

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.

Tip: disable this comment in your organization's Code Review settings.

@jbocce
jbocce deployed to fork-pr-approval September 30, 2026 18:03 — with GitHub Actions Active
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 00ff6b4c-68b4-4df6-961d-882c4b1066e8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jbocce
jbocce requested a review from wayfarer3130 September 30, 2026 18:21
@jbocce
jbocce merged commit 09a892c into release/3.13 Sep 30, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
fork-pr-approval — 6f66d58e Deployed Sep 30, 2026 by jbocce via playwright-tests (24.15.0) #5136
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants