Skip to content

Clear the two advisories blocking every PR in this repo - #194

Merged
AdamXweb merged 1 commit into
mainfrom
fix/audit-nanoid-dompurify
Aug 11, 2026
Merged

Clear the two advisories blocking every PR in this repo#194
AdamXweb merged 1 commit into
mainfrom
fix/audit-nanoid-dompurify

Conversation

@adamXbot

Copy link
Copy Markdown
Collaborator

pnpm audit --prod fails on main, so CI's Audit production dependency tree step blocks every open pull request regardless of what it changes — #192 and #193 are both sitting on it right now.

Package Advisory Fix
dompurify 3.4.12 GHSA-mmhx-hgw6-5g2q (moderate) direct bump to 3.4.13
nanoid 3.3.16 GHSA-2v37-7h3g-55p8 (high) override to ^3.3.17, resolves 3.3.18

#193 alone does not fix this. It bumps dompurify, but nanoid still fails the audit, so that PR stays blocked too. This PR does both — #193 can be closed as superseded, or merged first and this rebased.

nanoid arrives via next > postcss > nanoid, and the existing postcss: ^8.5.18 override does not lift it: postcss 8.5.18 still declares nanoid ^3.3.6, which resolves to 3.3.16. So it needs its own entry, following the pattern already established for postcss, @babel/core and sharp.

The override goes in pnpm-workspace.yaml, not package.json — per the note in that file, declaring them in both causes ERR_PNPM_LOCKFILE_CONFIG_MISMATCH in CI.

Verified locally with pnpm 11.18.0 (the pinned version): pnpm audit --prod reports No known vulnerabilities.

🤖 Generated with Claude Code

pnpm audit --prod fails on main, so the Audit production dependency tree step
in CI blocks every open pull request regardless of what it changes.

dompurify is a direct dependency and moves 3.4.12 -> 3.4.13 for
GHSA-mmhx-hgw6-5g2q.

nanoid arrives via next > postcss > nanoid and the existing postcss override
does not lift it — postcss 8.5.18 still declares nanoid ^3.3.6, which resolves
to 3.3.16. GHSA-2v37-7h3g-55p8 is fixed in 3.3.17, so it needs its own
override; it now resolves to 3.3.18. Drop the override once postcss's own
range moves.

The override goes in pnpm-workspace.yaml rather than package.json, per the
note in that file: declaring overrides in both causes
ERR_PNPM_LOCKFILE_CONFIG_MISMATCH in CI.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@adamXbot
adamXbot requested a review from AdamXweb as a code owner August 10, 2026 16:31
@AdamXweb
AdamXweb merged commit e4d99e7 into main Aug 11, 2026
16 checks passed
@AdamXweb
AdamXweb deleted the fix/audit-nanoid-dompurify branch August 11, 2026 02:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants