Skip to content

chore(deps): patch dependabot security alerts 305 and 306 - #3082

Draft
shvenkat-rh wants to merge 1 commit into
mainfrom
fix/dependabot-security-alerts
Draft

chore(deps): patch dependabot security alerts 305 and 306#3082
shvenkat-rh wants to merge 1 commit into
mainfrom
fix/dependabot-security-alerts

Conversation

@shvenkat-rh

Copy link
Copy Markdown
Contributor

Add pnpm overrides to fix 18 vulnerabilities in transitive dependencies:

  • undici: cross-user disclosure, CRLF injection, cookie injection
  • fast-uri: host confusion via backslash
  • ip-address: SSRF bypass via leading-zero octets and CIDR suffix
  • brace-expansion: DoS via unbounded intermediate arrays
  • hono: ReDoS in CORS middleware
  • file-type: ASF parser infinite loop, ZIP decompression bomb
  • diff: DoS in parsePatch/applyPatch

related: #305, #306

@github-actions github-actions Bot added the chore label Aug 4, 2026
@shvenkat-rh
shvenkat-rh force-pushed the fix/dependabot-security-alerts branch 3 times, most recently from 1f8b525 to 5351b84 Compare August 10, 2026 09:29
Add pnpm overrides to fix 18 vulnerabilities in transitive dependencies:
- undici: cross-user disclosure, CRLF injection, cookie injection
- fast-uri: host confusion via backslash
- ip-address: SSRF bypass via leading-zero octets and CIDR suffix
- brace-expansion: DoS via unbounded intermediate arrays
- hono: ReDoS in CORS middleware
- file-type: ASF parser infinite loop, ZIP decompression bomb
- diff: DoS in parsePatch/applyPatch

related: #305, #306
Co-authored-by: Cursor <cursoragent@cursor.com>
@shvenkat-rh
shvenkat-rh force-pushed the fix/dependabot-security-alerts branch from 5351b84 to 62f5a6c Compare August 12, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant