Skip to content

fix(deps): resolve the audit gate - #1192

Merged
prisis merged 1 commit into
mainfrom
fix/audit
Oct 6, 2026
Merged

prisis merged 1 commit into
mainfrom
fix/audit

Conversation

@prisis

@prisis prisis commented Oct 6, 2026

Copy link
Copy Markdown
Member

pnpm audit fails the setup step of every workflow.

  • nx 23.1.1 → 23.2.1 in the default catalog
  • override source-map-js <1.2.2 → >=1.2.2, tinypool <2.1.2 → >=2.1.2
  • ignore sprintf-js (no patched release — latest is 1.1.3) and katex (fix is 0.18.2 but micromark-extension-math requires ^0.16.0), both dev-only

Verified: pnpm audit --audit-level=moderate → exit 0; nx 23.2.1; tests pass.

`pnpm audit` fails the setup step of every workflow. Fix what has a patched
release and ignore what does not:

- nx 23.1.1 -> 23.2.1 in the default catalog (GHSA-w3vv-58gj-gw77, GHSA-hrvq-x7jp-36xv)
- override source-map-js to >=1.2.2 (GHSA-68fv-2mgg-jv7q)
- override tinypool to >=2.1.2 (GHSA-5gmw-xhrv-c9v3, GHSA-85c8-ppgw-ccpr)
- ignore sprintf-js (no patched release) and katex (fix is 0.18.2 but
  micromark-extension-math needs ^0.16.0); both dev-only
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednx@​23.1.1 ⏵ 23.2.168 +10100 +1893 +1100100

View full report

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c56bd74a-fbf4-4c1c-ad7c-fed205d77d8c
📥 Commits

Reviewing files that changed from the base of the PR and between d9ce049 and abd33de.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml
 ______________________________________________________________________________________________________________________________________________________
< Why do you need code reviews? dB/dt = ∇ × Bv: The proliferation rate of bugs (dB/dt) equals the curl of the bug vector field (Bv). It's simple math. >
 ------------------------------------------------------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@prisis
prisis merged commit 3222190 into main Oct 6, 2026
24 of 25 checks passed
@prisis
prisis deleted the fix/audit branch October 6, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant