Skip to content

deps: patch high-risk npm CVEs in toolchain dependencies#209

Open
benvinegar wants to merge 1 commit intomainfrom
fix/npm-high-risk-cves
Open

deps: patch high-risk npm CVEs in toolchain dependencies#209
benvinegar wants to merge 1 commit intomainfrom
fix/npm-high-risk-cves

Conversation

@benvinegar
Copy link
Copy Markdown
Member

Summary

  • upgrade the pi coding agent and Vitest toolchain to pull in patched transitive dependencies
  • explicitly bump yaml and file-type to clear the remaining moderate advisories
  • reduce npm audit findings from multiple high/critical CVEs to zero

Testing

  • npm audit
  • npm test
  • npm run lint

Notes

  • npm run typecheck currently fails in pi/extensions/sentry-monitor.ts after the dependency upgrade; this PR is scoped to dependency/CVE remediation and leaves that follow-up separate.

This PR description was generated by Pi using GPT-5 Codex

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​mariozechner/​pi-coding-agent@​0.52.12 ⏵ 0.73.071 -1100100 +198100
Updatedvitest@​4.0.18 ⏵ 4.1.59610079 +199100
Updated@​vitest/​coverage-v8@​4.0.18 ⏵ 4.1.59910079 +1199100
Updatedfile-type@​21.3.0 ⏵ 21.3.499100 +3100 +191100
Updatedyaml@​2.8.2 ⏵ 2.8.499 +1100 +210092100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant