Dependabot flagged two open alerts on main in pnpm-lock.yaml (surfaced during #10 development):
Severity
Package
Vulnerable
Patched
Issue
HIGH
form-data
>=4.0.0 <4.0.6
4.0.6
CRLF injection via unescaped multipart field names/filenames
MEDIUM
uuid
<11.1.1
11.1.1
Missing buffer bounds check in v3/v5/v6 when buf provided
Both are transitive dev-tooling deps (pulled in by wrangler / @usebruno/cli), NOT shipped in the Go/Wasm Worker, so runtime exposure is low — but they are real alerts and cheap to fix.
Scope
Force patched versions via pnpm overrides in package.json ("pnpm": { "overrides": { "form-data": ">=4.0.6", "uuid": ">=11.1.1" } }) or pnpm update, then regenerate pnpm-lock.yaml.
Verify pnpm install exits 0 and the resolved versions are patched.
Confirm the Bruno suite (pnpm run test:api) and wrangler still work.
Acceptance criteria
Both Dependabot alerts resolve (patched versions in the lockfile); pnpm install clean; Bruno + wrangler unaffected.
## Context
Dependabot flagged two open alerts on `main` in `pnpm-lock.yaml` (surfaced during #10 development):
| Severity | Package | Vulnerable | Patched | Issue |
|---|---|---|---|---|
| **HIGH** | `form-data` | `>=4.0.0 <4.0.6` | `4.0.6` | CRLF injection via unescaped multipart field names/filenames |
| MEDIUM | `uuid` | `<11.1.1` | `11.1.1` | Missing buffer bounds check in v3/v5/v6 when `buf` provided |
Both are **transitive dev-tooling deps** (pulled in by `wrangler` / `@usebruno/cli`), NOT shipped in the Go/Wasm Worker, so runtime exposure is low — but they are real alerts and cheap to fix.
## Scope
- [ ] Force patched versions via **pnpm overrides** in `package.json` (`"pnpm": { "overrides": { "form-data": ">=4.0.6", "uuid": ">=11.1.1" } }`) or `pnpm update`, then regenerate `pnpm-lock.yaml`.
- [ ] Verify `pnpm install` exits 0 and the resolved versions are patched.
- [ ] Confirm the Bruno suite (`pnpm run test:api`) and `wrangler` still work.
## Acceptance criteria
- Both Dependabot alerts resolve (patched versions in the lockfile); `pnpm install` clean; Bruno + wrangler unaffected.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
Dependabot flagged two open alerts on
maininpnpm-lock.yaml(surfaced during #10 development):form-data>=4.0.0 <4.0.64.0.6uuid<11.1.111.1.1bufprovidedBoth are transitive dev-tooling deps (pulled in by
wrangler/@usebruno/cli), NOT shipped in the Go/Wasm Worker, so runtime exposure is low — but they are real alerts and cheap to fix.Scope
package.json("pnpm": { "overrides": { "form-data": ">=4.0.6", "uuid": ">=11.1.1" } }) orpnpm update, then regeneratepnpm-lock.yaml.pnpm installexits 0 and the resolved versions are patched.pnpm run test:api) andwranglerstill work.Acceptance criteria
pnpm installclean; Bruno + wrangler unaffected.