Patches the two open Dependabot alerts on main by forcing patched versions of vulnerable transitive dev-tooling dependencies. Both are pulled in via wrangler / @usebruno/cli and are not part of the Go/Wasm Worker.
Before → After
Package
Advisory
Vulnerable range
Patched floor
Before
After
form-data
HIGH — CRLF injection
>=4.0.0 <4.0.6
4.0.6
4.0.4
4.0.6
uuid
MEDIUM — buffer bounds
<11.1.1
11.1.1
10.0.0
14.0.1
Note on uuid: the override is >=11.1.1 (the advisory's patched floor). pnpm resolves that to the latest published uuid — 14.0.1 — which is well above the vulnerable <11.1.1 range. That is a 3-major jump from the previous 10.0.0, but uuid is a dev-only transitive dep and the Bruno suite (its only consumer) passes on it. Happy to cap it (e.g. >=11.1.1 <12) if you'd rather stay on the 11.x line.
Implementation note
The pnpm overrides are added to pnpm-workspace.yaml (its overrides: key), not package.json's pnpm.overrides, because pnpm 11 no longer reads the pnpm field in package.json — it emits [WARN] The "pnpm" field in package.json is no longer read by pnpm ... ignored: "pnpm.overrides" and the lockfile does not change. The overrides therefore sit alongside the existing allowBuilds build-approval config in the same file. pnpm-lock.yaml was regenerated accordingly (the vulnerable form-data@4.0.4 collapses to a single 4.0.6; uuid@10.0.0 → 14.0.1).
pnpm install --frozen-lockfile → exit 0 (lockfile self-consistent; CI parity — CI runs pnpm install --frozen-lockfile with pnpm 10, which also reads pnpm-workspace.yaml)
pnpm why form-data → single form-data@4.0.6
pnpm why uuid → single uuid@14.0.1
pnpm run test:api (Bruno suite, run against go run ./cmd/devserver) → 5/5 requests, 8/8 tests pass
## Summary
Patches the two open Dependabot alerts on `main` by forcing patched versions of vulnerable **transitive dev-tooling** dependencies. Both are pulled in via `wrangler` / `@usebruno/cli` and are **not** part of the Go/Wasm Worker.
## Before → After
| Package | Advisory | Vulnerable range | Patched floor | Before | After |
| --- | --- | --- | --- | --- | --- |
| `form-data` | **HIGH** — CRLF injection | `>=4.0.0 <4.0.6` | `4.0.6` | `4.0.4` | **`4.0.6`** |
| `uuid` | **MEDIUM** — buffer bounds | `<11.1.1` | `11.1.1` | `10.0.0` | **`14.0.1`** |
> Note on `uuid`: the override is `>=11.1.1` (the advisory's patched floor). pnpm resolves that to the latest published `uuid` — `14.0.1` — which is well above the vulnerable `<11.1.1` range. That is a 3-major jump from the previous `10.0.0`, but `uuid` is a dev-only transitive dep and the Bruno suite (its only consumer) passes on it. Happy to cap it (e.g. `>=11.1.1 <12`) if you'd rather stay on the 11.x line.
## Implementation note
The pnpm `overrides` are added to **`pnpm-workspace.yaml`** (its `overrides:` key), not `package.json`'s `pnpm.overrides`, because **pnpm 11 no longer reads the `pnpm` field in `package.json`** — it emits `[WARN] The "pnpm" field in package.json is no longer read by pnpm ... ignored: "pnpm.overrides"` and the lockfile does not change. The overrides therefore sit alongside the existing `allowBuilds` build-approval config in the same file. `pnpm-lock.yaml` was regenerated accordingly (the vulnerable `form-data@4.0.4` collapses to a single `4.0.6`; `uuid@10.0.0` → `14.0.1`).
Files touched: `pnpm-workspace.yaml`, `pnpm-lock.yaml`.
## Verification
- `pnpm install` → exit 0
- `pnpm install --frozen-lockfile` → exit 0 (lockfile self-consistent; CI parity — CI runs `pnpm install --frozen-lockfile` with pnpm 10, which also reads `pnpm-workspace.yaml`)
- `pnpm why form-data` → single `form-data@4.0.6`
- `pnpm why uuid` → single `uuid@14.0.1`
- `pnpm run test:api` (Bruno suite, run against `go run ./cmd/devserver`) → **5/5 requests, 8/8 tests pass**
- `pnpm exec wrangler --version` → `4.106.0`
Closes #36
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Patches the two open Dependabot alerts on
mainby forcing patched versions of vulnerable transitive dev-tooling dependencies. Both are pulled in viawrangler/@usebruno/cliand are not part of the Go/Wasm Worker.Before → After
form-data>=4.0.0 <4.0.64.0.64.0.44.0.6uuid<11.1.111.1.110.0.014.0.1Implementation note
The pnpm
overridesare added topnpm-workspace.yaml(itsoverrides:key), notpackage.json'spnpm.overrides, because pnpm 11 no longer reads thepnpmfield inpackage.json— it emits[WARN] The "pnpm" field in package.json is no longer read by pnpm ... ignored: "pnpm.overrides"and the lockfile does not change. The overrides therefore sit alongside the existingallowBuildsbuild-approval config in the same file.pnpm-lock.yamlwas regenerated accordingly (the vulnerableform-data@4.0.4collapses to a single4.0.6;uuid@10.0.0→14.0.1).Files touched:
pnpm-workspace.yaml,pnpm-lock.yaml.Verification
pnpm install→ exit 0pnpm install --frozen-lockfile→ exit 0 (lockfile self-consistent; CI parity — CI runspnpm install --frozen-lockfilewith pnpm 10, which also readspnpm-workspace.yaml)pnpm why form-data→ singleform-data@4.0.6pnpm why uuid→ singleuuid@14.0.1pnpm run test:api(Bruno suite, run againstgo run ./cmd/devserver) → 5/5 requests, 8/8 tests passpnpm exec wrangler --version→4.106.0Closes #36
🤖 Generated with Claude Code