#36 Security: patch form-data + uuid (Dependabot) #37

Merged
JMR-dev merged 1 commits from ticket-36-deps-security into main 2026-07-02 20:44:59 +00:00
JMR-dev commented 2026-07-02 20:41:25 +00:00 (Migrated from github.com)

Summary

Patches the two open Dependabot alerts on main by forcing patched versions of vulnerable transitive dev-tooling dependencies. Both are pulled in via wrangler / @usebruno/cli and are not part of the Go/Wasm Worker.

Before → After

Package Advisory Vulnerable range Patched floor Before After
form-data HIGH — CRLF injection >=4.0.0 <4.0.6 4.0.6 4.0.4 4.0.6
uuid MEDIUM — buffer bounds <11.1.1 11.1.1 10.0.0 14.0.1

Note on uuid: the override is >=11.1.1 (the advisory's patched floor). pnpm resolves that to the latest published uuid — 14.0.1 — which is well above the vulnerable <11.1.1 range. That is a 3-major jump from the previous 10.0.0, but uuid is a dev-only transitive dep and the Bruno suite (its only consumer) passes on it. Happy to cap it (e.g. >=11.1.1 <12) if you'd rather stay on the 11.x line.

Implementation note

The pnpm overrides are added to pnpm-workspace.yaml (its overrides: key), not package.json's pnpm.overrides, because pnpm 11 no longer reads the pnpm field in package.json — it emits [WARN] The "pnpm" field in package.json is no longer read by pnpm ... ignored: "pnpm.overrides" and the lockfile does not change. The overrides therefore sit alongside the existing allowBuilds build-approval config in the same file. pnpm-lock.yaml was regenerated accordingly (the vulnerable form-data@4.0.4 collapses to a single 4.0.6; uuid@10.0.0 → 14.0.1).

Files touched: pnpm-workspace.yaml, pnpm-lock.yaml.

Verification

  • pnpm install → exit 0
  • pnpm install --frozen-lockfile → exit 0 (lockfile self-consistent; CI parity — CI runs pnpm install --frozen-lockfile with pnpm 10, which also reads pnpm-workspace.yaml)
  • pnpm why form-data → single form-data@4.0.6
  • pnpm why uuid → single uuid@14.0.1
  • pnpm run test:api (Bruno suite, run against go run ./cmd/devserver) → 5/5 requests, 8/8 tests pass
  • pnpm exec wrangler --version → 4.106.0

Closes #36

🤖 Generated with Claude Code

## Summary Patches the two open Dependabot alerts on `main` by forcing patched versions of vulnerable **transitive dev-tooling** dependencies. Both are pulled in via `wrangler` / `@usebruno/cli` and are **not** part of the Go/Wasm Worker. ## Before → After | Package | Advisory | Vulnerable range | Patched floor | Before | After | | --- | --- | --- | --- | --- | --- | | `form-data` | **HIGH** — CRLF injection | `>=4.0.0 <4.0.6` | `4.0.6` | `4.0.4` | **`4.0.6`** | | `uuid` | **MEDIUM** — buffer bounds | `<11.1.1` | `11.1.1` | `10.0.0` | **`14.0.1`** | > Note on `uuid`: the override is `>=11.1.1` (the advisory's patched floor). pnpm resolves that to the latest published `uuid` — `14.0.1` — which is well above the vulnerable `<11.1.1` range. That is a 3-major jump from the previous `10.0.0`, but `uuid` is a dev-only transitive dep and the Bruno suite (its only consumer) passes on it. Happy to cap it (e.g. `>=11.1.1 <12`) if you'd rather stay on the 11.x line. ## Implementation note The pnpm `overrides` are added to **`pnpm-workspace.yaml`** (its `overrides:` key), not `package.json`'s `pnpm.overrides`, because **pnpm 11 no longer reads the `pnpm` field in `package.json`** — it emits `[WARN] The "pnpm" field in package.json is no longer read by pnpm ... ignored: "pnpm.overrides"` and the lockfile does not change. The overrides therefore sit alongside the existing `allowBuilds` build-approval config in the same file. `pnpm-lock.yaml` was regenerated accordingly (the vulnerable `form-data@4.0.4` collapses to a single `4.0.6`; `uuid@10.0.0` → `14.0.1`). Files touched: `pnpm-workspace.yaml`, `pnpm-lock.yaml`. ## Verification - `pnpm install` → exit 0 - `pnpm install --frozen-lockfile` → exit 0 (lockfile self-consistent; CI parity — CI runs `pnpm install --frozen-lockfile` with pnpm 10, which also reads `pnpm-workspace.yaml`) - `pnpm why form-data` → single `form-data@4.0.6` - `pnpm why uuid` → single `uuid@14.0.1` - `pnpm run test:api` (Bruno suite, run against `go run ./cmd/devserver`) → **5/5 requests, 8/8 tests pass** - `pnpm exec wrangler --version` → `4.106.0` Closes #36 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.