Force patched versions of two vulnerable transitive dev-tooling deps flagged by Dependabot. Both are dev-only (pulled in transitively by wrangler / @usebruno/cli) and are not part of the Go/Wasm Worker: - form-data 4.0.4 -> 4.0.6 (HIGH, CRLF injection; vuln >=4.0.0 <4.0.6) - uuid 10.0.0 -> 14.0.1 (MEDIUM, buffer bounds; vuln <11.1.1) The pnpm overrides live in pnpm-workspace.yaml (the `overrides:` key) rather than package.json's `pnpm.overrides` because pnpm 11 no longer reads the "pnpm" field in package.json (it warns and ignores it). This sits alongside the existing allowBuilds config in the same file. The lockfile was regenerated so form-data resolves to a single 4.0.6 and uuid to 14.0.1 (the >=11.1.1 override resolves to the latest published uuid, which is well above the vulnerable <11.1.1 range). Verified locally: - pnpm install and pnpm install --frozen-lockfile exit 0 - pnpm run test:api (Bruno suite) passes 8/8 against go devserver - pnpm exec wrangler --version -> 4.106.0 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
23 lines
1.1 KiB
YAML
23 lines
1.1 KiB
YAML
# Approve build (postinstall) scripts for dev-tooling deps.
|
|
# esbuild/sharp/workerd are first-party Cloudflare / well-known packages required
|
|
# by `wrangler dev`/`deploy`; protobufjs is a transitive dependency of
|
|
# `@usebruno/cli` (the API-test runner). None are needed for `go test` or the dev
|
|
# server. Without approving protobufjs, pnpm 11 exits non-zero on the ignored
|
|
# build script, which would break CI's `pnpm install` and `pnpm exec`/`pnpm run`.
|
|
allowBuilds:
|
|
esbuild: true
|
|
protobufjs: true
|
|
sharp: true
|
|
workerd: true
|
|
|
|
# Force patched versions of vulnerable transitive dev-tooling deps (see #36).
|
|
# form-data <4.0.6 has a HIGH CRLF-injection advisory; uuid <11.1.1 has a MEDIUM
|
|
# buffer-bounds advisory. Both are pulled in transitively by wrangler /
|
|
# @usebruno/cli and are dev-only (not in the Go/Wasm Worker). pnpm 11 no longer
|
|
# reads the "pnpm" field in package.json, so overrides live here alongside the
|
|
# build-approval config. Values are quoted because a leading ">" is a YAML
|
|
# block-scalar indicator.
|
|
overrides:
|
|
form-data: '>=4.0.6'
|
|
uuid: '>=11.1.1'
|