Files
LibreMail-Bug-Report-Ingest/pnpm-workspace.yaml
T
JMR-devandClaude Opus 4.8 52ce6e9aca #36 Security: patch vulnerable transitive deps form-data + uuid
Force patched versions of two vulnerable transitive dev-tooling deps
flagged by Dependabot. Both are dev-only (pulled in transitively by
wrangler / @usebruno/cli) and are not part of the Go/Wasm Worker:

- form-data 4.0.4 -> 4.0.6  (HIGH, CRLF injection; vuln >=4.0.0 <4.0.6)
- uuid      10.0.0 -> 14.0.1 (MEDIUM, buffer bounds; vuln <11.1.1)

The pnpm overrides live in pnpm-workspace.yaml (the `overrides:` key)
rather than package.json's `pnpm.overrides` because pnpm 11 no longer
reads the "pnpm" field in package.json (it warns and ignores it). This
sits alongside the existing allowBuilds config in the same file. The
lockfile was regenerated so form-data resolves to a single 4.0.6 and
uuid to 14.0.1 (the >=11.1.1 override resolves to the latest published
uuid, which is well above the vulnerable <11.1.1 range).

Verified locally:
- pnpm install and pnpm install --frozen-lockfile exit 0
- pnpm run test:api (Bruno suite) passes 8/8 against go devserver
- pnpm exec wrangler --version -> 4.106.0

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 15:42:41 -05:00

23 lines
1.1 KiB
YAML

# Approve build (postinstall) scripts for dev-tooling deps.
# esbuild/sharp/workerd are first-party Cloudflare / well-known packages required
# by `wrangler dev`/`deploy`; protobufjs is a transitive dependency of
# `@usebruno/cli` (the API-test runner). None are needed for `go test` or the dev
# server. Without approving protobufjs, pnpm 11 exits non-zero on the ignored
# build script, which would break CI's `pnpm install` and `pnpm exec`/`pnpm run`.
allowBuilds:
esbuild: true
protobufjs: true
sharp: true
workerd: true
# Force patched versions of vulnerable transitive dev-tooling deps (see #36).
# form-data <4.0.6 has a HIGH CRLF-injection advisory; uuid <11.1.1 has a MEDIUM
# buffer-bounds advisory. Both are pulled in transitively by wrangler /
# @usebruno/cli and are dev-only (not in the Go/Wasm Worker). pnpm 11 no longer
# reads the "pnpm" field in package.json, so overrides live here alongside the
# build-approval config. Values are quoted because a leading ">" is a YAML
# block-scalar indicator.
overrides:
form-data: '>=4.0.6'
uuid: '>=11.1.1'