fix(deps): resolve 17 dependabot alerts via pnpm overrides - #2556
Merged
Conversation
|
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I39eae84f8621adf8ad6193b6dab5f2196a6a6964
shikanime
force-pushed
the
fix/dependabot-2552
branch
from
August 24, 2026 10:16
e1326bf to
a4d8ced
Compare
3 tasks
shikanime
marked this pull request as ready for review
August 24, 2026 10:52
shikanime
enabled auto-merge
August 24, 2026 10:52
StephaneTrebel
approved these changes
Aug 24, 2026
StephaneTrebel
left a comment
Collaborator
There was a problem hiding this comment.
Je suis certain que ça va nous poser un problème bien relou à un moment donné, mais l'écosystème est tellement claqué au sol que je ne vois pas comment on ne peut pas prendre le risque…
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

2 New Issues
0 Fixed Issues
0 Accepted Issues
Issues liées
Issues numéro: #2552
Quel est le comportement actuel ?
pnpm auditouvre 19 alertes (10 high, 8 moderate, 1 low) surpnpm-lock.yaml, majoritairement transitivity ou issues de catalog.Quel est le nouveau comportement ?
Résolution de 17 des 19 alertes par un unique bloc
overrides(et un bump de catalog) danspnpm-workspace.yaml, selon la convention déjà en place dans le dépôt :protobufjs@8.0.0/8.0.1→>=8.6.6 <9(11 alertes)@opentelemetry/core@2.7.1→>=2.8.0 <3@opentelemetry/propagator-jaeger@2.7.1→>=2.9.0 <3nanoid@3.3.17(transitif postcss) →>=3.3.18 <4deepmerge-ts@7.1.5→>=8.0.2 <9nanoid:5.0.9→5.1.16pnpm auditpasse de 19 → 2 alertes ouvertes. Aucune API exposée modifiée.Cette PR introduit-elle un breaking change ?
Non.
Autres informations
Validation Socle requise (CONTRIBUTING.md §60-70) : toute modification de dépendance Node.js exige l'approbation explicite de l'équipe CPIN (
@cloud-pi-native/socle). Cette PR touchepnpm-workspace.yaml(overrides/catalogs) — approbation requise avant merge.2 alertes non corrigeables (suivies en amont, hors périmètre) :
elliptic(low) : aucune version>=6.6.2publiée sur npm (dernier = 6.6.1, vulnérable).ts-deepmerge(moderate) : correctif>=8.0.0exigé, mais le parent@anatine/zod-openapi@1.14.2contraint^6.0.3(exclut 7/8).Refs #2552