Skip to content

chore: fix package.json indentation and add pnpm security overrides#163

Merged
sdserranog merged 5 commits intomainfrom
sdserranog/update-package-json
Apr 21, 2026
Merged

chore: fix package.json indentation and add pnpm security overrides#163
sdserranog merged 5 commits intomainfrom
sdserranog/update-package-json

Conversation

@sdserranog
Copy link
Copy Markdown
Contributor

@sdserranog sdserranog commented Apr 21, 2026

Summary

  • Add pnpm overrides for known vulnerable dependency version ranges (diff, minimatch, ajv, flatted, handlebars, brace-expansion, picomatch)

sdserranog and others added 5 commits April 21, 2026 09:06
Normalize package.json indentation from tabs to spaces and add pnpm
overrides for known vulnerable dependency version ranges.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The broad >=6.14.0 override was resolving ajv to v8, breaking @eslint/eslintrc
which requires the v6 API.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Unbound overrides (e.g. >=2.0.3) were resolving to new major versions
with breaking API changes, crashing ESLint (ajv v6→v8) and publint
(brace-expansion v2→v5 ESM-only). Constrain each override to its
current major version range.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@sdserranog sdserranog requested a review from nbarbettini April 21, 2026 12:15
@sdserranog sdserranog merged commit a3afb66 into main Apr 21, 2026
7 checks passed
@sdserranog sdserranog deleted the sdserranog/update-package-json branch April 21, 2026 13:40
@stainless-app stainless-app Bot mentioned this pull request Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants