Skip to content

Security: override vulnerable transitive dependencies#33348

Merged
marker-dao merged 2 commits intoDevExpress:26_1from
marker-dao:26_1_security_alerts_tribe_duty_p2
Apr 17, 2026
Merged

Security: override vulnerable transitive dependencies#33348
marker-dao merged 2 commits intoDevExpress:26_1from
marker-dao:26_1_security_alerts_tribe_duty_p2

Conversation

@marker-dao
Copy link
Copy Markdown
Contributor

No description provided.

@marker-dao marker-dao requested review from a team April 17, 2026 14:46
@marker-dao marker-dao self-assigned this Apr 17, 2026
@marker-dao marker-dao marked this pull request as ready for review April 17, 2026 14:46
Copilot AI review requested due to automatic review settings April 17, 2026 14:46
@marker-dao marker-dao added the dependencies Pull requests that update a dependency file label Apr 17, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates pnpm.overrides to force patched versions of transitive dependencies to address known vulnerabilities.

Changes:

  • Adjusts existing overrides (e.g., basic-ftp, qs, hono, dompurify) to newer safe versions/ranges.
  • Adds new overrides for terser, follow-redirects, and @angular/platform-server.

Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
r-farkhutdinov
r-farkhutdinov previously approved these changes Apr 17, 2026
@marker-dao marker-dao removed the request for review from a team April 17, 2026 15:27
@marker-dao marker-dao merged commit 7c1f961 into DevExpress:26_1 Apr 17, 2026
150 of 152 checks passed
@marker-dao marker-dao deleted the 26_1_security_alerts_tribe_duty_p2 branch April 17, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

26_1 dependencies Pull requests that update a dependency file force all tests skip-cache

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants