fix: bump picomatch to resolve high severity audit#73
Conversation
npm audit fix: picomatch 4.0.x → patched version. Fixes GHSA-c2c7-rcm5-vvqj (ReDoS) and GHSA-3v7f-55p6-f55p (method injection). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
To use Codex here, create a Codex account and connect to github. |
Summary
npm audit fixnpm audit --audit-level=highstep for all open PRs (fix: address PR #68 review — silent failures, path traversal, dead code #69, fix: harden litigation AI pipeline — QC false-clear, empty response, source tracing #70)Test plan
npm audit --audit-level=highpasses with 0 vulnerabilities🤖 Generated with Claude Code