Skip to content

fix: window formofy assigning#103

Merged
TamHuynhTee merged 1 commit into
mainfrom
fix/window-formofy
Jul 15, 2025
Merged

fix: window formofy assigning#103
TamHuynhTee merged 1 commit into
mainfrom
fix/window-formofy

Conversation

@TamHuynhTee
Copy link
Copy Markdown
Contributor

No description provided.

@TamHuynhTee TamHuynhTee merged commit f329157 into main Jul 15, 2025
3 checks passed
@TamHuynhTee TamHuynhTee deleted the fix/window-formofy branch July 15, 2025 08:52
@github-actions
Copy link
Copy Markdown

🎉 This PR is included in version 1.19.2 🎉

yosriady added a commit that referenced this pull request May 16, 2026
Dependabot could not auto-fix these (transitive dev deps with no
parent release bumping them), so pin via pnpm overrides — same
pattern already used for picomatch/diff/hono:

- serialize-javascript >=7.0.5 (was 6.0.2 via mocha): fixes RCE via
  RegExp.flags/Date.toISOString (#75) and CPU-exhaustion DoS (#103)
- fast-uri >=3.1.2 (was 3.1.0 via webpack/ts-loader): fixes path
  traversal (#104) and host confusion (#105)

Dev/build-only — not shipped in @formo/analytics. Full mocha suite
passes (594/594) with the serialize-javascript 6->7 major bump.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
yosriady added a commit that referenced this pull request May 16, 2026
* Fix min release age units

* Upgrade to pnpm 11

* chore: gitignore .claude/, drop invalid minReleaseAge key

- Ignore .claude/ (local Claude Code settings + worktrees) so the
  nested repo copies are never committed.
- Remove minReleaseAge: 2 from pnpm-workspace.yaml — not a valid pnpm
  key (silently ignored, leftover from old .npmrc). The active
  supply-chain cooldown remains minimumReleaseAge: 2880 (48h).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* security: override serialize-javascript & fast-uri to patched versions

Dependabot could not auto-fix these (transitive dev deps with no
parent release bumping them), so pin via pnpm overrides — same
pattern already used for picomatch/diff/hono:

- serialize-javascript >=7.0.5 (was 6.0.2 via mocha): fixes RCE via
  RegExp.flags/Date.toISOString (#75) and CPU-exhaustion DoS (#103)
- fast-uri >=3.1.2 (was 3.1.0 via webpack/ts-loader): fixes path
  traversal (#104) and host confusion (#105)

Dev/build-only — not shipped in @formo/analytics. Full mocha suite
passes (594/594) with the serialize-javascript 6->7 major bump.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant