Skip to content

chore: vulnerabilities 2026-05-12 part 2#8044

Merged
n1ru4l merged 2 commits into
mainfrom
chore-vulnerabilities-2026-05-12-part-2
May 13, 2026
Merged

chore: vulnerabilities 2026-05-12 part 2#8044
n1ru4l merged 2 commits into
mainfrom
chore-vulnerabilities-2026-05-12-part-2

Conversation

@n1ru4l
Copy link
Copy Markdown
Contributor

@n1ru4l n1ru4l commented May 12, 2026

Background

New thing dropped

image

Description

protobufjs@8.x.x

needs to be manually overridden cuz @opentelemetry/otlp-transformer is pinning the exact version... See https://www.npmjs.com/package/@opentelemetry/otlp-transformer?activeTab=code

image

@github-actions
Copy link
Copy Markdown
Contributor

🚀 Snapshot Release (alpha)

The latest changes of this PR are available as alpha on npm (based on the declared changesets):

Package Version Info
hive 11.1.1-alpha-20260512161015-ba9d97ead7a13881fc3acaa3f21ee22b68876cbc npm ↗︎ unpkg ↗︎

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request addresses several security vulnerabilities by adding a changeset for the 'hive' scope and introducing a version override for protobufjs@8.x.x in package.json. Feedback suggests documenting this override at the top of the pnpm object to maintain consistency with existing security documentation patterns in the file.

Comment thread package.json
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 12, 2026

🐋 This PR was built and pushed to the following Docker images:

Targets: build

Platforms: linux/amd64

Image Tag: ba9d97ead7a13881fc3acaa3f21ee22b68876cbc

@n1ru4l n1ru4l marked this pull request as ready for review May 13, 2026 06:49
@n1ru4l n1ru4l merged commit ce4d445 into main May 13, 2026
22 of 23 checks passed
@n1ru4l n1ru4l deleted the chore-vulnerabilities-2026-05-12-part-2 branch May 13, 2026 06:50
This was referenced May 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants