Repository navigation
chore(deps-dev): clear the new dev-dependency advisories - #628
Conversation
GHSA-68fv-2mgg-jv7q (high, event-loop denial of service) affects source-map-js < 1.2.2, which postcss and magicast pull in for the dev toolchain. The lockfile now resolves 1.2.2. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
Tree-shaking report✅ No bundle size impact. All 200 exports are the same size as on the base branch (full import 1387.9 KB, gzip 293.3 KB). All exports (200)
How this is measuredEvery export is imported alone into an esbuild consumer bundle (minified, tree-shaken) built from the head and from the base of this pull request; the sizes are the resulting bundles, gzip is their gzipped size. 🔴 marks a regression: a pre-existing export that grew more than 20% and more than 256 B, or the bundle importing every pre-existing export growing more than 5%. 🟡 is growth under the threshold, 🟢 a decrease, ⚪ no change, 🆕 an export that does not exist on the base (never a regression), 🗑️ an export that was removed. An intentional increase is accepted with the |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #628 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 263 263
Lines 2656 2656
Branches 754 754
=========================================
Hits 2656 2656
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
…dvisory in OSV smol-toml 1.9.0 fixes GHSA-r4xh-jqrq-34v2 (knip). GHSA-hp3w-g68c-fv3c has no patched sprintf-js; it only reaches the dev toolchain through @microsoft/api-extractor, so osv-scanner.toml ignores it with the reason, like the extract-zip entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu
…udit-ci check:vex requires every suppressed advisory to have a not_affected statement and to be in every suppression list, so GHSA-hp3w-g68c-fv3c gets its statement and the audit-ci allowlist entry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu
Clears the dependency advisories that fail Check (
audit-ci --high) and the OSV scan on every PR (#626, #627). All of them are dev-only.source-map-js1.2.1 → 1.2.2: GHSA-68fv-2mgg-jv7q (high), via postcss and magicast.smol-toml1.8.0 → 1.9.0: GHSA-r4xh-jqrq-34v2 (medium), via knip.sprintf-js1.0.3: GHSA-hp3w-g68c-fv3c (medium) has no patched release; it only reaches the toolchain through@microsoft/api-extractor(argparse), soosv-scanner.tomlignores it with the reason, like the extract-zip entries.audit-ciandnpm run checkpass locally.🤖 Generated with Claude Code
https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu