Skip to content

Conversation

@jamie-albert
Copy link
Member

Summary

Fixes GHSA-5j98-mcp5-4vw2 and GHSA-mh29-5h37-fv8m in renovate by adding pnpm overrides for glob and js-yaml.

Changes

Verification

  • Build succeeds: make package/renovate
  • Scan confirms CVEs resolved: wolfictl scan packages/*/*/renovate-*.apk

References

… glob and js-yaml

- Incremented epoch to 1
- Added pnpm overrides for glob 10.5.0 and js-yaml 4.1.1
- Fixes GHSA-5j98-mcp5-4vw2 (glob vulnerability)
- Fixes GHSA-mh29-5h37-fv8m (js-yaml vulnerability)
@octo-sts octo-sts bot added bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. labels Nov 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant