fix(security): update dependencies to address several vulnerabilities - #6263
Conversation
✅ Deploy Preview for ohif-dev ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe workspace configuration adds a GHSA ignore entry and updates version overrides for ChangesWorkspace dependency updates
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This updates workspace dependency overrides to patched versions and adds an audit ignore entry. No current merge-blocking production, security, or compatibility risk is evidenced. Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Context
extract-zip allows arbitrary file writes through symlink archive entries
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
SVGO: removeScripts allows executable links through namespace and control-character bypasses
Changes & Results
Patch the various packages using overrides.
Testing
All automated checks and tests must pass.
Checklist
PR
semantic-release format and guidelines.
Code
etc.)
Public Documentation Updates
additions or removals.
Summary by CodeRabbit
Security
Maintenance