fix(deps): remediate OSV findings - #76
Conversation
|
Warning Review limit reached
Next review available in: 40 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Post-merge verification complete for squash commit
CodeRabbit's hosted and CLI retries exhausted their quotas without reviewing this head; neither rate-limit status is counted as review evidence. The independent lockfile review and repository security/verification gates were clean. |
Summary
brace-expansion,fast-uri,hono,ip-address, andundiciWhy
New advisory data made the default branch fail the repository's complete-lockfile OSV gate, including on documentation-only PRs. Existing Renovate PRs each leave part of the current baseline unresolved.
Four fixed versions remain within their parent ranges. Miniflare pins
undici@7.28.0exactly, so the rootundici@7.29.0override is the one intentional range bypass; full Wrangler, build, and browser verification passed against it.This PR supersedes the
brace-expansionupdate in #73. It does not replace the broader lock maintenance in #53 or the independent@hono/node-serverupdate in #72.Validation
pnpm install --frozen-lockfilepnpm-lock.yaml:No issues foundpnpm verifypnpm why brace-expansion fast-uri hono ip-address undici: one fixed version of eachgit diff --checkIndependent lockfile and override review completed clean. Both the CodeRabbit CLI retry and hosted incremental lane exhausted their quotas without reviewing this head; neither rate-limit status is counted as review evidence.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.