Repository navigation
fix(website): pin brace-expansion and fast-uri past new advisories - #2019
Conversation
Security's docs-site audit went red on main after four advisories landed in the site's dev-only serve dependency chain. Raise the site's existing overrides so they resolve patched versions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deploying openspec-docs with
|
| Latest commit: |
a650a58
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://cd408e04.openspec-docs.pages.dev |
| Branch Preview URL: | https://fix-website-brace-expansion.openspec-docs.pages.dev |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: Fission-AI/OpenSpec/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe workspace updates the version ranges for the ChangesDependency overrides
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to No concrete merge-blocking risk is established; the website’s reachable dependency paths use the reported fixed versions. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
No PR-relevant drift confirmed.
|
- _change_log: 0011 审计(v1.13.1→v1.14.0,源码核实)+ plan-9 账本收尾 - _digested: workflows×9、spec_cli×6、mechanisms、system、internal-spec-driven、schema、specs_truth、_coverage、README SSOT→v1.14.0 - _faq_on_digested: 06/07/12/16/17/03 实质更新,11 目录核实,基线脚注→SSOT - _openspec_handbook: 11 文件更新(工具速查全量扩容含 dsh),8 章核实未动 - 事实核对:Fission-AI#2019 依赖钉版不在 tag;补漏 Fission-AI#1912 Purpose 占位符判定
Status: LGTM. Fixes the red Security workflow on
main.What was wrong: after v1.14.0 merged, Security's "Audit documentation site" step failed on
main(run 36787938895). Four advisories published today hit the docs site's dev-onlyservetool:The published CLI is not affected: the root package already resolves brace-expansion 5.0.12, and
pnpm auditat the root reports no vulnerabilities.How it was fixed: raised the site's existing pins in
website/pnpm-workspace.yaml(the only place its overrides live) tobrace-expansion@<5.0.12: '>=5.0.12 <6'andfast-uri@<3.1.8: ^3.1.8, then regeneratedwebsite/pnpm-lock.yamlwith pnpm 10.34.5. The root lockfile is untouched, so the Nix flake hash does not change.Proof:
pnpm audit --dir website→ 4 vulnerabilities (2 high, 2 moderate). After: no known vulnerabilities.pnpm install --frozen-lockfileandpnpm buildinwebsite/succeed, andserve outserves the built site (HTTP 200).overrides:block keeps every existing pin (postcss, sharp, nanoid).Notes: docs-site tooling only, so no changeset. This also supersedes the failed Dependabot update job for brace-expansion in
/website.🤖 Generated with Claude Code
Summary by CodeRabbit