chore(deps): close transitive CVE alerts via pnpm overrides (#1527)

Four open Dependabot alerts, all on transitive npm dependencies, so no
direct dependency changes:

- browserslist 4.28.1 -> 4.28.8 (GHSA-73wf-gq98-2v4g, high)
- @xmldom/xmldom 0.8.13 -> 0.8.15 (GHSA-6gmq-8vp8-gcm6)
- @humanfs/node 0.16.7 -> 0.16.8 (GHSA-p498-v437-472g)
- postcss-selector-parser 6.1.2 -> 6.1.4 (GHSA-w9m9-85wc-3x92)

@xmldom/xmldom already had an override, but its pinned target 0.8.13 had
itself fallen into the widened advisory range (<= 0.8.14), so that entry
is bumped rather than added.

browserslist is pinned to 4.28.8 rather than the advisory's 4.28.7 because
4.28.8 was already resolved elsewhere in the tree; collapsing onto it takes
browserslist from three copies to one and drops the duplicate
caniuse-lite/electron-to-chromium/update-browserslist-db trees with it, so
the lockfile is a net reduction. postcss-selector-parser 6.0.10 is left
alone: it sits below the advisory's >= 6.1.0 lower bound.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Opus 5 authored and GitHub committed 2026-09-04 19:59:51 +02:00
1 parent d8d36476e6
commit 302afb237a
3 files changed
+50 -103

No files matched your search

+4 -1
View File
@@ -241,10 +241,12 @@
"overrides": {
"@esbuild-kit/core-utils>esbuild": "0.25.12",
"@hono/node-server@1.19.9": "1.19.17",
"@xmldom/xmldom@0.8.11": "0.8.13",
"@humanfs/node@0.16.7": "0.16.8",
"@xmldom/xmldom@0.8.11": "0.8.15",
"ajv@6.12.6": "6.14.0",
"ajv@8.17.1": "8.18.0",
"brace-expansion@1.1.12": "1.1.18",
"browserslist@4.28.1": "4.28.8",
"defu@6.1.4": "6.1.6",
"devalue@5.6.2": "5.6.4",
"express-rate-limit@8.2.1": "8.3.0",
@@ -265,6 +267,7 @@
"path-to-regexp@0.1.12": "0.1.13",
"picomatch@2.3.1": "2.3.2",
"picomatch@4.0.3": "4.0.5",
"postcss-selector-parser@6.1.2": "6.1.4",
"postcss@8.5.6": "8.5.26",
"qs@6.14.1": "6.15.3",
"rollup@4.52.3": "4.59.0",