diff --git a/.changes/deps-transitive-cve-overrides.md b/.changes/deps-transitive-cve-overrides.md new file mode 100644 index 000000000..8be3e46d5 --- /dev/null +++ b/.changes/deps-transitive-cve-overrides.md @@ -0,0 +1,8 @@ +--- +type: internal +area: deps +--- + +Patched five vulnerable transitive dependencies that ship with the app — +including the YAML parser `electron-updater` uses to read update manifests, and +the HTTP form encoder behind portal requests. No behaviour change. diff --git a/docs/architecture/dependency-security-overrides.md b/docs/architecture/dependency-security-overrides.md index b86331f12..be525ed63 100644 --- a/docs/architecture/dependency-security-overrides.md +++ b/docs/architecture/dependency-security-overrides.md @@ -45,10 +45,18 @@ npm view @ dependencies --json ## Verifying an override actually applied -pnpm leaves the superseded package block in `pnpm-lock.yaml` even when nothing -resolves to it any more, so grepping for the old version is misleading — it will -still be there. Check the _dependents_ instead, or resolve the real path on -disk: +Grepping `pnpm-lock.yaml` for the old version still finds it, but that hit is +not a leftover package block — pnpm removes those once nothing resolves to them. +It is the override's own selector key, echoed in the `overrides:` block at the +top of the lockfile: + +```yaml +overrides: + '@xmldom/xmldom@0.8.11': 0.8.13 +``` + +So a bare grep proves only that the override is declared, never that it took +effect. Resolve the real path on disk instead: ```bash node -e "console.log(require('./node_modules/.pnpm/mpd-parser@1.3.1/node_modules/@xmldom/xmldom/package.json').version)"