From c7e46f880b80f5ee0ef3c96c792e6a184ca9bc12 Mon Sep 17 00:00:00 2001 From: 4gray Date: Sat, 25 Jul 2026 19:44:33 +0200 Subject: [PATCH] docs(deps): add release note and correct lockfile verification guidance MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Addresses both Codex review findings: - P1: add the missing `.changes/` entry. Typed `internal` per `.changes/README.md`, which names dependency bumps with behaviour risk as exactly that category. - P2: the doc claimed pnpm leaves superseded package blocks in the lockfile. It does not — it removes them. The old versions survive only as the overrides' own selector keys in the `overrides:` block at the top of `pnpm-lock.yaml`, which is what a naive grep actually hits. The practical advice is unchanged (resolve on disk, do not grep), but the reason it gives is now correct. Co-Authored-By: Claude Opus 5 --- .changes/deps-transitive-cve-overrides.md | 8 ++++++++ .../dependency-security-overrides.md | 16 ++++++++++++---- 2 files changed, 20 insertions(+), 4 deletions(-) create mode 100644 .changes/deps-transitive-cve-overrides.md diff --git a/.changes/deps-transitive-cve-overrides.md b/.changes/deps-transitive-cve-overrides.md new file mode 100644 index 000000000..8be3e46d5 --- /dev/null +++ b/.changes/deps-transitive-cve-overrides.md @@ -0,0 +1,8 @@ +--- +type: internal +area: deps +--- + +Patched five vulnerable transitive dependencies that ship with the app — +including the YAML parser `electron-updater` uses to read update manifests, and +the HTTP form encoder behind portal requests. No behaviour change. diff --git a/docs/architecture/dependency-security-overrides.md b/docs/architecture/dependency-security-overrides.md index b86331f12..be525ed63 100644 --- a/docs/architecture/dependency-security-overrides.md +++ b/docs/architecture/dependency-security-overrides.md @@ -45,10 +45,18 @@ npm view @ dependencies --json ## Verifying an override actually applied -pnpm leaves the superseded package block in `pnpm-lock.yaml` even when nothing -resolves to it any more, so grepping for the old version is misleading — it will -still be there. Check the _dependents_ instead, or resolve the real path on -disk: +Grepping `pnpm-lock.yaml` for the old version still finds it, but that hit is +not a leftover package block — pnpm removes those once nothing resolves to them. +It is the override's own selector key, echoed in the `overrides:` block at the +top of the lockfile: + +```yaml +overrides: + '@xmldom/xmldom@0.8.11': 0.8.13 +``` + +So a bare grep proves only that the override is declared, never that it took +effect. Resolve the real path on disk instead: ```bash node -e "console.log(require('./node_modules/.pnpm/mpd-parser@1.3.1/node_modules/@xmldom/xmldom/package.json').version)"