Bump astro 7.2.4 → 7.2.10 (critical, website build) and retarget the pinned
pnpm overrides for the transitive alerts: js-yaml → 4.3.2 (the one runtime
path, via electron-updater), smol-toml → 1.7.1 (new key for nx's exact 1.6.1
pin), svgo → 4.1.0 (new key for astro's 4.0.2 resolution) and hono → 4.13.5.
Every target stays inside its parent's declared range except nx's exact
smol-toml pin, which is now recorded as the deliberate exception in
docs/architecture/dependency-security-overrides.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Closes 13 runtime-scope Dependabot advisories that Dependabot cannot fix itself:
every vulnerable package here is transitive, so the bot has no lever until each
parent publishes a release widening its own pin.
Overrides added (pinned-source form, matching existing convention):
- @xmldom/xmldom 0.8.11 -> 0.8.13 (5 high) via video.js -> mpd-parser
- fast-uri 3.1.0 -> 3.1.4 (4 high) via electron-conf -> ajv
- js-yaml 4.1.1 -> 4.3.0 (2) via electron-updater
- form-data 4.0.5 -> 4.0.6 (1 high) via axios
- ajv 8.17.1 -> 8.18.0 (1) via electron-conf
Every target stays inside its parent's declared semver range. For xmldom,
fast-uri and js-yaml the newest published version is outside that range
(0.9.x / 4.x / 5.x), so "latest" would have broken them; the new doc
records that constraint.
Deliberately excluded: axios and uuid are direct deps already covered by open
Dependabot PRs (#1251, #1252). undici is labelled runtime scope but every path
to it is build tooling (electron -> @electron/get, @angular/build,
@module-federation/dts-plugin) and it is not in the packaged app.
Reachability: xmldom arrives via video.js -> VHS -> mpd-parser, but the app
routes every .mpd to Shaka, which uses its own DASH parser, so that one is
defence in depth. The genuinely reachable one is js-yaml, which
electron-updater uses to parse latest.yml from releases.
Adds docs/architecture/dependency-security-overrides.md and a .changes note.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>