ff5b0e778b
Adds a pnpm override forcing form-data >=4.0.6 in all five workspaces that resolved the vulnerable transitive form-data@4.0.5 (CVE-2026-12143, GHSA-hmw2-7cc7-3qxx — CRLF injection via unescaped multipart field names/filenames). Override added to pnpm-workspace.yaml everywhere, and also to package.json pnpm.overrides for the workspaces whose CI pnpm version reads it (mem0-ts, openmemory/ui, pi-agent-plugin, openclaw). Lockfiles regenerated with each workspace's CI pnpm version; only form-data changes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>