Files
mem0/integrations
kartik-mem0 7495ab67ad chore(n8n): add pnpm security overrides and refresh the lockfile
The n8n node was the only integration without a `pnpm.overrides` block,
so its tree carried 9 advisories (7 high, 2 moderate) that
pi-agent-plugin, openclaw, and vercel-ai-sdk already pin out. Adds the
same block, scoped to the packages actually present in this tree
(`esbuild` and `undici` are not, so their sibling entries are omitted
rather than carried over as dead config).

Down to 2 from 9. Both remaining are GHSA-mh99-v99m-4gvg on the 1.x and
2.x brace-expansion lines, whose fix shipped only in 5.0.8 with no
backport. Forcing those lines to 5.x does clear the audit but breaks
`gulp build`: rimraf -> glob -> minimatch@9 imports brace-expansion as a
default export, which the 5.x ESM build does not provide.

Replacement ranges are capped per major rather than left open like the
siblings'. An unbounded `uuid >=11.1.1` resolves to 14.x, which is
pure ESM and cannot be required by n8n-workflow under Jest's CJS
runtime.

All dev-only: the published package still declares zero runtime
dependencies, so none of this reaches an installed node. lint, build,
and the 5 tests pass; `pnpm install --frozen-lockfile` is clean.
2026-07-29 18:20:12 +05:30
..