d3d9cc9e26
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.
undici 7.28.0 -> 7.29.0 mem0-ts, openclaw, pi-agent-plugin
8.5.0 -> 8.10.0 pi-agent-plugin (GHSA-4cwx-7wf7-3272 +4)
ip-address 10.2.0 -> 10.4.0 mem0-ts (GHSA-mwp4-54f8-5fhr +2)
brace-expansion 2.1.2 -> 2.1.4 mem0-ts (GHSA-rgw5-rvv9-x895,
GHSA-mh99-v99m-4gvg)
1.1.15 -> 1.1.18 zapier-mem0 (GHSA-3jxr-9vmj-r5cp)
Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.
Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.
Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results