Files
mem0/integrations/zapier-mem0/pnpm-workspace.yaml
T
harshgupta-mem0 d3d9cc9e26 fix(security): patch 8 HIGH + 18 MEDIUM Vanta vulnerabilities
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.

  undici           7.28.0 -> 7.29.0   mem0-ts, openclaw, pi-agent-plugin
                   8.5.0  -> 8.10.0   pi-agent-plugin      (GHSA-4cwx-7wf7-3272 +4)
  ip-address       10.2.0 -> 10.4.0   mem0-ts              (GHSA-mwp4-54f8-5fhr +2)
  brace-expansion  2.1.2  -> 2.1.4    mem0-ts              (GHSA-rgw5-rvv9-x895,
                                                            GHSA-mh99-v99m-4gvg)
                   1.1.15 -> 1.1.18   zapier-mem0          (GHSA-3jxr-9vmj-r5cp)

Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.

Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.

Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.

Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
2026-08-07 17:22:49 +05:30

11 lines
244 B
YAML

packages:
- '.'
overrides:
"form-data@<4.0.6": ">=4.0.6"
"uuid@<11.1.1": ">=11.1.1"
"esbuild": ">=0.28.1"
"undici@<7.29.0": ">=7.29.0 <8.0.0"
"undici@>=8.0.0 <8.9.0": ">=8.9.0 <9.0.0"
"brace-expansion@<1.1.16": ">=1.1.16 <2.0.0"