Files
mem0/mem0-ts/pnpm-workspace.yaml
T
harshgupta-mem0 d3d9cc9e26 fix(security): patch 8 HIGH + 18 MEDIUM Vanta vulnerabilities
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.

  undici           7.28.0 -> 7.29.0   mem0-ts, openclaw, pi-agent-plugin
                   8.5.0  -> 8.10.0   pi-agent-plugin      (GHSA-4cwx-7wf7-3272 +4)
  ip-address       10.2.0 -> 10.4.0   mem0-ts              (GHSA-mwp4-54f8-5fhr +2)
  brace-expansion  2.1.2  -> 2.1.4    mem0-ts              (GHSA-rgw5-rvv9-x895,
                                                            GHSA-mh99-v99m-4gvg)
                   1.1.15 -> 1.1.18   zapier-mem0          (GHSA-3jxr-9vmj-r5cp)

Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.

Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.

Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.

Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
2026-08-07 17:22:49 +05:30

39 lines
1.2 KiB
YAML

packages:
- "."
onlyBuiltDependencies:
- esbuild
- better-sqlite3
overrides:
"form-data@<4.0.6": ">=4.0.6"
"picomatch@<2.3.2": "^2.3.2"
"picomatch@>=4.0.0 <4.0.4": "^4.0.4"
"jws@4.0.0": "4.0.1"
"js-yaml@<3.15.0": ">=3.15.0 <4.0.0"
"js-yaml@>=4.0.0 <4.3.0": ">=4.3.0 <5.0.0"
"langsmith@<0.6.0": "^0.6.0"
"minimatch@<3.1.3": "^3.1.3"
"minimatch@>=5.0.0 <5.1.8": "^5.1.8"
"minimatch@>=9.0.0 <9.0.7": "^9.0.7"
"path-to-regexp@>=8.0.0 <8.4.0": "^8.4.0"
"postcss@<8.5.18": ">=8.5.18 <9.0.0"
"uuid@<11.1.1": ">=11.1.1"
"ws@>=8.0.0 <8.20.1": ">=8.20.1"
"rollup@>=4.0.0 <4.59.0": "^4.59.0"
"tar-fs@>=2.0.0 <2.1.4": "^2.1.4"
"glob@>=10.2.0 <10.5.0": "^10.5.0"
"@modelcontextprotocol/sdk": "^1.25.4"
"esbuild": ">=0.28.1"
"undici@<7.29.0": ">=7.29.0 <8.0.0"
"axios@<1.18.0": ">=1.18.0 <2.0.0"
"brace-expansion@<1.1.16": ">=1.1.16 <2.0.0"
"brace-expansion@>=2.0.0 <2.1.4": ">=2.1.4 <3.0.0"
"brace-expansion@>=3.0.0 <5.0.8": ">=5.0.8 <6.0.0"
"fast-xml-parser@>=5.0.0 <5.10.1": ">=5.10.1 <6.0.0"
"tar@>=7.0.0 <7.5.21": ">=7.5.21 <8.0.0"
"thrift@<0.23.0": "^0.23.0"
"mongoose@>=9.0.0 <9.7.2": ">=9.7.2 <10.0.0"
"protobufjs@<7.6.5": ">=7.6.5 <8.0.0"
"ip-address@<10.3.1": ">=10.3.1 <11.0.0"