Skip to content

pnpm dependency update 2026-09-22 - #32

Merged
pfferrari merged 1 commit into
mainfrom
chore/deps-update-202609220938
Sep 22, 2026
Merged

pfferrari merged 1 commit into
mainfrom
chore/deps-update-202609220938

Conversation

@commercelayer-ci

Copy link
Copy Markdown
Contributor

Dependency update

Closes #31
Branch: chore/deps-update-202609220938
Based on stable: v3.1.0
Prerelease tag: v3.1.1-auto-deps-202609220938.0
Node.js: 24.20.0
pnpm: ``

Automated dependency update via pnpm. Review the dependency diff and validation output before merging.

Dependency update results

  • Check: skipped
  • Build: success
  • Test: skipped

Semver bump log

packages/dato-plugin/package.json
  @types/node  ^24.13.3  →  ^24.13.6
  datocms-plugin-sdk  ^2.2.7  →  ^2.4.2  [cooldown] 2.5.0
  vite                ^8.2.2  →  ^8.3.0

Audit log

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ JS-YAML: Quadratic CPU consumption in !!omap           │
│                     │ resolution (3.x and 4.x) — CVE-2026-59870 fix not      │
│                     │ backported                                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ js-yaml                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <4.3.1                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=4.3.1                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>lerna>cosmiconfig>js-yaml                            │
│                     │                                                        │
│                     │ .>lerna>js-yaml                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-5p4m-2wfm-xmqj      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ pacote is vulnerable to Denial of Service (DoS) via    │
│                     │ the addGitSha function                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ pacote                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=11.2.7 <21.5.1                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=21.5.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>lerna>pacote                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-w4pp-8pjf-rmxw      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ js-yaml: maxTotalMergeKeys does not limit CPU use for  │
│                     │ empty merge sources                                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ js-yaml                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <4.3.2                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=4.3.2                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>lerna>cosmiconfig>js-yaml                            │
│                     │                                                        │
│                     │ .>lerna>js-yaml                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-2883-xcg3-v3hh      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ smol-toml: Denial of Service via malformed TOML        │
│                     │ documents                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ smol-toml                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=1.7.0                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.7.1                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>lerna>@nx/devkit>nx>smol-toml                        │
│                     │                                                        │
│                     │ .>lerna>nx>smol-toml                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-7w5x-hrqm-74c2      │
└─────────────────────┴────────────────────────────────────────────────────────┘
4 vulnerabilities found
Severity: 4 high

Major updates log not updated

package.json
  pnpm        11.9.0  →  12.5.1
  typescript  ^5.9.3  →  ^7.0.2

packages/dato-plugin/package.json
  datocms-plugin-sdk  ^2.4.2  →  ^2.5.0
  datocms-react-ui    ^2.2.7  →  ^2.5.0
  @fortawesome/fontawesome-svg-core    ^6.7.2  →    ^7.3.1
  @fortawesome/free-solid-svg-icons    ^6.7.2  →    ^7.3.1
  @fortawesome/react-fontawesome       ^0.2.6  →    ^3.5.0
  @types/node                        ^24.13.6  →   ^26.6.2
  @types/react                       ^18.3.31  →   ^19.3.0
  @types/react-dom                    ^18.3.7  →   ^19.3.0
  final-form                         ^4.20.10  →    ^5.0.1
  immer                               ^10.2.0  →  ^11.1.18
  react                               ^18.3.1  →   ^19.3.0
  react-dom                           ^18.3.1  →   ^19.3.0
  react-final-form                     ^6.5.9  →    ^7.0.1
  typescript                           ^5.9.3  →    ^7.0.2
  zustand                              ^4.5.7  →   ^5.0.15

@commercelayer-ci commercelayer-ci added the dependencies Pull requests that update a dependency file label Sep 22, 2026
@commercelayer-ci commercelayer-ci self-assigned this Sep 22, 2026
@pfferrari
pfferrari merged commit 47b61a6 into main Sep 22, 2026
2 checks passed
@commercelayer-ci
commercelayer-ci deleted the chore/deps-update-202609220938 branch September 26, 2026 10:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[VANTA] [VULNERABILITY] <CRITICAL> CVE-2024-21536, CVE-2024-21538, CVE-2024-4068 and others, fix before 2026-10-03

2 participants