fix: Dependency bumps in transitive dependencies#26149
Merged
shortstacked merged 2 commits intomasterfrom Feb 23, 2026
Merged
Conversation
Bundle ReportBundle size has no change ✅ |
[email protected] and eslint use minimatch as a default export which was removed in minimatch 10.x. These are dev-only dependencies not present in the production image. Co-Authored-By: Claude Opus 4.6 <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This comment has been minimized.
This comment has been minimized.
geemanjs
approved these changes
Feb 23, 2026
This comment has been minimized.
This comment has been minimized.
Contributor
|
Git push to origin failed for 1.x with exitcode 1 |
shortstacked
added a commit
that referenced
this pull request
Feb 25, 2026
Backport of #26149 to 1.x branch. Bumps transitive dependencies via pnpm overrides: tar, fast-xml-parser, ajv, bn.js, minimatch. Co-Authored-By: Claude Opus 4.6 <[email protected]>
4 tasks
shortstacked
added a commit
that referenced
this pull request
Feb 25, 2026
Backport of #26149 to 1.x branch. Bumps transitive dependencies via pnpm overrides: tar, fast-xml-parser, ajv, bn.js, minimatch. Co-Authored-By: Claude Opus 4.6 <[email protected]>
shortstacked
added a commit
that referenced
this pull request
Feb 25, 2026
Backport of #26149 to 1.x branch. Bumps transitive dependencies via pnpm overrides: tar, fast-xml-parser, ajv, bn.js, minimatch. Co-Authored-By: Claude Opus 4.6 <[email protected]>
shortstacked
added a commit
that referenced
this pull request
Feb 25, 2026
Backport of #26149 to 1.x branch. Bumps transitive dependencies via pnpm overrides: tar, fast-xml-parser, ajv, bn.js, minimatch. Co-Authored-By: Claude Opus 4.6 <[email protected]>
Merged
Tuukkaa
pushed a commit
that referenced
this pull request
Mar 2, 2026
Co-authored-by: Claude Opus 4.6 <[email protected]>
Merged
Tuukkaa
pushed a commit
that referenced
this pull request
Mar 2, 2026
Co-authored-by: Claude Opus 4.6 <[email protected]>
Contributor
|
Got released with |
Contributor
|
Git push to origin failed for 1.x with exitcode 1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bumps multiple transitive dependencies to their latest stable versions via pnpm overrides. All packages are transitive (not direct dependencies) so overrides are the appropriate fix per our process.
Safe bumps (patch/minor)
Major version overrides (transitive only)
These packages had no backport fix in their current major line, so the override forces a newer major version. Since these are deep transitive dependencies consumed by other libraries, the risk is contained.
.modn()renamed to.modrn(),.strip()internalized. Low risk for ASN.1 integer operationsdataPath→instancePathin error objects, error message wording changes ("should" → "must")Not overridden
minimatch()as a default export — removed in v10. Dev-only, not in production imageAlso added
ajv,bn.js,fast-xml-parser,hono, andminimatchtominimumReleaseAgeExcludeinpnpm-workspace.yamlto allow recently-published versions.Verification
pnpm install— cleanpnpm build— 48/48 tasks successfulpnpm typecheck(cli, nodes-base) — cleanpnpm test:affected— no regressionsRelated Linear tickets, Github issues, and Community forum posts
Review / Merge checklist
release/backport(if the PR is an urgent fix that needs to be backported)