Skip to content

fix: update flatted to resolve CVE-2026-33228#32

Open
dannyneira wants to merge 1 commit into
mainfrom
independabot/flatted-CVE-2026-33228
Open

fix: update flatted to resolve CVE-2026-33228#32
dannyneira wants to merge 1 commit into
mainfrom
independabot/flatted-CVE-2026-33228

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

  • Adds a flatted override/resolution at ^3.4.2 to remediate the transitive dev dependency vulnerability from flat-cache.
  • Refreshes pnpm-lock.yaml so flat-cache@4.0.1 resolves flatted@3.4.2 instead of 3.3.3.

Vulnerability

Verification

  • pnpm audit --json no longer reports an advisory for flatted.
  • pnpm test
  • pnpm lint

Conversation: https://staging.warp.dev/conversation/814b2f39-259d-4186-9f96-20ba78682683
Run: https://oz.staging.warp.dev/runs/019e7476-c593-7dbd-b96a-44d01f18b66f
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from ianhodge May 29, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants