Resolve Dependabot security update failure by forcing non-vulnerable nanoid resolution #26

Merged
Copilot merged 2 commits from copilot/fix-dependabot-failure into main 2026-08-17 22:47:02 +02:00
Copilot commented 2026-08-17 22:41:57 +02:00 (Migrated from github.com)

Dependabot’s npm_and_yarn security job failed with security_update_not_possible because dependency resolution stayed on vulnerable nanoid@3.3.17 while the minimum patched version is 3.3.18. This PR introduces an explicit resolution path so security updates can proceed without framework downgrades.

  • Dependency resolution policy

    • Added an npm override in package.json to pin nanoid to 3.3.18 across the tree.
  • Lockfile alignment

    • Updated package-lock.json to resolve node_modules/nanoid to 3.3.18 (including tarball/integrity metadata), matching the new override.
  • Why this unblocks Dependabot

    • Dependabot now has a deterministic, non-vulnerable target for nanoid instead of failing on an unresolvable transitive path.
{
  "overrides": {
    "nanoid": "3.3.18"
  }
}
Dependabot’s `npm_and_yarn` security job failed with `security_update_not_possible` because dependency resolution stayed on vulnerable `nanoid@3.3.17` while the minimum patched version is `3.3.18`. This PR introduces an explicit resolution path so security updates can proceed without framework downgrades. - **Dependency resolution policy** - Added an npm override in `package.json` to pin `nanoid` to `3.3.18` across the tree. - **Lockfile alignment** - Updated `package-lock.json` to resolve `node_modules/nanoid` to `3.3.18` (including tarball/integrity metadata), matching the new override. - **Why this unblocks Dependabot** - Dependabot now has a deterministic, non-vulnerable target for `nanoid` instead of failing on an unresolvable transitive path. ```json { "overrides": { "nanoid": "3.3.18" } } ```
Quinta0 (Migrated from github.com) reviewed 2026-08-17 22:41:57 +02:00
Sign in to join this conversation.