Dependabot’s npm_and_yarn security job failed with security_update_not_possible because dependency resolution stayed on vulnerable nanoid@3.3.17 while the minimum patched version is 3.3.18. This PR introduces an explicit resolution path so security updates can proceed without framework downgrades.
Dependency resolution policy
Added an npm override in package.json to pin nanoid to 3.3.18 across the tree.
Lockfile alignment
Updated package-lock.json to resolve node_modules/nanoid to 3.3.18 (including tarball/integrity metadata), matching the new override.
Why this unblocks Dependabot
Dependabot now has a deterministic, non-vulnerable target for nanoid instead of failing on an unresolvable transitive path.
{"overrides":{"nanoid":"3.3.18"}}
Dependabot’s `npm_and_yarn` security job failed with `security_update_not_possible` because dependency resolution stayed on vulnerable `nanoid@3.3.17` while the minimum patched version is `3.3.18`. This PR introduces an explicit resolution path so security updates can proceed without framework downgrades.
- **Dependency resolution policy**
- Added an npm override in `package.json` to pin `nanoid` to `3.3.18` across the tree.
- **Lockfile alignment**
- Updated `package-lock.json` to resolve `node_modules/nanoid` to `3.3.18` (including tarball/integrity metadata), matching the new override.
- **Why this unblocks Dependabot**
- Dependabot now has a deterministic, non-vulnerable target for `nanoid` instead of failing on an unresolvable transitive path.
```json
{
"overrides": {
"nanoid": "3.3.18"
}
}
```
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Dependabot’s
npm_and_yarnsecurity job failed withsecurity_update_not_possiblebecause dependency resolution stayed on vulnerablenanoid@3.3.17while the minimum patched version is3.3.18. This PR introduces an explicit resolution path so security updates can proceed without framework downgrades.Dependency resolution policy
package.jsonto pinnanoidto3.3.18across the tree.Lockfile alignment
package-lock.jsonto resolvenode_modules/nanoidto3.3.18(including tarball/integrity metadata), matching the new override.Why this unblocks Dependabot
nanoidinstead of failing on an unresolvable transitive path.