Skip to content

Upgrade vulnerable deps + pull out pnpm audit - #1453

Merged
brandur merged 1 commit into
masterfrom
brandur-no-pnpm-audit
Oct 6, 2026
Merged

brandur merged 1 commit into
masterfrom
brandur-no-pnpm-audit

Conversation

@brandur

@brandur brandur commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

While fixing an intermittent build from for JS [1], I ran into a
different intermittent build problem in JS. The CI job runs pnpm audit, and the JS ecosystem has so many vulnerabilities being
discovered all the time that this will arbitrarily fail the build at any
time.

I've upgraded the vulnerable dependencies here, but I'm also pulling
pnpm audit out of the build for now. It doesn't seem like a bad idea,
but we need a way to do this that doesn't involve randomly failing
unrelated builds. I assume Dependabot will get to those dependencies,
but we've been having a heck of a problem with noise from that recently
too, but we may need to find option three.

[1] #1452

While fixing an intermittent build from for JS [1], I ran into a
different intermittent build problem in JS. The CI job runs `pnpm
audit,` and the JS ecosystem has so many vulnerabilities being
discovered all the time that this will arbitrarily fail the build at any
time.

I've upgraded the vulnerable dependencies here, but I'm also pulling
`pnpm audit` out of the build for now. It doesn't seem like a bad idea,
but we need a way to do this that doesn't involve randomly failing
unrelated builds. I assume Dependabot will get to those dependencies,
but we've been having a heck of a problem with noise from that recently
too, but we may need to find option three.

[1] #1452
@brandur
brandur merged commit ba85f3e into master Oct 6, 2026
24 of 25 checks passed
@brandur
brandur deleted the brandur-no-pnpm-audit branch October 6, 2026 04:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant