Dashboard › craft › Distillation
ad84672a-8c03-4ddf-a488-a2469ab4cf43["38f72cf58c2e080cb08dd6472979800a","b2638febeecc8aff5891604d46008815","e2203712d393e81dcee51b874e6d4c1b","15d8c945f0c4ef8658e879ff0f0deba4"]
Date: Jul 28, 2026
semgrep-code-getsentry[bot] posted inline review comments on pnpm-lock.yaml flagging: vite — High severity vulnerability at line 3080 (3 identical comments posted); fast-xml-parser — High severity vulnerability at line 2255; vitest — Critical severity vulnerability at line 3120.pnpm-lock.yaml content near flagged line numbers via git fetch tool result. At current master line numbers the flagged packages are absent: ~line 3080 region contains @smithy/util-utf8@2.3.0, tslib@2.8.1, @aws-crypto/sha256-js@5.2.0, @aws-crypto/supports-web-crypto@5.2.0; ~line 2255 region contains https-proxy-agent@5.0.1, https-proxy-agent@7.0.6, ieee754@1.2.1; ~line 3120 region contains @smithy/* packages (hash-node@4.2.8, invalid-dependency@4.2.8, middleware-content-length@4.2.8, middleware-endpoint@4.4.13, middleware-retry@4.4.30, middleware-serde@4.2.9, middleware-stack@4.2.8, node-config-provider@4.3.8, node-http-handler@4.4.9, protocol-http@5.3.8, smithy-client@4.11.2).pnpm-lock.yaml at PR #854 time), not current merged master — line numbers shifted post-merge. Investigation ongoing into actual resolved versions of vite/vitest/fast-xml-parser and whether genuine CVEs exist (vs phantom/transitive warnings).