Dashboardcraftgetsentry/craft open Dependabot alerts:…

getsentry/craft open Dependabot alerts: smol-toml, cookie, brace-expansion, svgo

Category: pattern
Confidence: 0.80
ID: 019fdd24-1a85-7f54-9f0c-7df180274162
Project ID: e16af391-c497-4837-b681-c849a5514499
Cross-project: No
Recalled in other projects: 0
Source session: 1LCorxku9DNLu5w5f
Created: 2026-08-07 16:52:38
Updated: 2026-08-07 16:52:38

Content

Snapshot after PR #866 merge (Aug 2026): 7 Dependabot alerts still open on getsentry/craft default branch: js-yaml ×3 (alerts #215/#216/#219, GHSA-5p4m-2wfm-xmqj — same advisory, multiple vulnerable copies), smol-toml (#218, GHSA-v3rj-xjv7-4jmq), cookie (#217, GHSA-pxg6-pf52-xh8x), brace-expansion (#214, GHSA-rgw5-rvv9-x895), svgo (#197, GHSA-2p49-hgcm-8545). All are transitive. Before fixing each: trace the full chain in BOTH root and docs/ lockfiles (root pnpm.overrides don't cascade [[019fa896-e1de-7551-bdb9-bce5ad328264]]), follow the deep-chain verification rule [[019fdd20-369f-740b-95af-7487ca5d076a]], and check whether the package is a direct-pin devDep (like tar [[019ef40b-f60a-7a76-81c9-cc1efbc24430]]) before reaching for overrides.

Move to: