Skip to content

fix(dev-1706): bump vitest to 3.2.6 in monocle-backend - #76

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1706
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1706

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

packages/monocle-backend/package.json pins its own vitest devDependency separately from the root workspace (^1.3.1), distinct from the root-workspace vitest advisory already covered by PR #56 (tracked in DEV-1687). GHSA-5xrq-8626-4rwp requires vitest >= 3.2.6. No Dependabot PR exists for this finding. Bumped via pnpm update vitest@3.2.6 --filter @spur.us/monocle-backend --lockfile-only.

Test evidence

No Dependabot PR existed to replay; constructed from first_patched_version 3.2.6. CI will run on this PR (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check).

Risk

Medium. Dev-only dependency bump (vitest 1 -> 3) scoped to one workspace package's test tooling; no production/published package code changes. CI's Unit Tests step exercises monocle-backend's test suite directly.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Oct 7, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

ci-failed: the 'Linting and Changeset Checks' CI job failed on this PR (CodeQL and Unit Tests passed). Not merged. A human must review this. This reviewer will not act on this PR again.

[[spur-vuln-reviewer: escalated ci-failed]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants