Skip to content

Commit e838c80

Browse files
Goosterhofclaude
andcommitted
chore(deps): pin qs >=6.15.2 under typed-rest-client via overrides — durable GHSA-q8mj-m7cp-5q26 curation (queue #94)
Stryker's transitive typed-rest-client@2.3.1 exact-pins vulnerable qs@6.15.1 (GHSA-q8mj-m7cp-5q26 DoS). A lockfile-only pin does not survive clean regens — applied and lost twice before. This adds a regen-invariant overrides block forcing qs>=6.15.2 within the typed-rest-client subtree, so curation holds across any future npm install from scratch. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 15e100f commit e838c80

2 files changed

Lines changed: 926 additions & 1659 deletions

File tree

0 commit comments

Comments
 (0)