Skip to content

build(deps): override smol-toml to 1.7.1 - #1755

Merged
jpyzio123 merged 1 commit into
mainfrom
build/ac-4477-smol-toml
Sep 10, 2026
Merged

jpyzio123 merged 1 commit into
mainfrom
build/ac-4477-smol-toml

Conversation

@jpyzio123

@jpyzio123 jpyzio123 commented Sep 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • override the vulnerable transitive smol-toml@1.6.1 used by Nx with patched 1.7.1
  • scope the override to Nx instead of applying it repository-wide
  • resolve the High-severity Dependabot alert tracked in AC-4477

Nx currently hard-pins smol-toml@1.6.1. The latest compatible Nx 22 release, as well as Nx 23.2.1, still uses that vulnerable version, so a parent-package bump cannot resolve the alert yet.

Dependabot alert: https://github.com/livechat/design-system/security/dependabot/507

Validation

  • npm explain smol-toml resolves 1.7.1 through the scoped override
  • npm audit reports 0 High and 0 Critical vulnerabilities
  • npm test
  • npm run build
  • commit hooks and TypeScript type-check

Copilot AI balanced review requested due to automatic review settings September 10, 2026 10:50

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The override is correctly scoped to nx and the lockfile reflects smol-toml@1.7.1 as the resolved installed version.

Pull request overview

This PR mitigates a high-severity vulnerability by using an npm overrides rule to replace Nx’s transitive dependency on smol-toml@1.6.1 with the patched smol-toml@1.7.1, while keeping the override scoped to Nx rather than applying it globally across the workspace.

Changes:

  • Add a scoped npm override so only nx resolves smol-toml to 1.7.1.
  • Update package-lock.json to reflect smol-toml@1.7.1 as the installed version.
File summaries
File Description
package.json Adds a scoped overrides.nx.smol-toml = 1.7.1 rule to address the vulnerability without a repo-wide override.
package-lock.json Updates the resolved node_modules/smol-toml entry to 1.7.1 (including updated integrity metadata).
Review details
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jpyzio123
jpyzio123 merged commit 202b9e6 into main Sep 10, 2026
12 checks passed
@jpyzio123
jpyzio123 deleted the build/ac-4477-smol-toml branch September 10, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants