Patches the only HIGH/CRITICAL advisories in the c0py dependency tree: two HIGH findings, both on postcss@8.4.31.
Advisory
Package
Before
Fixed in
After
CVE-2026-45623 (HIGH)
postcss
8.4.31
8.5.12
8.5.28
CVE-2026-73646 (HIGH)
postcss
8.4.31
8.5.18
8.5.28
brace-expansion, fast-uri and @xhmikosr/decompress are not present in this repo's lockfile; the scan reports nothing for them.
Why an override
postcss@8.4.31 comes only from next@15.5.25, and every next@15.5.x release (checked up to 15.5.26) pins postcss to exactly 8.4.31. A plain lockfile update therefore cannot reach the fix, and moving to a different next major is out of scope.
The change adds "postcss@<8.5.18": "8.5.28" to pnpm.overrides in the root package.json, next to the existing nanoid override. It stays within the same major (8.x), and 8.5.28 is already resolved for vite, so the tree ends up with one postcss version.
The lockfile diff is limited to three changes: the new overrides line, next now pointing at postcss@8.5.28, and the removal of the postcss@8.4.31 entries. No other package moved and no direct dependency was bumped.
Scan results
Before: trivy fs --scanners vuln --severity HIGH,CRITICAL reported 2 findings (both listed above); the result was the same with --include-dev-deps.
After: trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 1 . reports 0 vulnerabilities and exits 0. With --include-dev-deps it also reports 0. (Trivy DB was cached and current, updated 2026-09-30.)
pnpm audit --prod --audit-level high: no known vulnerabilities found.
Checks run (Node 22.23.2 via mise, pnpm 9.15.9)
pnpm install --frozen-lockfile: OK (lockfile consistent)
pnpm run validate:architecture: OK
pnpm run typecheck: OK (5 workspace projects)
pnpm run test: OK (config 1, web 1, c0py-core 11, api 34 tests, all passing)
pnpm run build: OK (next build on 15.5.25 and tsc for the api)
Not run: pnpm run lint (not part of the CI gates and not required for a lockfile change).
Notes
Note for reviewers: .gitea/workflows/ci.yml currently runs Trivy with --exit-code 0, so it does not block on findings; that is unchanged here.
No production deploy, no branch-protection or secret changes are involved.
## Summary
Patches the only HIGH/CRITICAL advisories in the c0py dependency tree: two HIGH findings, both on `postcss@8.4.31`.
| Advisory | Package | Before | Fixed in | After |
|---|---|---|---|---|
| CVE-2026-45623 (HIGH) | postcss | 8.4.31 | 8.5.12 | 8.5.28 |
| CVE-2026-73646 (HIGH) | postcss | 8.4.31 | 8.5.18 | 8.5.28 |
`brace-expansion`, `fast-uri` and `@xhmikosr/decompress` are not present in this repo's lockfile; the scan reports nothing for them.
## Why an override
`postcss@8.4.31` comes only from `next@15.5.25`, and every `next@15.5.x` release (checked up to 15.5.26) pins `postcss` to exactly `8.4.31`. A plain lockfile update therefore cannot reach the fix, and moving to a different `next` major is out of scope.
The change adds `"postcss@<8.5.18": "8.5.28"` to `pnpm.overrides` in the root `package.json`, next to the existing `nanoid` override. It stays within the same major (8.x), and 8.5.28 is already resolved for `vite`, so the tree ends up with one postcss version.
The lockfile diff is limited to three changes: the new overrides line, `next` now pointing at `postcss@8.5.28`, and the removal of the `postcss@8.4.31` entries. No other package moved and no direct dependency was bumped.
## Scan results
- Before: `trivy fs --scanners vuln --severity HIGH,CRITICAL` reported 2 findings (both listed above); the result was the same with `--include-dev-deps`.
- After: `trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 1 .` reports 0 vulnerabilities and exits 0. With `--include-dev-deps` it also reports 0. (Trivy DB was cached and current, updated 2026-09-30.)
- `pnpm audit --prod --audit-level high`: no known vulnerabilities found.
## Checks run (Node 22.23.2 via mise, pnpm 9.15.9)
- `pnpm install --frozen-lockfile`: OK (lockfile consistent)
- `pnpm run validate:architecture`: OK
- `pnpm run typecheck`: OK (5 workspace projects)
- `pnpm run test`: OK (config 1, web 1, c0py-core 11, api 34 tests, all passing)
- `pnpm run build`: OK (`next build` on 15.5.25 and `tsc` for the api)
Not run: `pnpm run lint` (not part of the CI gates and not required for a lockfile change).
## Notes
- Note for reviewers: `.gitea/workflows/ci.yml` currently runs Trivy with `--exit-code 0`, so it does not block on findings; that is unchanged here.
- No production deploy, no branch-protection or secret changes are involved.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
next@15.5.x hard-pins postcss 8.4.31, so a plain lockfile update cannot
reach the fix. Add a pnpm override (postcss@<8.5.18 -> 8.5.28, same major,
already resolved for vite) so the whole tree uses one patched postcss.
Lockfile diff is limited to dropping postcss 8.4.31 and repointing next.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
OSV re-verification of this branch (head 1258903) against api.osv.dev, 2026-09-30.
Before (main 15cf3ee lockfile): CRITICAL 0, HIGH 2 (postcss@8.4.31: GHSA-6g55-p6wh-862q fixed 8.5.12, GHSA-r28c-9q8g-f849 fixed 8.5.18; pulled in by next@15.5.25, which hard-pins 8.4.31).
After (this branch): CRITICAL 0, HIGH 0 (322 lockfile pairs scanned). No further commits were needed; no other CRITICAL/HIGH advisories exist in pnpm-lock.yaml. Next.js is 15.5.25, so the next/og ImageResponse advisory for 16.3.4/16.3.5 does not apply.
Consistency checks run on the branch (node 22.23.2, pnpm 9.15.9, nice -n 10):
pnpm install --frozen-lockfile: OK
pnpm run validate:architecture: OK
pnpm run typecheck (5 workspace projects): OK
pnpm run test: 5 packages, 54 tests, all passed
pnpm run build (next build with postcss 8.5.28 + tsc for api): OK
Not run / not passing, unrelated to this change: pnpm run lint (root eslint .) exits with code 2 because the repo has no eslint.config.* file (ESLint 9 needs one); it is not part of CI and no config was added here since this lane only touches manifests and lockfiles. Trivy in CI was not run locally.
No guard/pin file changes, no workflow changes, nothing merged.
OSV re-verification of this branch (head 1258903) against api.osv.dev, 2026-09-30.
**Before (main 15cf3ee lockfile):** CRITICAL 0, HIGH 2 (postcss@8.4.31: GHSA-6g55-p6wh-862q fixed 8.5.12, GHSA-r28c-9q8g-f849 fixed 8.5.18; pulled in by next@15.5.25, which hard-pins 8.4.31).
**After (this branch):** CRITICAL 0, HIGH 0 (322 lockfile pairs scanned). No further commits were needed; no other CRITICAL/HIGH advisories exist in pnpm-lock.yaml. Next.js is 15.5.25, so the next/og ImageResponse advisory for 16.3.4/16.3.5 does not apply.
Consistency checks run on the branch (node 22.23.2, pnpm 9.15.9, nice -n 10):
- `pnpm install --frozen-lockfile`: OK
- `pnpm run validate:architecture`: OK
- `pnpm run typecheck` (5 workspace projects): OK
- `pnpm run test`: 5 packages, 54 tests, all passed
- `pnpm run build` (next build with postcss 8.5.28 + tsc for api): OK
Not run / not passing, unrelated to this change: `pnpm run lint` (root `eslint .`) exits with code 2 because the repo has no eslint.config.* file (ESLint 9 needs one); it is not part of CI and no config was added here since this lane only touches manifests and lockfiles. Trivy in CI was not run locally.
No guard/pin file changes, no workflow changes, nothing merged.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Patches the only HIGH/CRITICAL advisories in the c0py dependency tree: two HIGH findings, both on
postcss@8.4.31.brace-expansion,fast-uriand@xhmikosr/decompressare not present in this repo's lockfile; the scan reports nothing for them.Why an override
postcss@8.4.31comes only fromnext@15.5.25, and everynext@15.5.xrelease (checked up to 15.5.26) pinspostcssto exactly8.4.31. A plain lockfile update therefore cannot reach the fix, and moving to a differentnextmajor is out of scope.The change adds
"postcss@<8.5.18": "8.5.28"topnpm.overridesin the rootpackage.json, next to the existingnanoidoverride. It stays within the same major (8.x), and 8.5.28 is already resolved forvite, so the tree ends up with one postcss version.The lockfile diff is limited to three changes: the new overrides line,
nextnow pointing atpostcss@8.5.28, and the removal of thepostcss@8.4.31entries. No other package moved and no direct dependency was bumped.Scan results
trivy fs --scanners vuln --severity HIGH,CRITICALreported 2 findings (both listed above); the result was the same with--include-dev-deps.trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 1 .reports 0 vulnerabilities and exits 0. With--include-dev-depsit also reports 0. (Trivy DB was cached and current, updated 2026-09-30.)pnpm audit --prod --audit-level high: no known vulnerabilities found.Checks run (Node 22.23.2 via mise, pnpm 9.15.9)
pnpm install --frozen-lockfile: OK (lockfile consistent)pnpm run validate:architecture: OKpnpm run typecheck: OK (5 workspace projects)pnpm run test: OK (config 1, web 1, c0py-core 11, api 34 tests, all passing)pnpm run build: OK (next buildon 15.5.25 andtscfor the api)Not run:
pnpm run lint(not part of the CI gates and not required for a lockfile change).Notes
.gitea/workflows/ci.ymlcurrently runs Trivy with--exit-code 0, so it does not block on findings; that is unchanged here.🤖 Generated with Claude Code
OSV re-verification of this branch (head
1258903) against api.osv.dev, 2026-09-30.Before (main
15cf3eelockfile): CRITICAL 0, HIGH 2 (postcss@8.4.31: GHSA-6g55-p6wh-862q fixed 8.5.12, GHSA-r28c-9q8g-f849 fixed 8.5.18; pulled in by next@15.5.25, which hard-pins 8.4.31).After (this branch): CRITICAL 0, HIGH 0 (322 lockfile pairs scanned). No further commits were needed; no other CRITICAL/HIGH advisories exist in pnpm-lock.yaml. Next.js is 15.5.25, so the next/og ImageResponse advisory for 16.3.4/16.3.5 does not apply.
Consistency checks run on the branch (node 22.23.2, pnpm 9.15.9, nice -n 10):
pnpm install --frozen-lockfile: OKpnpm run validate:architecture: OKpnpm run typecheck(5 workspace projects): OKpnpm run test: 5 packages, 54 tests, all passedpnpm run build(next build with postcss 8.5.28 + tsc for api): OKNot run / not passing, unrelated to this change:
pnpm run lint(rooteslint .) exits with code 2 because the repo has no eslint.config.* file (ESLint 9 needs one); it is not part of CI and no config was added here since this lane only touches manifests and lockfiles. Trivy in CI was not run locally.No guard/pin file changes, no workflow changes, nothing merged.
🤖 Generated with Claude Code
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.