Conversation
Co-Authored-By: Penelope <penelope@paella.dev>
Original prompt from Penelope |
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
Description
Resolves Dependabot alert #362 (CVE-2025-59343) - high severity path traversal vulnerability in tar-fs.
Added pnpm override to force tar-fs version 2.1.4 (patched version) instead of the vulnerable 2.1.3. The vulnerable version was being pulled in as a transitive dependency by
@remix-run/dev.Test plan
Package updates
Link to Devin run: https://app.devin.ai/sessions/ae745e25423b4e3693564324ee5bffa9
Requested by: Penelope (@soinclined)