Repository navigation
chore(deps): clear root workspace security alerts - #3363
Conversation
Bump undici 7.29.0 -> 7.29.1 (direct pins and override), fast-uri override 3.1.6 -> 3.1.7, brace-expansion@5 override to ^5.0.12, oxfmt ^0.64.0 -> ^0.67.0 (pulls tinypool 2.1.2), and refresh source-map-js to 1.2.2. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Size Report
Startup median (7 runs, lower is better):
|
@limrun/api 0.60.0 pins undici 7.29.1, matching the direct pins, so the transitive override is no longer needed. 0.61.0 is held back by pnpm's default minimumReleaseAge. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
This PR is ready at e61a275. Checks are green (22 of 22), and the diff only touches manifests, the lockfile and workspace overrides. The limrun provider unit tests, the type-check and the bundled-undici size report all cover the changed packages. I read the lockfile text and diffed the @limrun/api tarball. I did not re-run |
Summary
Clears every open root-workspace Dependabot alert. 6 files; no source changes.
^0.59.0→^0.60.0pins undici 7.29.1 itself, so theundici@7override is removed. 0.61.0 is <24h old, held back byminimumReleaseAge. Alerts Expose dump of recent HTTP traffic for session app #95, Expose app container and file system access (get_app_container / adb pull) #96, Add pixel-level visual screenshot diff (in addition to tree diff) #97, Expose media input simulation (camera roll, photo/video, mic) #98, [Lower priority] Expose performance metrics (FPS, memory, CPU, startup time) #101, [Lower priority] Keyboard state introspection (visibility, type, dismiss) #102, [Lower priority] Biometric simulation beyond Face ID (Touch ID, fingerprint on Android) #104, [Lower priority] Orientation and rotation control (landscape layouts) #105, feat: add full session log coverage and diagnostics workflows #106, chore: streamline AGENTS onboarding and testing matrix #107, feat: publish on ClawHub #110, feat: improve logs debugging workflow #111, docs: harden agent-device skill security guidance #113, open <package> fails to launch app without explicit --activity flag (launcher activity resolution broken for multi-entry apps) #114, fix: add MAIN/LAUNCHER flags to Android launcher activity resolver #115, Fail to fill text with Chinese character or emoji #116, feat: add settings appearance command #119, feat: add network dump command for session app traffic #120, Add trigger-screenshot command to simulate iOS screenshot notification #123, Port https://skills.sh/vercel-labs/agent-browser/dogfood to agent-device ? #124, feat: add AndroidTV and tvOS target support #125, Implement Android CPU and memory sampling in perf payload #126,screenshotfails on physical iOS device with Xcode 26.x —devicectl device screenshotsubcommand not found #129, fix: fallback iOS/tvOS screenshot when devicectl screenshot is unavailable #130.^5.0.9→^5.0.12. Alert feat: port dogfood skill to agent-device #133.^0.64.0→^0.67.0(oldest with tinypool 2.1.2);pnpm formatchanged nothing. Alerts Android:press @reffails with "press requires x y" error #139, Android:filltruncates input with standard ASCII special characters (+, @) #140.Validation
At
e61a2759a:pnpm install --frozen-lockfileclean;pnpm check:affected --run→all runnable checks passed. Limrun suites run directly: 33 files, 212 tests passed. Device lanes are GitHub-authoritative.pnpm why -r <pkg>:Size +4.7 kB unpacked (>3 kB threshold): bundled
undici.js+4.26 kB is the 7.29.1 security patch itself; limrunlog-stream.js/ios-client.js+0.4 kB from 0.60.0. Dropping either would reintroduce the vulnerability or the override.examples/test-appalerts are out of scope.🤖 Generated with Claude Code