Update transitive toml dependency to patched 4.3.0 - #11
Open
elijahwander wants to merge 1 commit into
Open
elijahwander wants to merge 1 commit into
elijahwander wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update the locked transitive
tomldependency from 4.1.2 to 4.3.0, within Effect's existing^4.1.1range. This addresses GHSA-82x6-q7mm-w9cf / CVE-2026-77465, fixed in 4.2.0 and later. The lockfile now includes the updated package's registry URL and integrity hash; no direct dependency ranges change.Dependency path:
@opencode-ai/plugin@1.17.15 → effect@4.0.0-beta.83 → toml.Validation on Node 26.8.2:
npm ci --ignore-scriptssucceeded. The existing pinned Git core dependency was built separately from its reviewed source because script suppression omits its generateddistfiles.TMPDIR=/private/tmp).npm auditreports zero known vulnerabilities, down from one high-severity advisory.RangeError.No path from intercom messages to the TOML parser was demonstrated; this fixes a known vulnerable installed dependency rather than claiming a reproduced remote adapter exploit.