Skip to content

Conversation

@taylorreece
Copy link

🎉 Thanks for submitting a pull request! 🎉

Summary

Fixes #7741

Due to npm-shrinkwrap.json, people who install the Netlify CLI pull in fast-redact@3.5.0, which flags dependabot and similar due to CVE-2025-57319

└─┬ netlify-cli@23.9.4 └─┬ fastify@4.29.1 └─┬ pino@9.9.5 └── fast-redact@3.5.0 

pino version 9.12.0 and later do not depend on fast-redact. fastify@4.29.1 accepts pino@^9.0.0, so bumping pino to 9.12.0 is perfectly fine.


For us to review and ship your PR efficiently, please perform the following steps:

  • Open a bug/issue before writing your code 🧑‍💻. This ensures we can discuss the changes and get feedback from everyone that should be involved. If you`re fixing a typo or something that`s on fire 🔥 (e.g. incident related), you can skip this step.
  • Read the contribution guidelines 📖. This ensures your code follows our style guide and
    passes our tests.
  • Update or add tests (if any source code was changed or added) 🧪
  • Update or add documentation (if features were changed or added) 📝
  • Make sure the status checks below are successful ✅

A picture of a cute animal (not mandatory, but encouraged)

@taylorreece taylorreece requested a review from a team as a code owner October 24, 2025 13:46
@serhalp
Copy link
Member

serhalp commented Oct 24, 2025

awesome, thank you! let me just see if I can resolve the same security warning through one of our dev deps: verdaccio/verdaccio#5421 (comment). if not, I'll merge this as is.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants