Loading
Fix UI dependency CVEs for uuid and marked
Summary
Fixes the UI dependency CVEs mirrored as GitHub issues:
- https://github.com/postgres-ai/database-lab-engine/issues/346 — CVE-2026-41907 in
uuid@8.3.2, fixed by forcinguuid >=14.0.0 - https://github.com/postgres-ai/database-lab-engine/issues/347 — CVE-2026-41680 in
marked@14.0.0, fixed by forcingmarked >=18.0.2
Also relates to GitLab work item #706 (closed).
Changes
- Adds pnpm overrides for vulnerable transitive dependency ranges.
- Regenerates
ui/pnpm-lock.yamlwith pnpm 8.15.9, preserving lockfile v6.
Validation
Red/green:
- RED:
grep -qE '^ /(uuid@8\.3\.2|marked@14\.0\.0):' ui/pnpm-lock.yamlfound both vulnerable versions before the fix. - GREEN: same lockfile check passes after the fix.
Local gates:
PATH=/tmp/pnpm-bin:$PATH pnpm --filter @postgres.ai/ce lintPATH=/tmp/pnpm-bin:$PATH pnpm --filter @postgres.ai/ce buildPATH=/tmp/pnpm-bin:$PATH pnpm --filter @postgres.ai/ce testPATH=/tmp/pnpm-bin:$PATH pnpm --filter @postgres.ai/ce cy:run
All passed locally.