Repository navigation
docs: sync translations - #5736
github-actions[bot] wants to merge 1 commit into
Conversation
github-actions
Bot
commented
Jul 4, 2026
- Sync translated documents
e2aa966 to
d547e5a
Compare
a5e0d14 to
e82a105
Compare
c5dd1e9 to
6004159
Compare
6835398 to
457bb0f
Compare
fa8ee2f to
cc49ddd
Compare
668897f to
858c624
Compare
4c3ef6b to
08ae176
Compare
4bec419 to
15748ca
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
6c34966 to
addc0ee
Compare
|
|
||
| tinypool@1.1.1: {} | ||
| /tinypool@1.1.1: |
There was a problem hiding this comment.
Critical severity vulnerability introduced by a package you're using:
Line 10470 lists a dependency (tinypool) with a known Critical severity vulnerability. Fixing requires upgrading or replacing the dependency.
ℹ️ Why this matters
Affected versions of tinypool are vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). Tinypool builds worker options by spreading them into a plain object, so inherited properties from a polluted Object.prototype (such as execArgv or env.NODE_OPTIONS) are passed to every spawned worker. An attacker who can pollute Object.prototype anywhere in the process can gain arbitrary code execution in all pool workers, including those created internally by Vitest.
References: https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91718, GHSA, CVE
To resolve this comment:
Upgrade this dependency to at least version 2.1.1 at website/pnpm-lock.yaml.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.