Context
git-semver-tags@8.0.0 depends on @conventional-changelog/git-client@^1.0.0, which resolves to 1.0.1 — vulnerable to argument injection (CVE-2025-59433, GHSA-vh25-5764-9wcr).
Since no patched version of git-semver-tags is available, we added an npm override forcing @conventional-changelog/git-client@^2.0.0 for git-semver-tags.
Action
Once git-semver-tags releases a version that depends on @conventional-changelog/git-client@^2.0.0 natively, remove the override from package.json.
Context
git-semver-tags@8.0.0depends on@conventional-changelog/git-client@^1.0.0, which resolves to1.0.1— vulnerable to argument injection (CVE-2025-59433, GHSA-vh25-5764-9wcr).Since no patched version of
git-semver-tagsis available, we added an npm override forcing@conventional-changelog/git-client@^2.0.0forgit-semver-tags.Action
Once
git-semver-tagsreleases a version that depends on@conventional-changelog/git-client@^2.0.0natively, remove the override frompackage.json.