fix(security): remediate open npm Dependabot alerts - #1452
Open
Wassim Chegham (manekinekko) wants to merge 2 commits into
Open
Wassim Chegham (manekinekko) wants to merge 2 commits into
Wassim Chegham (manekinekko) wants to merge 2 commits into
Conversation
Bump pnpm override floors (scoped per major) and direct dependency ranges so every vulnerable package in pnpm-lock.yaml resolves to a patched release: - undici@5 -> ^6.28.1, undici@7 -> ^7.29.1 - brace-expansion@5 -> ^5.0.12 (2.x line refreshed to 2.1.7) - tar ^7.5.21 (packages/shared), multer ^2.4.0 (apps/api + override) - adm-zip ^0.6.1, @grpc/grpc-js ^1.14.5, qs ^6.16.0, js-yaml@3 ^3.15.2 - fast-xml-parser ^5.10.1, postcss ^8.5.23 (apps/portal + override) - react-router / react-router-dom ^7.18.2, shell-quote ^1.9.0 - vitest / @vitest/coverage-v8 ^4.1.11 - transitive refresh: body-parser 1.20.8, browserslist 4.29.1, baseline-browser-mapping 2.11.25, postcss-selector-parser 6.1.4 - nanoid: replace the bare 3.3.15 pin with nanoid@3 ^3.3.18 (postcss 8.5.28 requires ^3.3.18) Regenerate NOTICE for the updated production dependency versions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Upgrade the docs site to Astro 7 (required by the astro advisories, first patched in 7.2.8) and refresh its transitive dependencies: - astro ^7.3.5, @astrojs/starlight ^0.42.4, starlight-openapi ^0.26.2 - add @astrojs/markdown-remark: Astro 7 defaults to Satteri and only runs markdown.remarkPlugins when the remark pipeline is installed - sharp ^0.35.4 - overrides: vite >=8.0.16 <9 (Astro 7 requires Vite 8), js-yaml >=4.3.2 <5 - transitive refresh: fast-uri 3.1.8, svgo 4.1.0, nanoid 3.3.19, postcss 8.5.28, devalue 5.9.4, smol-toml 1.9.0, postcss-selector-parser 6.1.4 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Test Results (Node.js 22)test: Run #172
🎉 All tests passed! |
Wassim Chegham (manekinekko)
marked this pull request as ready for review
October 1, 2026 19:37
Wassim Chegham (manekinekko)
requested a review
from Cedric Vidal (cedricvidal)
as a code owner
October 1, 2026 19:37
Cedric Vidal (cedricvidal)
approved these changes
Oct 2, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR fixes all 91 npm Dependabot alerts that were open on
mainas of 2026-10-01: 58 in the rootpnpm-lock.yamland 33 inwebsite/.pnpm.overridesfloors, keeping overrides scoped per major (undici@5,undici@7,brace-expansion@5,js-yaml@3, …). I also raised direct dependency ranges where the package is a direct dependency:multerinapps/api,postcssandreact-router-dominapps/portal,tarinpackages/shared, andvitestat the root and inevaluations/static-prompts. I refreshed the remaining transitive packages withpnpm update -r --depth Infinity, which adds no new overrides.NOTICEis regenerated withpnpm notice.Alerts resolved
Root (
pnpm-lock.yaml)undici@5override)"nanoid": "3.3.15"pin is replaced by"nanoid@3": "^3.3.18", because postcss 8.5.28 requiresnanoid ^3.3.18.pnpm auditis now clean.Website (
website/pnpm-lock.yaml,website/package.json)Supporting website changes:
@astrojs/starlight0.39 → 0.42.4 andstarlight-openapi0.25 → 0.26.2. These are the versions compatible with Astro 7.@astrojs/markdown-remarkas a direct dependency. Astro 7 uses the Sätteri Markdown processor by default, andmarkdown.remarkPlugins(GFM, base-path, HTTP snippets) only run when the remark pipeline is installed.website/AGENTS.mddocuments this.website/pnpm-workspace.yaml: theviteoverride changes from>=7.3.5 <8to>=8.0.16 <9, because Astro 7 requires Vite 8 and 8.0.16 is the first patched 8.x release. Thejs-yamloverride changes from>=4.2.0 <5to>=4.3.2 <5.Alerts that could not be fixed
None. I checked every alert's vulnerable range with semver against the regenerated lockfiles: 91/91 are no longer matched.
first_patched_version. Its vulnerable range is>= 0.5.9, <= 0.6.0, so 0.6.1 falls outside it.Supersedes these open Dependabot PRs
Not closed here:
#736 (uuid 14) is not a security alert and is intentionally untouched.
Notes for reviewers
registry.npmjs.orgis blocked on the dev network, so both lockfiles were regenerated through the Microsoft CFS proxy (packagefeedproxy.microsoft.io). CFS metadata exposes only the sha1shasum, not the sha512integrity.sha1integrity and a1es-publictarball URL.mainalready contains 172 entries of this form, and the feed is anonymously readable, so CI installs from it today.The collection "i18n" does not exist or is empty. It's harmless (the site is single-locale) and build output is unaffected.Validation
Root
pnpm install --frozen-lockfile✅pnpm build✅pnpm test: 251 files / 3177 tests pass withvitest run --maxWorkers=6✅spawnSync ETIMEDOUT. These arescripts/register-agent,install-cli,ensure-dev-certsandbuild-windows-worker.pnpm lintmain:eslintisn't installed, and the CI job iscontinue-on-errorwith a TODO. Portal lint passes.pnpm notice:check✅ (NOTICE regenerated with cargo-about 0.9.1)pnpm audit: no known vulnerabilities ✅Website
pnpm install --frozen-lockfile,pnpm test(7/7), andSITE=https://microsoft.github.io BASE_PATH=/scope pnpm run buildall pass: 214 pages ✅main: same 214 HTML files and the same counts of tables (26), HTTP-snippet tabs (302),<pre>blocks (839) and content links. Only CSS bundle hashes and names differ.astro devsmoke test: HTTP 200, and the HTTP snippet tabs render ✅pnpm audit: no known vulnerabilities ✅