Skip to content

Bump web dependencies to fix Dependabot security alerts - #469

Open
alex-clickhouse wants to merge 2 commits into
mainfrom
alex/web-deps-security
Open

alex-clickhouse wants to merge 2 commits into
mainfrom
alex/web-deps-security

Conversation

@alex-clickhouse

@alex-clickhouse alex-clickhouse commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Fixes 28 of the 30 open Dependabot alerts in web/. Each package goes to a patched version in its current major version, so the change is in the lockfile, plus two floor bumps in package.json.

Package From To Alerts
js-yaml 4.1.1 4.3.2 #25, #28, #42, #54
react-router, react-router-dom 7.17.0 7.18.4 #27, #30, #31, #32, #41
undici 8.10.0 8.11.2 #56, #58, #59, #60, #61, #63, #65
postcss 8.5.12 8.5.28 #33, #40
brace-expansion 1.1.12, 5.0.3 1.1.21, 5.0.12 #26, #29
vite 7.3.2 7.3.6 #21, #22
esbuild 0.27.3 0.28.2 #19
nanoid 3.3.11 3.3.19 #49
browserslist 4.28.1 4.29.2 #46
baseline-browser-mapping 2.10.0 2.11.26 #51
@humanfs/node 0.16.7 0.16.8 #48
@babel/core 7.29.0 7.29.7 #23

The other changes in the lockfile are dependencies of these packages: the @babel/* family, the @esbuild/* platform binaries, and the browserslist data packages. Vite 7.3.6 accepts esbuild ^0.27.0 || ^0.28.0, so the esbuild alert does not need Vite 8.

Not in this PR: the vitest and @vitest/mocker alerts (#50, #52) need vitest 4.1.11 or later, which is a major upgrade. #431 has that.

This replaces the Dependabot PRs #266, #302, #303, #419, #423, #427, #432 and #443. Dependabot closes them when this is merged. #146 and #114 (Vite 8) are not necessary for these alerts.

Verification

  • npm ci --strict-peer-deps, npm run build and npm test (358 tests) pass on Node 22.21.0.
  • Each changed package declares a Node engine range that includes the 22.12.0 floor, except undici. undici is a dev dependency of jsdom and requires Node 22.19.0 in both 8.10.0 and 8.11.2. ci.yml already allows this for dev-only tools.
  • A script compared each open alert's vulnerable range with every copy of the package in the new lockfile. Only Cache notification messages for reaction context #50 and Cap adaptive-thinking effort per model's supported levels #52 are still vulnerable.

🤖 Generated with Claude Code

alex-clickhouse and others added 2 commits September 29, 2026 13:34
Update each package that has an open Dependabot alert to a patched version
in its current major version:

- js-yaml 4.3.2, nanoid 3.3.19, browserslist 4.29.2,
  baseline-browser-mapping 2.11.26, @humanfs/node 0.16.8,
  brace-expansion 1.1.21 and 5.0.12, postcss 8.5.28, @babel/core 7.29.7
- react-router-dom and react-router 7.18.4
- vite 7.3.6. It accepts esbuild 0.28, so esbuild goes to 0.28.2.

The vitest alerts need vitest 4.1.11 or later, which is a major upgrade.
That is in #431.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
undici below 8.10.2 has seven open alerts. jsdom 30 accepts undici
^8.9.0, so this is a lockfile change only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant