Repository navigation
chore: resolve open dependabot security alerts - #1450
jonathannorris wants to merge 8 commits into
Conversation
93ccb16 to
10a3576
Compare
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe root and Angular package configurations update dependency versions and overrides. Four pull request workflow jobs install npm 11.5.1 before running ChangesPackage dependency updates
Pull request workflow npm setup
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk was established in the reviewed changes. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The changes affect development dependencies and CI tooling without an observed expansion of credential or deployment authority. No introduced architecture-level security concern was established. Complete dependency-alert remediation remains uncertain because one transitive development dependency has unresolved advisory applicability and reachability. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Out of Scope Changes checkExplanation The current PR description scopes the changes to Dependabot security fixes and the required npm and Prettier pins. The summary for
Comment |
10a3576 to
5f0a97a
Compare
f40b29c to
661610b
Compare
Pull request was converted to draft
- @angular/compiler ^21.2.19 -> 21.2.23 (medium, alert #303) - browserslist -> 4.28.9, which pulls in patched baseline-browser-mapping 2.11.23 (high/medium, alerts #284, #292) - fast-uri (via ajv) -> 3.1.8 (high, alerts #288, #289, #290, #283) - hono (via @modelcontextprotocol/sdk) -> 4.13.8 (medium, alerts #295, #297) - js-yaml (via @istanbuljs/load-nyc-config) -> 3.15.2 (high, alert #299) - vitest/@vitest/browser/@vitest/coverage-v8/@vitest/mocker ^4.1.10 -> ^4.1.11 (medium, alerts #293, #294) - Added scoped override forcing multer >=2.3.0 under @nestjs/platform-express, whose exact pin (2.1.1) is outside every available semver range (high/low, alerts #291, #301) - Kept the existing scoped uuid >=11.1.1 override for jest-cucumber's exact-pinned transitive dependency (medium, alert #179) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Matches release-please.yml. actions/setup-node bundles npm 10.x for Node 22/24/26, which drops the nested uuid override needed for alert Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com> #179 and fails npm ci's strict lockfile validation.
661610b to
0ad2150
Compare
npm resolved prettier to 3.9.8 within the existing ^3.7.4 range while regenerating the lockfile for the dependabot alert fixes, which reformats files unrelated to this change and fails the Format CI check. Pin back to 3.8.4 (matching main) to keep this PR's diff scoped to the alert fixes. Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- multer -> 2.4.0 via existing @nestjs/platform-express override (high/low, alerts #291, #301) - js-yaml -> 3.15.2 via @istanbuljs/load-nyc-config (high, alert #299) - baseline-browser-mapping -> 2.11.26 via browserslist (medium, alert #292) - browserslist -> 4.29.2 (high, alert #284) - fast-uri -> 3.1.8 via ajv (high, alerts #283, #288, #289, #290) - uuid -> 11.1.1 via existing jest-cucumber override, already satisfied (medium, alert #179) - Regenerated package-lock.json from scratch so the existing overrides in package.json are fully re-resolved against current npm registry state (the prior lockfile had drifted and was not honoring them) - Pinned prettier to exact 3.8.4 (was ^3.8.4) to avoid unrelated formatting drift from a newer 3.9.x resolving within range Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
The previous commit regenerated package-lock.json from scratch, which
re-resolved unrelated transitive dependencies (e.g. ng-packagr's
rolldown-plugin-dts) to newer versions that broke the Angular build
("Cannot find package 'yuku-ast'"). Replaced with a scoped
`npm update <pkg>` for just the vulnerable packages, keeping the diff
minimal and the rest of the dependency tree untouched.
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
| "overrides": { | ||
| "jest-cucumber": { | ||
| "uuid": "^11.1.1", | ||
| "@cucumber/gherkin": { | ||
| "@cucumber/messages": { | ||
| "uuid": "^11.1.1" | ||
| } | ||
| } | ||
| }, | ||
| "@nestjs/platform-express": { | ||
| "multer": "^2.3.0" | ||
| } | ||
| }, |
There was a problem hiding this comment.
I'd prefer not to use any overrides.
Summary
multer,js-yaml,hono,fast-uri,browserslist,baseline-browser-mapping,ip-address,markdown-it,brace-expansion); no newoverrides/resolutionspr-checks.yamlto matchrelease-please.yml.setup-nodebundles npm 10.x, which drops the nesteduuidoverride (alert chore: improve merging test to include the before hook #179) and failsnpm cilockfile validationprettierto3.8.4so the caret range doesn't pull in 3.9.x and reformat unrelated filesNot resolved
piscina(critical): pinned to exactly 5.2.0 by@angular/build22.1.7, and the fix needs the Angular 22.2.x set. Covered by chore(deps): update angular monorepo #1492; re-run after it merges