Skip to content

chore: resolve open dependabot security alerts - #1450

Open
jonathannorris wants to merge 8 commits into
mainfrom
chore/dependabot-alerts
Open

jonathannorris wants to merge 8 commits into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris

@jonathannorris jonathannorris commented Aug 17, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Resolves 22 of 23 open Dependabot alerts with lockfile-only bumps (multer, js-yaml, hono, fast-uri, browserslist, baseline-browser-mapping, ip-address, markdown-it, brace-expansion); no new overrides/resolutions
  • Pins npm to 11.5.1 in pr-checks.yaml to match release-please.yml. setup-node bundles npm 10.x, which drops the nested uuid override (alert chore: improve merging test to include the before hook #179) and fails npm ci lockfile validation
  • Pins prettier to 3.8.4 so the caret range doesn't pull in 3.9.x and reformat unrelated files

Not resolved

@jonathannorris
jonathannorris requested review from a team as code owners August 17, 2026 14:22
@jonathannorris
jonathannorris marked this pull request as draft August 17, 2026 14:22
@jonathannorris
jonathannorris force-pushed the chore/dependabot-alerts branch from 93ccb16 to 10a3576 Compare August 17, 2026 14:30
@coderabbitai

coderabbitai Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d2a12476-3139-4bd2-b8ca-6d49a188d3b5
📥 Commits

Reviewing files that changed from the base of the PR and between 661610b and 046354a.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (3)
  • .github/workflows/pr-checks.yaml
  • package.json
  • packages/angular/package.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The root and Angular package configurations update dependency versions and overrides. Four pull request workflow jobs install npm 11.5.1 before running npm ci.

Changes

Package dependency updates

Layer / File(s) Summary
Root dependency versions
package.json
Pins prettier to 3.8.4 and adds overrides for uuid in the jest-cucumber dependency chain and multer under @nestjs/platform-express.
Angular Vitest updates
packages/angular/package.json
Updates @vitest/browser, @vitest/coverage-v8, and vitest from ^4.1.10 to ^4.1.11.

Pull request workflow npm setup

Layer / File(s) Summary
Set npm version in workflow jobs
.github/workflows/pr-checks.yaml
The build-test, format-lint, codecov-and-docs, and e2e jobs install npm 11.5.1 before running npm ci.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 04635

No actionable merge-blocking risk was established in the reviewed changes.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 04635

The changes affect development dependencies and CI tooling without an observed expansion of credential or deployment authority. No introduced architecture-level security concern was established. Complete dependency-alert remediation remains uncertain because one transitive development dependency has unresolved advisory applicability and reachability.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant exposure includes developer environments and CI/build runners, including the existing release workflow’s dependency-installation path. Development-only classification limits evidence of shipped runtime exposure but does not remove build-time supply-chain authority. No new tenant, datastore, or production request-handler exposure was established.

Security Findings and Attack Paths

  • inferred — The prior advisory inspection reports that Hono 4.13.10 remains within the affected range for serveStatic path double-decoding. The base version is also within that reported range, and the inspected dependency path is unchanged. Whether Angular tooling invokes the affected handler is unresolved; neither a reachable attack path nor a PR-introduced worsening is established.

Trust Boundaries and Controls

  • observed — The new npm installation uses a fixed version in existing pull_request and merge_group jobs. The workflow comparison adds no trigger changes, permission declarations, or secret references. Existing release identity, token, and OIDC configuration is unchanged; effective organization-level permission defaults were not verified.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The current PR description scopes the changes to Dependabot security fixes and the required npm and Prettier pins. The summary for packages/angular/package.json also shows range bumps for `@vitest/b… Remove the three Vitest range bumps, or provide reviewable evidence that they are needed to resolve an alert or support another stated PR objective.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The only directly linked issue is #301. It is closed and completed, so it supplies historical context only. No active linked issue imposes coding or test requirements.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Title check ✅ Passed The title describes the main change: resolving Dependabot security alerts through dependency updates.
Description check ✅ Passed The description explains the dependency updates, npm pinning, Prettier pin, and one alert that remains unresolved.
Full details: Out of Scope Changes check

Explanation

The current PR description scopes the changes to Dependabot security fixes and the required npm and Prettier pins. The summary for packages/angular/package.json also shows range bumps for @vitest/browser, @vitest/coverage-v8, and vitest from ^4.1.10 to ^4.1.11. The supplied evidence does not connect these bumps to the listed alerts or the CI and formatting changes. package-lock.json is excluded from review, so its contents cannot establish such a connection.

  • Fix all pre-merge checks with AI

Comment @coderabbitai help to get the list of available commands.

@jonathannorris
jonathannorris marked this pull request as ready for review August 17, 2026 14:33
@jonathannorris
jonathannorris force-pushed the chore/dependabot-alerts branch from 10a3576 to 5f0a97a Compare August 26, 2026 15:07
@jonathannorris
jonathannorris marked this pull request as draft September 15, 2026 11:49
auto-merge was automatically disabled September 15, 2026 11:49

Pull request was converted to draft

- @angular/compiler ^21.2.19 -> 21.2.23 (medium, alert #303)
- browserslist -> 4.28.9, which pulls in patched baseline-browser-mapping 2.11.23 (high/medium, alerts #284, #292)
- fast-uri (via ajv) -> 3.1.8 (high, alerts #288, #289, #290, #283)
- hono (via @modelcontextprotocol/sdk) -> 4.13.8 (medium, alerts #295, #297)
- js-yaml (via @istanbuljs/load-nyc-config) -> 3.15.2 (high, alert #299)
- vitest/@vitest/browser/@vitest/coverage-v8/@vitest/mocker ^4.1.10 -> ^4.1.11 (medium, alerts #293, #294)
- Added scoped override forcing multer >=2.3.0 under @nestjs/platform-express, whose exact pin (2.1.1) is outside every available semver range (high/low, alerts #291, #301)
- Kept the existing scoped uuid >=11.1.1 override for jest-cucumber's exact-pinned transitive dependency (medium, alert #179)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Matches release-please.yml. actions/setup-node bundles npm 10.x for
Node 22/24/26, which drops the nested uuid override needed for alert

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
#179 and fails npm ci's strict lockfile validation.
npm resolved prettier to 3.9.8 within the existing ^3.7.4 range while
regenerating the lockfile for the dependabot alert fixes, which
reformats files unrelated to this change and fails the Format CI
check. Pin back to 3.8.4 (matching main) to keep this PR's diff
scoped to the alert fixes.

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- multer -> 2.4.0 via existing @nestjs/platform-express override (high/low, alerts #291, #301)
- js-yaml -> 3.15.2 via @istanbuljs/load-nyc-config (high, alert #299)
- baseline-browser-mapping -> 2.11.26 via browserslist (medium, alert #292)
- browserslist -> 4.29.2 (high, alert #284)
- fast-uri -> 3.1.8 via ajv (high, alerts #283, #288, #289, #290)
- uuid -> 11.1.1 via existing jest-cucumber override, already satisfied (medium, alert #179)
- Regenerated package-lock.json from scratch so the existing overrides in package.json are fully re-resolved against current npm registry state (the prior lockfile had drifted and was not honoring them)
- Pinned prettier to exact 3.8.4 (was ^3.8.4) to avoid unrelated formatting drift from a newer 3.9.x resolving within range

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
The previous commit regenerated package-lock.json from scratch, which
re-resolved unrelated transitive dependencies (e.g. ng-packagr's
rolldown-plugin-dts) to newer versions that broke the Angular build
("Cannot find package 'yuku-ast'"). Replaced with a scoped
`npm update <pkg>` for just the vulnerable packages, keeping the diff
minimal and the rest of the dependency tree untouched.

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
@jonathannorris
jonathannorris marked this pull request as ready for review October 5, 2026 15:19
Comment thread package.json
Comment on lines +86 to +98
"overrides": {
"jest-cucumber": {
"uuid": "^11.1.1",
"@cucumber/gherkin": {
"@cucumber/messages": {
"uuid": "^11.1.1"
}
}
},
"@nestjs/platform-express": {
"multer": "^2.3.0"
}
},

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd prefer not to use any overrides.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants