Skip to content

Resolve the 23 open Dependabot alerts - #86

Merged
dggrunzweig merged 2 commits into
devfrom
dependabot/resolve-open-alerts
Sep 22, 2026
Merged

dggrunzweig merged 2 commits into
devfrom
dependabot/resolve-open-alerts

Conversation

@dggrunzweig

Copy link
Copy Markdown
Contributor

The 23 open alerts are ten packages, each flagged several times as its advisory chain moved the patched version forward. Every one has a fix available, so this is a lockfile change with no source change.

Two pins in resolutions had gone stale and were themselves the vulnerable version: qs at 6.14.2 sits inside the range of alert #138, and brace-expansion was held at 1.1.16 and 2.0.2.

Package Was Now Route
brace-expansion 1.1.16, 2.0.2 1.1.21, 2.1.7 refreshed pin
qs 6.14.2 6.16.0 refreshed pin
immutable 3.7.6 3.8.4 new pin, ~3.7.6 blocks it
browserslist 4.23.0 4.29.0 already in range
ip-address 10.0.1 10.7.2 already in range
js-yaml 4.3.0 4.3.2 already in range
nanoid 3.3.8 3.3.19 already in range
postcss 8.5.3 8.5.28 already in range
vitest, @vitest/mocker 3.1.3 4.1.11 major upgrade
  • vitest goes to 4 because the @vitest/mocker advisory has no 3.x fix. The suite needed no changes: same 78 passing, and vitest.config.ts only sets a graphql alias. Held at 4.x rather than 5, which requires Node 22 while CI runs 20.
  • immutable is the one package whose declared range blocked the patch, so it gets a scoped pin on ~3.7.6 rather than a bare override.
  • I kept vitest as an exact pin to match the file, though an exact pin on a dev tool is what let it drift onto a vulnerable release in the first place.

yarn typecheck and yarn build pass. yarn test:ci gives 78 passed and 13 failed, identical to the same run before this change; all 13 are the missing-credentials guard, which the CI job supplies. yarn lint fails on --ignore-path under the flat config, which also reproduces on an unmodified checkout and is left alone here.

🤖 Generated with Claude Code

Refreshes the stale resolution pins, bumps the transitives whose declared
ranges already allowed a patched release, and moves vitest to 4.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dggrunzweig
dggrunzweig merged commit 754d9bc into dev Sep 22, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants