Skip to content

chore(web): patch vulnerable transitive dependencies - #717

Open
markmur wants to merge 2 commits into
mainfrom
security/web-dependencies
Open

markmur wants to merge 2 commits into
mainfrom
security/web-dependencies

Conversation

@markmur

@markmur markmur commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Pin patched brace-expansion, fast-uri, and postcss releases.
  • Pin nanoid 3.x to 3.3.18, including the vulnerable copy not yet shown on the Dependabot dashboard.
  • Regenerate the Web lockfile without changing direct dependencies.

Stack

  1. chore(react-native): replace vulnerable URI decoder #719
  2. chore(react-native): patch vulnerable transitive dependencies #718
  3. chore(web): patch vulnerable transitive dependencies #717 ← This PR
  4. chore(protocol): patch vulnerable transitive dependencies #716

@markmur
markmur force-pushed the security/web-dependencies branch from 78cb1e8 to 9e35532 Compare September 18, 2026 13:06
@markmur
markmur force-pushed the security/protocol-dependencies branch from a2c42ea to f2d9371 Compare September 18, 2026 13:06
@github-actions

Copy link
Copy Markdown

Web — Coverage Report

Lines Statements Branches Functions
Coverage: 96%
94.47% (342/362) 81.77% (166/203) 96.84% (92/95)

@github-actions

Copy link
Copy Markdown

Package Size

Platform Artifact Base Head Delta
Web npm tarball 80.1 KiB 80.1 KiB 0 B
Web file breakdown
File Base Head Delta
dist/index.js.map 217.7 KiB 217.7 KiB 0 B
dist/custom-elements.json 51.4 KiB 51.4 KiB 0 B
dist/index.d.ts 45.9 KiB 45.9 KiB 0 B
dist/index.js 39.5 KiB 39.5 KiB 0 B
README.md 20.0 KiB 20.0 KiB 0 B
package.json 2.9 KiB 2.9 KiB 0 B
LICENSE 1.1 KiB 1.1 KiB 0 B

Measured from the PR base SHA and PR head SHA. The file breakdown shows uncompressed sizes within each package artifact, so individual files do not sum to the compressed artifact total. This comment reports package artifact sizes only; it is not a final app binary-size report.

Base automatically changed from security/protocol-dependencies to main September 18, 2026 13:29
@bitrise

bitrise Bot commented Sep 18, 2026

Copy link
Copy Markdown

Install this build

Open Tophat, select your target device, then click Install. Links open on the Mac running Tophat.

SDK Install
React Native Install with Tophat
Swift Install with Tophat
Kotlin Install with Tophat

Checkout Kit E2E results

Status Tags Target Platform OS version tag Device
launch, checkout-presentation, checkout-completion, buyer-identity react-native ios latest iPhone 15
iOS 27 Beta
launch, checkout-presentation, checkout-completion, buyer-identity react-native android latest Google Pixel 9
Android 17.0
launch, checkout-presentation, checkout-completion, buyer-identity, preload kotlin android latest Google Pixel 9
Android 17.0
launch, checkout-presentation, checkout-completion, buyer-identity, preload swift ios latest iPhone 15
iOS 27 Beta

@markmur
markmur enabled auto-merge (squash) September 18, 2026 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant