Skip to content

chore: resolve open dependabot security alerts - #426

Open
jonathannorris wants to merge 5 commits into
mainfrom
chore/dependabot-alerts
Open

jonathannorris wants to merge 5 commits into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris

@jonathannorris jonathannorris commented Aug 31, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Resolved 20 open Dependabot security alerts by bumping vulnerable dependencies (lockfile-only bumps / npm overrides, no manifest-breaking changes)

Dependabot Alerts Resolved

Alert Package Severity Fix
#229 react-router-dom moderate Bumped to 6.30.6
#260 react-router-dom moderate Bumped to 6.30.6 (open redirect leading to XSS)
#259 toml high Override to ^4.1.2 (was 2.3.6, transitive via markdown-toc)
#257 fast-uri high Override to ^3.1.6
#256 fast-uri high Override to ^3.1.6
#255 fast-uri high Override to ^3.1.6
#250 fast-uri high Override to ^3.1.6
#251 browserslist high Override to ^4.28.7
#265 baseline-browser-mapping medium Fixed transitively by the browserslist override above (resolves to 2.11.21)
#254 qs medium Override bumped from ^6.15.2 to ^6.16.0
#253 qs medium Override bumped from ^6.15.2 to ^6.16.0
#249 postcss-selector-parser low Override to ^6.1.3 (6.x line)
#248 postcss-selector-parser low Scoped override under css-loader to ^7.1.3 (7.x line)
#261 multer high Override bumped from ^2.2.0 to ^2.3.0 (DoS via file descriptor leak on aborted uploads)
#268 multer high Override bumped from ^2.2.0 to ^2.3.0 (DoS via oversized array index in field names)
#269 multer low Override bumped from ^2.2.0 to ^2.3.0 (file size limit bypass via async fileFilter race)
#270 multer high Override bumped from ^2.2.0 to ^2.3.0 (DoS via crafted multipart field names)
#263 svgo medium New override to ^3.3.5 (removeScripts incomplete sanitization of executable HTML)
#264 svgo high New override to ^3.3.5 (removeScripts allows executable links via namespace/control-char bypass)
#266 js-yaml high Override range extended to js-yaml@>=4.0.0 <4.3.2 -> ^4.3.2
#267 js-yaml high Override range extended to js-yaml@>=3.0.0 <3.15.2 -> ^3.15.2

Note on postcss-selector-parser: two majors are intentionally in play; the root override stays on 6.x because other direct consumers require the v6 API, while css-loader's internal postcss-modules-* plugins require v7. A single global major would break one side or the other, so the fix is scoped rather than unified.

Deferred / Unresolvable

Verified locally: build, lint, and test all pass with npm install --legacy-peer-deps (matching CI's install flags).

2026-09-20 weekly check-in

Re-fetched all 23 open Dependabot alerts and re-verified against this branch:

@coderabbitai

coderabbitai Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: e07a0651-75c0-47e2-92d0-50ec3fe8b195

📥 Commits

Reviewing files that changed from the base of the PR and between d2a331b and 270fcc5.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8f82567d-6902-4985-a68a-3297bc9e1b0f

📥 Commits

Reviewing files that changed from the base of the PR and between 6e91120 and d2a331b.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The package manifest updates react-router-dom and multiple dependency override constraints, including qs, multer, js-yaml, and six newly overridden packages.

Changes

Dependency updates

Layer / File(s) Summary
React Router DOM version
package.json
The dependency constraint changes from ^6.30.3 to ^6.30.6.
Package override constraints
package.json
The manifest updates qs, multer, and both js-yaml constraints. It adds overrides for fast-uri, browserslist, svgo, postcss-selector-parser, css-loader, and toml. The css-loader override includes a nested postcss-selector-parser constraint.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning Issue #229 requires @splitsoftware/splitio-browserjs to change from 0.9.5 to 0.9.6. The reviewed package.json changes do not include this dependency. package-lock.json is excluded from revie… Update @splitsoftware/splitio-browserjs to 0.9.6. Provide reviewable dependency evidence outside the excluded package-lock.json, or make the relevant lockfile evidence available for review.
Out of Scope Changes check ⚠️ Warning Issue #229 covers only the @splitsoftware/splitio-browserjs update. The pull request instead changes react-router-dom, qs, multer, js-yaml, and multiple dependency overrides. No directly lin… Remove the unrelated dependency and override changes, or link the issues that require them and assess this pull request against those issues.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: resolving open Dependabot security alerts through dependency updates.
Description check ✅ Passed The description directly explains the dependency updates, resolved security alerts, deferred alerts, and validation results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Full details: Linked Issues check

Explanation

Issue #229 requires @splitsoftware/splitio-browserjs to change from 0.9.5 to 0.9.6. The reviewed package.json changes do not include this dependency. package-lock.json is excluded from review, so its resolved version cannot establish compliance.

Full details: Out of Scope Changes check

Explanation

Issue #229 covers only the @splitsoftware/splitio-browserjs update. The pull request instead changes react-router-dom, qs, multer, js-yaml, and multiple dependency overrides. No directly linked issue establishes these changes as required by #229.


Comment @coderabbitai help to get the list of available commands.

@jonathannorris
jonathannorris marked this pull request as ready for review August 31, 2026 14:17
@jonathannorris
jonathannorris marked this pull request as draft September 8, 2026 13:54
auto-merge was automatically disabled September 8, 2026 13:54

Pull request was converted to draft

@jonathannorris
jonathannorris requested a balanced review from Copilot September 8, 2026 13:54
@jonathannorris
jonathannorris marked this pull request as ready for review September 8, 2026 13:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Pull request overview

Resolves a Dependabot security alert by upgrading routing dependencies, with additional dependency override adjustments in package.json.

Changes:

  • Bumped react-router-dom to ^6.30.6.
  • Bumped qs to ^6.16.0.
  • Added multiple new dependency overrides (e.g., fast-uri, browserslist, postcss-selector-parser, toml, and a scoped override for css-loader).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
@jonathannorris
jonathannorris marked this pull request as draft September 15, 2026 11:26
@jonathannorris
jonathannorris marked this pull request as ready for review September 21, 2026 01:17
- react-router-dom 6.30.4 -> 6.30.6 (moderate, alert #229; open redirect leading to XSS)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- qs 6.15.2 -> 6.16.0 (medium, alerts #253/#254; array-limit bypass and DoS via isBuffer)
- fast-uri 3.1.5 -> 3.1.6+ (high, alerts #250/#255/#256/#257; SSRF/host-confusion issues)
- browserslist 4.28.2 -> 4.28.7+ (high, alert #251; crash/prototype write via untrusted stats)
- postcss-selector-parser 6.1.2 -> 6.1.3+ and 7.1.1 -> 7.1.3+ (low, alerts #248/#249; ReDoS via AST recursion)
- toml 2.3.6 -> 4.1.2+ (high, alert #259; prototype pollution via __proto__ key-path)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- multer 2.2.0 -> 2.3.0+ (override) (high/low, alerts #261/#268/#269/#270; DoS via fd leak, oversized array index, and crafted multipart field names, plus fileFilter race condition)
- svgo 3.3.4 -> 3.3.5 (new override) (medium/high, alerts #263/#264; removeScripts incomplete sanitization of executable HTML/links in SVG foreignObject elements)
- js-yaml 4.3.1 -> 4.3.2+, 3.15.1 -> 3.15.2+ (override range extended) (high, alerts #266/#267; maxTotalMergeKeys does not limit CPU use for empty merge sources)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants