chore: resolve open dependabot security alerts - #426
jonathannorris wants to merge 5 commits into
Conversation
|
Important Review skippedReview was skipped as selected files did not have any reviewable changes. ⛔ Files ignored due to path filters (1)
⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe package manifest updates ChangesDependency updates
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Linked Issues checkExplanation Issue Full details: Out of Scope Changes checkExplanation Issue Comment |
Pull request was converted to draft
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Pull request overview
Resolves a Dependabot security alert by upgrading routing dependencies, with additional dependency override adjustments in package.json.
Changes:
- Bumped
react-router-domto^6.30.6. - Bumped
qsto^6.16.0. - Added multiple new dependency overrides (e.g.,
fast-uri,browserslist,postcss-selector-parser,toml, and a scoped override forcss-loader).
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
6e91120 to
d2a331b
Compare
- react-router-dom 6.30.4 -> 6.30.6 (moderate, alert #229; open redirect leading to XSS) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- qs 6.15.2 -> 6.16.0 (medium, alerts #253/#254; array-limit bypass and DoS via isBuffer) - fast-uri 3.1.5 -> 3.1.6+ (high, alerts #250/#255/#256/#257; SSRF/host-confusion issues) - browserslist 4.28.2 -> 4.28.7+ (high, alert #251; crash/prototype write via untrusted stats) - postcss-selector-parser 6.1.2 -> 6.1.3+ and 7.1.1 -> 7.1.3+ (low, alerts #248/#249; ReDoS via AST recursion) - toml 2.3.6 -> 4.1.2+ (high, alert #259; prototype pollution via __proto__ key-path) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- multer 2.2.0 -> 2.3.0+ (override) (high/low, alerts #261/#268/#269/#270; DoS via fd leak, oversized array index, and crafted multipart field names, plus fileFilter race condition) - svgo 3.3.4 -> 3.3.5 (new override) (medium/high, alerts #263/#264; removeScripts incomplete sanitization of executable HTML/links in SVG foreignObject elements) - js-yaml 4.3.1 -> 4.3.2+, 3.15.1 -> 3.15.2+ (override range extended) (high, alerts #266/#267; maxTotalMergeKeys does not limit CPU use for empty merge sources) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
d2a331b to
270fcc5
Compare
Summary
Dependabot Alerts Resolved
react-router-domreact-router-domtomlfast-urifast-urifast-urifast-uribrowserslistbaseline-browser-mappingbrowserslistoverride above (resolves to 2.11.21)qsqspostcss-selector-parserpostcss-selector-parsercss-loaderto ^7.1.3 (7.x line)multermultermultermultersvgosvgojs-yamljs-yaml@>=4.0.0 <4.3.2->^4.3.2js-yamljs-yaml@>=3.0.0 <3.15.2->^3.15.2Deferred / Unresolvable
react-router(moderate) — patched version is7.18.0, which requires bumpingreact-router-domto v7. That in turn requires React 17 -> 18 (this repo is pinned toreact@^17.0.2), a breaking peer-dependency change plus router API migration. Deferred to a dedicated migration.nx(medium) — patched version22.7.2is 4+ majors ahead of the pinnednx/@nx/*toolchain (17.3.2/18.3.5) and would require a fullnx migrateacross the monorepo. The advisory affects thenx graphdev server's permissive CORS policy, which this repo's scripts never invoke, so practical risk is low. Note: a separate Renovate PR (fix(security): update dependency nx to v22 [security] #424) already targets this.Verified locally:
build,lint, andtestall pass withnpm install --legacy-peer-deps(matching CI's install flags).2026-09-20 weekly check-in
Re-fetched all 23 open Dependabot alerts and re-verified against this branch:
react-router) and Broken link to after hook #233 (nx) remain deferred for the reasons above; no new patched-but-safe version is available yet.main(30 commits, mostly Renovate bumps) and refreshedpackage-lock.jsonaccordingly; re-ranbuild,lint, andtest— all pass.