fix(deps): resolve all 47 open Dependabot alerts - #140
Open
sachin-panayil wants to merge 2 commits into
Open
Conversation
Consolidates the five open npm Dependabot PRs (#114, #115, #116, #117, #121) with a full lockfile re-resolve, clearing every open alert (npm audit: 0 vulnerabilities, was 1 critical / 11 high / 15 moderate / 2 low). Production: - @actions/core 1.11.1 -> 3.0.0 (#117). Pulls @actions/http-client 4.x, moving the shipped action off the vulnerable undici 5 line. v3 is ESM-only, which this package already is (type: module, rollup format es). - octokit-plugin-create-pull-request 6.0.0 -> 6.0.1 (#114) Development: - @github/local-action 2.6.1 -> 7.0.0 (#115), root cause of ~9 alerts through @actions/artifact's old @octokit/* chain - @jest/globals 29.7.0 -> 30.2.0 (#116) - the 13 npm-development group bumps from #121, including rollup 4.60.0 which clears GHSA-mw96-cpmx-2vgc - drop prettier-eslint: unreferenced by any script or config, and the only source of the minimatch 9.0.x ReDoS alerts via a pinned old @typescript-eslint/typescript-estree Adds an overrides entry for undici ^6.28.0. Nothing upstream ships a patched undici in the @actions/artifact -> @actions/github 6.x subtree (npm audit fix --force only offers a downgrade to the also-vulnerable @github/local-action 5.2.0). With @actions/core 3 this stays within the ^6.23.0 range every production package declares. Remove the override once @actions/artifact ships a subtree on undici >= 6.28.0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
natalialuzuriaga
approved these changes
Aug 18, 2026
natalialuzuriaga
left a comment
Contributor
There was a problem hiding this comment.
LOVE IT LGTM! Very important as you prep AGC for a new release!!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Clears all 47 open Dependabot alerts on
devin a single lockfile re-resolve.npm auditgoes from 1 critical / 11 high / 15 moderate / 2 low tofound 0 vulnerabilities.Only
package.jsonandpackage-lock.jsonchange — no source changes.dist/is not tracked (the Docker image runsnpm run bundleat build time), so nothing needs re-bundling here.Supersedes
Consolidates the five open npm Dependabot PRs — Dependabot will close them automatically once this merges:
octokit-plugin-create-pull-request6.0.0 → 6.0.1@github/local-action2.6.1 → 7.0.0@jest/globals29.7.0 → 30.2.0@actions/core1.11.1 → 3.0.0The four GitHub Actions PRs (#109, #110, #111, #112) are workflow-file-only and are not included — they can be merged independently. Note #110 patches
.github/workflows/update-codejson-schema.yml, which #138 deletes; if #138 lands first, close #110 as obsolete.Major bumps and why they're needed
@actions/core1.11.1 → 3.0.0 (production) — pulls@actions/http-client4.x, which depends onundici ^6.23.0, moving the shipped action off the vulnerable undici 5 line. v3 is ESM-only; this package is already"type": "module"and rollup emitsformat: "es", so no source change was required. Verified vianpm testandnpm run package.@github/local-action2.6.1 → 7.0.0 (dev) — root cause of ~9 alerts through@actions/artifact's pinned old@octokit/*chain.@jest/globals29.7.0 → 30.2.0 (dev) — all 270 tests pass againstjest@29, matching the CI result on #116.Beyond the Dependabot PRs
Dropped
prettier-eslint— not referenced by any script or config (format:write/lintcallprettierandeslintdirectly), and it was the sole source of theminimatch9.0.x ReDoS alerts via a pinned old@typescript-eslint/typescript-estree.Added an
overridesentry:Nothing upstream ships a patched undici inside the
@actions/artifact→@actions/github6.x subtree;npm audit fix --forceonly offers a downgrade to@github/local-action@5.2.0, which is itself vulnerable. Paired with@actions/core3, this override stays within the^6.23.0range every production package already declares, so the shipped action is not forced across a major. It does lift@actions/artifact's@actions/github@6.0.1(declares^5.25.4) to undici 6 — dev-only, exercised solely bynpm run local-action, which was smoke-tested.Removal condition: drop the override once
@actions/artifactships a subtree on undici ≥ 6.28.0.Verification
npm auditfound 0 vulnerabilitiesnpm cinpm testnpm run lintcoverage/)npm run packagedist/index.jsbuiltnpx local-actionnpm ls undicinpx prettier --checkflags 14 files, but those same 14 files fail identically under the previousprettier@3.4.2— pre-existing ondev, untouched here to keep this diff to dependencies only.Node 20 remains supported throughout (
@github/local-action@7is the tightest constraint at^20 || ^22 || ^24).🤖 Generated with Claude Code