Skip to content

fix(deps): resolve all 47 open Dependabot alerts - #140

Open
sachin-panayil wants to merge 2 commits into
devfrom
sachin/dependabot-security-refresh
Open

fix(deps): resolve all 47 open Dependabot alerts#140
sachin-panayil wants to merge 2 commits into
devfrom
sachin/dependabot-security-refresh

Conversation

@sachin-panayil

Copy link
Copy Markdown
Collaborator

Summary

Clears all 47 open Dependabot alerts on dev in a single lockfile re-resolve. npm audit goes from 1 critical / 11 high / 15 moderate / 2 low to found 0 vulnerabilities.

Only package.json and package-lock.json change — no source changes. dist/ is not tracked (the Docker image runs npm run bundle at build time), so nothing needs re-bundling here.

Supersedes

Consolidates the five open npm Dependabot PRs — Dependabot will close them automatically once this merges:

The four GitHub Actions PRs (#109, #110, #111, #112) are workflow-file-only and are not included — they can be merged independently. Note #110 patches .github/workflows/update-codejson-schema.yml, which #138 deletes; if #138 lands first, close #110 as obsolete.

Major bumps and why they're needed

@actions/core 1.11.1 → 3.0.0 (production) — pulls @actions/http-client 4.x, which depends on undici ^6.23.0, moving the shipped action off the vulnerable undici 5 line. v3 is ESM-only; this package is already "type": "module" and rollup emits format: "es", so no source change was required. Verified via npm test and npm run package.

@github/local-action 2.6.1 → 7.0.0 (dev) — root cause of ~9 alerts through @actions/artifact's pinned old @octokit/* chain.

@jest/globals 29.7.0 → 30.2.0 (dev) — all 270 tests pass against jest@29, matching the CI result on #116.

Beyond the Dependabot PRs

Dropped prettier-eslint — not referenced by any script or config (format:write/lint call prettier and eslint directly), and it was the sole source of the minimatch 9.0.x ReDoS alerts via a pinned old @typescript-eslint/typescript-estree.

Added an overrides entry:

"overrides": {
  "undici": "^6.28.0"
}

Nothing upstream ships a patched undici inside the @actions/artifact@actions/github 6.x subtree; npm audit fix --force only offers a downgrade to @github/local-action@5.2.0, which is itself vulnerable. Paired with @actions/core 3, this override stays within the ^6.23.0 range every production package already declares, so the shipped action is not forced across a major. It does lift @actions/artifact's @actions/github@6.0.1 (declares ^5.25.4) to undici 6 — dev-only, exercised solely by npm run local-action, which was smoke-tested.

Removal condition: drop the override once @actions/artifact ships a subtree on undici ≥ 6.28.0.

Verification

Check Result
npm audit found 0 vulnerabilities
npm ci clean install from the regenerated lockfile
npm test 270 passed, 3 suites
npm run lint 0 errors (2 pre-existing warnings in untracked coverage/)
npm run package dist/index.js built
npx local-action CLI loads under the undici override
npm ls undici every instance resolves to 6.28.0, prod tree included

npx prettier --check flags 14 files, but those same 14 files fail identically under the previous prettier@3.4.2 — pre-existing on dev, untouched here to keep this diff to dependencies only.

Node 20 remains supported throughout (@github/local-action@7 is the tightest constraint at ^20 || ^22 || ^24).

🤖 Generated with Claude Code

sachin-panayil and others added 2 commits August 18, 2026 14:12
Consolidates the five open npm Dependabot PRs (#114, #115, #116, #117,
#121) with a full lockfile re-resolve, clearing every open alert
(npm audit: 0 vulnerabilities, was 1 critical / 11 high / 15 moderate / 2 low).

Production:
- @actions/core 1.11.1 -> 3.0.0 (#117). Pulls @actions/http-client 4.x,
  moving the shipped action off the vulnerable undici 5 line. v3 is
  ESM-only, which this package already is (type: module, rollup format es).
- octokit-plugin-create-pull-request 6.0.0 -> 6.0.1 (#114)

Development:
- @github/local-action 2.6.1 -> 7.0.0 (#115), root cause of ~9 alerts
  through @actions/artifact's old @octokit/* chain
- @jest/globals 29.7.0 -> 30.2.0 (#116)
- the 13 npm-development group bumps from #121, including rollup 4.60.0
  which clears GHSA-mw96-cpmx-2vgc
- drop prettier-eslint: unreferenced by any script or config, and the
  only source of the minimatch 9.0.x ReDoS alerts via a pinned old
  @typescript-eslint/typescript-estree

Adds an overrides entry for undici ^6.28.0. Nothing upstream ships a
patched undici in the @actions/artifact -> @actions/github 6.x subtree
(npm audit fix --force only offers a downgrade to the also-vulnerable
@github/local-action 5.2.0). With @actions/core 3 this stays within the
^6.23.0 range every production package declares. Remove the override once
@actions/artifact ships a subtree on undici >= 6.28.0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

@natalialuzuriaga natalialuzuriaga left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LOVE IT LGTM! Very important as you prep AGC for a new release!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants