fix(deps): close the 15 open Dependabot alerts on undici, brace-expansion and fast-uri - #166
Conversation
…sion and fast-uri jsdom 30.1 moved to undici 8, so the nested jsdom override that pinned undici 7 was holding back a vulnerable major nobody needs any more. Both parents (jsdom and testcontainers) now want undici 8, so a single flat override to ^8.10.2 replaces the two nested ones. brace-expansion and fast-uri get their patched floors. All three are dev-only; the runtime image does not change. npm audit reports 0 vulnerabilities.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: GeiserX/Pumperly/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe dependency overrides update ChangesDependency overrides
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Both dependency consumers resolve to compatible undici versions, and this change adds no supported-runtime floor beyond the existing jsdom requirement. No actionable merge risk is established. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dependabot listed 15 open alerts, all in the lockfile and all in dev-only packages: undici 7 (through jsdom), undici 8 (through testcontainers), brace-expansion (through eslint's minimatch) and fast-uri (through prisma's ajv). Two of the undici ones are high: a TLS certificate validation bypass in BalancedPool and cross-origin cache poisoning.
The root cause of the undici 7 alerts was our own override. jsdom 30.1 already depends on undici 8, and the nested
jsdom: { undici: ^7.28.0 }override was forcing it back down to a major that has no reason to be in the tree. Both parents now want undici 8, so one flatundici: ^8.10.2override replaces the two nested ones. brace-expansion and fast-uri get their patched floors (5.0.12 and 3.1.8).Verified locally:
npm auditreports 0 vulnerabilities,tscis clean, and the jsdom component tests pass on undici 8. The runtime image is unaffected because none of the four packages is a production dependency.Supersedes #164, which only bumped the undici 7 line.
Summary by CodeRabbit