Skip to content

fix(deps): close the 15 open Dependabot alerts on undici, brace-expansion and fast-uri - #166

Merged
GeiserX merged 1 commit into
mainfrom
fix/dependabot-2026-09-30
Sep 30, 2026
Merged

GeiserX merged 1 commit into
mainfrom
fix/dependabot-2026-09-30

Conversation

@GeiserX

@GeiserX GeiserX commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Dependabot listed 15 open alerts, all in the lockfile and all in dev-only packages: undici 7 (through jsdom), undici 8 (through testcontainers), brace-expansion (through eslint's minimatch) and fast-uri (through prisma's ajv). Two of the undici ones are high: a TLS certificate validation bypass in BalancedPool and cross-origin cache poisoning.

The root cause of the undici 7 alerts was our own override. jsdom 30.1 already depends on undici 8, and the nested jsdom: { undici: ^7.28.0 } override was forcing it back down to a major that has no reason to be in the tree. Both parents now want undici 8, so one flat undici: ^8.10.2 override replaces the two nested ones. brace-expansion and fast-uri get their patched floors (5.0.12 and 3.1.8).

Verified locally: npm audit reports 0 vulnerabilities, tsc is clean, and the jsdom component tests pass on undici 8. The runtime image is unaffected because none of the four packages is a production dependency.

Supersedes #164, which only bumped the undici 7 line.

Summary by CodeRabbit

  • Chores
    • Updated underlying components for pattern expansion, URI handling, and network requests. Network request version selection is now consistent across the application rather than separately specified for individual testing tools. These are maintenance changes; no user-facing feature changes are included.

…sion and fast-uri

jsdom 30.1 moved to undici 8, so the nested jsdom override that pinned
undici 7 was holding back a vulnerable major nobody needs any more. Both
parents (jsdom and testcontainers) now want undici 8, so a single flat
override to ^8.10.2 replaces the two nested ones. brace-expansion and
fast-uri get their patched floors. All three are dev-only; the runtime
image does not change. npm audit reports 0 vulnerabilities.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: GeiserX/Pumperly/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 6226e5ac-4f09-4c0a-ac4e-cc220785ea1d

📥 Commits

Reviewing files that changed from the base of the PR and between 2b6d91b and fe37f71.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json, !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The dependency overrides update brace-expansion and fast-uri versions. The nested undici overrides are removed, and a top-level undici override is added.

Changes

Dependency overrides

Layer / File(s) Summary
Update dependency overrides
package.json
The brace-expansion and fast-uri override versions are updated. Nested undici overrides for jsdom and testcontainers are replaced by a top-level undici override. Other listed overrides remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to fe37f

Both dependency consumers resolve to compatible undici versions, and this change adds no supported-runtime floor beyond the existing jsdom requirement. No actionable merge risk is established.

Architecture Summary

Architecture risk: 🔵 Low · up to fe37f

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: The brace-expansion and fast-uri override versions are updated. Nested undici overrides under jsdom and testcontainers are removed, and replaced with a top-level undici override at ^8.10.2; the other listed overrides remain unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically describes the dependency security updates for undici, brace-expansion, and fast-uri. These packages are the main focus of the changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@GeiserX
GeiserX merged commit 0689b08 into main Sep 30, 2026
10 checks passed
@GeiserX
GeiserX deleted the fix/dependabot-2026-09-30 branch September 30, 2026 13:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant