Skip to content

build(deps): fix dependabot vulnerabilities - #183

Open
soyuka wants to merge 1 commit into
mainfrom
fix/dependabot-vulnerabilities
Open

soyuka wants to merge 1 commit into
mainfrom
fix/dependabot-vulnerabilities

Conversation

@soyuka

@soyuka soyuka commented Sep 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Bump jsonld ^8.3.3 → ^9.0.0 to unlock a patched undici via @digitalbazaar/http-client. The 8.x chain was stuck on undici@5.29.0 (the newest 5.x), which never received these CVE fixes — fixes only shipped in the 6.x line. Verified this codebase's only touchpoint is jsonld.expand() with a documentLoader, plus type-only imports from jsonld/jsonld-spec.js; jsonld 9's breaking changes (Node 18+, dropped application/nquads alias, canonicalization algorithm change) don't affect that usage.
  • Bump vitest / @vitest/coverage-v8 3.2.4 → ^4.1.11 (minimum version patching the @vitest/mocker path-traversal advisory), which also resolves transitive postcss/nanoid alerts.
  • Bump knip ^5.62.0 → ^6.38.0 for js-yaml, smol-toml, and picomatch alerts.

pnpm audit: 38 advisories (19 high / 16 moderate / 3 low) → 1 low remaining.

Residual

One low-severity alert is left unresolved: esbuild@0.27.7 (needs >=0.28.1, GHSA-g7r4-m6w7-qqqr — arbitrary file read when running Vite's dev server on Windows). It comes in transitively via vitest → vite@7.3.5, which pins esbuild@^0.27.0. vite only appears here as a peer dependency, so a pnpm.overrides bump to vite@8 (which drops esbuild) doesn't take effect without fighting pnpm's peer resolution. This project never runs Vite's dev server (only Vitest's internal test runner uses it), and the vector is Windows-only, so it's left as a documented residual rather than force an unstable override.

Test plan

  • tsc --noEmit (typecheck) — clean
  • oxlint — 0 warnings/errors
  • vitest run — 6 files, 33/33 tests passed
  • tsc --project tsconfig.build.json (build) — clean
  • pnpm audit — confirmed 38 → 1 advisories

🤖 Generated with Claude Code

Bump jsonld to 9.0.0 to unlock a patched undici via
@digitalbazaar/http-client (the 8.x chain was stuck on the
unpatched undici 5.x line). Bump vitest and @vitest/coverage-v8
to 4.1.11 for the @vitest/mocker path-traversal advisory, and
knip to 6.38.0 for js-yaml/smol-toml/picomatch.

pnpm audit: 38 advisories (19 high/16 moderate/3 low) -> 1 low
(esbuild via vite's dev server, unused in this project, not
resolvable without an unstable peer override).
@github-actions

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🟢 Lines 71.82% (🎯 70%) 311 / 433
🟢 Statements 71.78% (🎯 70%) 313 / 436
🟢 Functions 70.76% (🎯 70%) 46 / 65
🟢 Branches 60.83% (🎯 58%) 247 / 406
File CoverageNo changed files found.
Generated in workflow #331 for commit 4a1618e by the Vitest Coverage Report Action

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant