Skip to content

fix: patch vulnerable transitive dependencies via yarn up - #1332

Merged
JeremyRH merged 1 commit into
masterfrom
fix-dependabot-security-vulnerabilities-4
Aug 6, 2026
Merged

fix: patch vulnerable transitive dependencies via yarn up#1332
JeremyRH merged 1 commit into
masterfrom
fix-dependabot-security-vulnerabilities-4

Conversation

@JeremyRH

@JeremyRH JeremyRH commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Description

This PR resolves open Dependabot security vulnerabilities by upgrading vulnerable transitive dependencies to patched versions.

Changes

  • Upgraded vulnerable dependencies to compatible patched versions
  • Updated yarn.lock with security patches (+921 -1095 lines)
  • No dependency overrides/resolutions used - only direct upgrades to available fixes
  • All breaking changes resolved by updating code as needed

Testing

  • Test suite passes
  • Project builds successfully
  • No new vulnerabilities introduced

Related Issues

Fixes open Dependabot security alerts


Agent session: https://supernova.dx.appf.io/coders/1eab8b55-5524-45eb-9838-292f422feb6b

Bumps tar, undici, ws, postcss, ajv, js-yaml, yaml, micromatch,
brace-expansion, diff, and @babel/* to patched versions within
existing semver ranges to resolve known CVEs (DoS, ReDoS, arbitrary
file read, cookie/CRLF injection).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Co-authored-by: Jeremy Holcomb <jeremy.holcomb@appfolio.com>
@JeremyRH JeremyRH self-assigned this Aug 5, 2026
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Released prerelease version 8.19.6-fix-dependabot-security-vulnerabilities-4-92b5417.0.
You may now run npm install @appfolio/react-gears@fix-dependabot-security-vulnerabilities-4

@supernova-dx-appf-io

Copy link
Copy Markdown

👀 Heads up: Supernova won't automatically act on bot reviews (like @github-actions[bot]). If you'd like me to evaluate or implement a suggestion, just reply here!

@JeremyRH
JeremyRH marked this pull request as ready for review August 5, 2026 23:37
@JeremyRH
JeremyRH requested a review from a team as a code owner August 5, 2026 23:37
@JeremyRH
JeremyRH merged commit a4db21c into master Aug 6, 2026
6 checks passed
@JeremyRH
JeremyRH deleted the fix-dependabot-security-vulnerabilities-4 branch August 6, 2026 01:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants