chore: resolve open dependabot security alerts - #255
jonathannorris wants to merge 2 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Angular integration package configuration pins ChangesAngular integration dependencies
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This updates the Angular integration dependency resolutions to patched browserslist and fast-uri versions. The pinned versions are reflected in the lockfile, with no current merge-blocking risk identified. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The security overrides and resolved lockfile entries are consistent and compatible with their dependency constraints.
Review effort: Balanced
Findings: None
What changed in this PR
Updates Angular integration dependencies to resolve reported security alerts.
Changes:
- Pins
browserslistto 4.28.7. - Upgrades
fast-urito 3.1.6. - Refreshes the lockfile and related transitive dependencies.
| File | Description |
|---|---|
test/angular-integration/package.json |
Adds secure dependency overrides. |
test/angular-integration/package-lock.json |
Locks updated dependency versions and integrity metadata. |
Files not reviewed (1)
- test/angular-integration/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- fast-uri 3.1.5 -> 3.1.6 (high, alerts #77 #78 #79 #80: host confusion / SSRF via IDN and percent-decoding issues) - browserslist transitive -> 4.28.7 via override (high, alert #82: crash / prototype write via untrusted browserslist-stats.json) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
fc68400 to
f631bb9
Compare
Summary
test/angular-integrationby bumping vulnerable npm dependenciesDependabot Alerts Resolved
fast-urifast-urifast-urifast-uribrowserslist@vitest/mockervitestbaseline-browser-mapping🤖 Generated with Claude Code