Skip to content

fix: resolve vulnerable transitive dependencies - #298

Merged
LadyBluenotes merged 4 commits into
mainfrom
fix/dependabot-vulnerabilities
Sep 30, 2026
Merged

LadyBluenotes merged 4 commits into
mainfrom
fix/dependabot-vulnerabilities

Conversation

@LadyBluenotes

@LadyBluenotes LadyBluenotes commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

Address all 15 open Dependabot alerts with overrides limited to vulnerable version ranges. Parent packages pin some affected versions, so a normal transitive update does not resolve every alert.

Package Vulnerable resolution Patched resolution
brace-expansion 1.1.18 / 5.0.9 1.1.21 / 5.0.12
fast-uri 3.1.6 3.1.8
js-yaml 5.2.2 5.4.1
qs 6.15.3 6.16.0
smol-toml 1.6.1 1.7.1
undici 7.29.0 7.29.1

Regenerate the lockfile with pnpm 11.9.0. Keep package manifests, unaffected resolutions, release-age limits, and supply-chain safeguards unchanged. Already safe versions remain unchanged.

Validation

  • pnpm audit: 23 advisories before; no known vulnerabilities after.
  • Checked every installed lockfile version against all 15 open Dependabot alert ranges: zero matches.
  • pnpm install --frozen-lockfile --registry=https://registry.npmjs.org/: passed.
  • NX_NO_CLOUD=true NX_DAEMON=false NX_SKIP_NX_CACHE=true pnpm test: all eight tasks passed, including types, lint, docs, unit tests, integration tests, and build.
  • pnpm exec prettier --check pnpm-workspace.yaml pnpm-lock.yaml: passed.
  • git diff --check: passed.
  • All 858 lockfile package entries use SHA-512 integrity; new artifact hashes match the official npm registry.

These are local validation results. Dependabot alerts remain open until the fix reaches the default branch and GitHub processes it.

CI failure and root-cause fix

The integration fixture installer assumed Yarn Classic, while CI runs Yarn 4.18.1. Classic-only flags caused YN0050 failures. After correcting the install configuration, Yarn's 24-hour release-age gate rejected the freshly published local fixtures with YN0016. Both failures were reproduced locally before their fixes.

  • Preserve Classic install behavior; use modern Yarn configuration for modern Yarn.
  • Isolate tarball and registry metadata caches per fixture to avoid stale local-registry ports.
  • Exempt only @test-intent/*@1.0.0 in generated fixture configuration. Real dependency policies are unchanged.
  • Stream Nx output into GitHub Actions logs so errors remain visible.

Verification: 60 Classic/npm/pnpm/bun cases passed. With CI Yarn 4.18.1 and hardened mode enabled, 57 cases passed; three existing Classic-only PnP cases were skipped. A negative control verified the 1440-minute age gate and hardened mode remain enabled, and a fixture outside the approved version remains quarantined. Lint, typecheck, formatting, and diff checks passed.

GitHub Actions run 36669819694 passed both Test and Preview at 7d0e9fc. The separate benchmark was still pending at verification time.

Summary by CodeRabbit

  • Chores
    • Updated several supporting components to patched versions while preserving existing version settings. These maintenance updates do not introduce user-facing changes. The pull request’s test workflow also now streams its output, making test progress visible during automated runs.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 34 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: dff9d0dc-0a53-4f93-930f-fdf5163ed5d6

📥 Commits

Reviewing files that changed from the base of the PR and between 48855b3 and c407b1e.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • .github/workflows/pr.yml
  • packages/intent/tests/integration/scaffold.ts
  • pnpm-workspace.yaml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1aca6df2-2ecc-482e-8a8c-63673785a8c9

📥 Commits

Reviewing files that changed from the base of the PR and between edcc844 and 48855b3.

📒 Files selected for processing (1)
  • .github/workflows/pr.yml

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The workspace configuration adds version-range overrides for six dependencies. The PR workflow adds the --outputStyle=stream option to its test command.

Changes

Dependency Version Overrides

Layer / File(s) Summary
Add dependency version overrides
pnpm-workspace.yaml
Adds overrides that map specified version ranges for brace-expansion, fast-uri, js-yaml, qs, smol-toml, and undici to patched versions.

PR Test Output

Layer / File(s) Summary
Set PR test output style
.github/workflows/pr.yml
Adds --outputStyle=stream to the PR workflow test command.

Priority: ⬆️ High

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: alemtuzlak

Merge Risk: ⚪ Minimal · up to 48855

The dependency overrides select the intended patched versions, and the PR workflow retains streamed test output. No material change-specific merge risk is evident; the change is ready after normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to edcc8

The change affects 1 system.

Changed systems: pnpm-workspace.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — pnpm-workspace.yaml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in pnpm-workspace.yaml: Adds overrides for brace-expansion versions below 1.1.21, fast-uri versions from 3.0.0 up to but excluding 3.1.8, and js-yaml versions from 5.0.0 up to but excluding 5.4.1, setting each to the corresponding minimum patched version.
  • observed — Modified behavior in pnpm-workspace.yaml: Adds overrides for qs versions from 2.2.5 up to but excluding 6.16.0, smol-toml versions at or below 1.7.0, and undici versions from 7.0.0 up to but excluding 7.29.1, setting each to the corresponding patched version.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the main change: resolving vulnerable transitive dependencies.
Description check ✅ Passed The description clearly explains the dependency overrides, validation results, CI fixes, and release-related constraints. It does not use the template headings or include the checklist and release-imp…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nx-cloud

nx-cloud Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit edcc844

Command Status Duration Result
nx run-many --targets=build ✅ Succeeded 3s View ↗
nx affected --targets=test:eslint,test:sherif,t... ✅ Succeeded 3s View ↗

☁️ Nx Cloud last updated this comment at 2026-09-30 04:47:50 UTC

@pkg-pr-new

pkg-pr-new Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@tanstack/intent@298

commit: c407b1e

@LadyBluenotes
LadyBluenotes requested a review from a team as a code owner September 30, 2026 04:27
@codspeed

codspeed Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 12 untouched benchmarks


Comparing fix/dependabot-vulnerabilities (c407b1e) with main (3cf6c14)

Open in CodSpeed

Use modern Yarn configuration instead of Classic-only install flags and isolate registry metadata per fixture. Preserve Classic behavior and print CI task output directly in GitHub Actions.
Limit the exemption to @test-intent/*@1.0.0 in generated fixture configuration. Keep hardened mode and the release-age policy for real dependencies enabled.
@LadyBluenotes
LadyBluenotes force-pushed the fix/dependabot-vulnerabilities branch from 7d0e9fc to c407b1e Compare September 30, 2026 04:47
@LadyBluenotes
LadyBluenotes merged commit 4fbc23c into main Sep 30, 2026
10 checks passed
@LadyBluenotes
LadyBluenotes deleted the fix/dependabot-vulnerabilities branch September 30, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants