Skip to content

chore: resolve open dependabot security alerts - #255

Open
jonathannorris wants to merge 4 commits into
mainfrom
chore/dependabot-alerts
Open

jonathannorris wants to merge 4 commits into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris

@jonathannorris jonathannorris commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Resolved 8 open Dependabot security alerts in test/angular-integration by bumping vulnerable npm dependencies

Dependabot Alerts Resolved

Alert Package Severity Fix
#77 fast-uri high Bumped override to 3.1.6
#78 fast-uri high Bumped override to 3.1.6
#79 fast-uri high Bumped override to 3.1.6
#80 fast-uri high Bumped override to 3.1.6
#82 browserslist high Added override pinning to 4.28.7
#83 @vitest/mocker medium Bumped to 4.1.11
#84 vitest medium Bumped to 4.1.11
#85 baseline-browser-mapping medium Resolved to 2.11.21 (satisfies patched range via lockfile refresh)

🤖 Generated with Claude Code

@jonathannorris
jonathannorris marked this pull request as draft September 8, 2026 14:01
@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 59bff4eb-a393-4a84-b49b-0fac3845756e
📥 Commits

Reviewing files that changed from the base of the PR and between 337c4bb and 31aa07c.

⛔ Files ignored due to path filters (1)
  • test/angular-integration/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • test/angular-integration/package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Angular integration package configuration pins browserslist to 4.28.7 and updates the fast-uri override to 3.1.7. The esbuild override remains unchanged.

Changes

Angular integration dependencies

Layer / File(s) Summary
Update dependency overrides
test/angular-integration/package.json
Pins browserslist to 4.28.7 and updates fast-uri from 3.1.5 to 3.1.7. The esbuild override remains ^0.28.1.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 31aa0

The Angular integration dependency pins match their lockfile resolutions. No actionable issue is identified before merge.

Architecture Summary

Architecture risk: 🔵 Low · up to 31aa0

The change affects 1 system.

Changed systems: test

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — test (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in test/angular-integration/package.json: The overrides add browserslist pinned to 4.28.7 and update fast-uri from 3.1.5 to 3.1.7; the esbuild override remains ^0.28.1.
🚥 Pre-merge checks | ✅ 4 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Out of Scope Changes check ❓ Inconclusive The reviewed package.json changes update fast-uri and add the browserslist override. Both changes match the PR's dependency-alert remediation intent. The PR also reports lockfile changes, but `t… A reviewable summary or diff of the excluded lockfile changes is needed to determine whether they include changes unrelated to the reported dependency alerts.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title describes the dependency updates as resolving Dependabot security alerts, which matches the main purpose of the changeset.
Description check ✅ Passed The description discusses Dependabot alerts and npm dependency updates in the same Angular integration package, so it is related to the changeset.
Linked Issues check ✅ Passed The only directly linked issue, #77, is closed. It supplies historical context only. No active directly linked issue imposes coding requirements.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Full details: Out of Scope Changes check

Explanation

The reviewed package.json changes update fast-uri and add the browserslist override. Both changes match the PR's dependency-alert remediation intent. The PR also reports lockfile changes, but test/angular-integration/package-lock.json is excluded by !**/package-lock.json and is not represented in the summary. Its contents are needed to determine whether those changes stay within scope.


Comment @coderabbitai help to get the list of available commands.

@jonathannorris
jonathannorris marked this pull request as ready for review September 8, 2026 18:40
@jonathannorris
jonathannorris marked this pull request as draft September 15, 2026 11:23
@jonathannorris
jonathannorris requested a balanced review from Copilot September 21, 2026 01:14
@jonathannorris
jonathannorris marked this pull request as ready for review September 21, 2026 01:14

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The security overrides and resolved lockfile entries are consistent and compatible with their dependency constraints.

Review effort: Balanced
Findings: None

What changed in this PR

Updates Angular integration dependencies to resolve reported security alerts.

Changes:

  • Pins browserslist to 4.28.7.
  • Upgrades fast-uri to 3.1.6.
  • Refreshes the lockfile and related transitive dependencies.
File Description
test/​angular-integration/​package.json Adds secure dependency overrides.
test/​angular-integration/​package-lock.json Locks updated dependency versions and integrity metadata.
Files not reviewed (1)
  • test/angular-integration/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

- fast-uri 3.1.5 -> 3.1.6 (high, alerts #77 #78 #79 #80: host confusion / SSRF via IDN and percent-decoding issues)
- browserslist transitive -> 4.28.7 via override (high, alert #82: crash / prototype write via untrusted browserslist-stats.json)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- vitest 4.1.8 -> 4.1.11 (medium, alert #84)
- @vitest/mocker 4.1.8 -> 4.1.11 (medium, alert #83)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants