Skip to content

fix(DEV-1693): bump vulnerable npm dependencies in pnpm-lock.yaml - #73

Open
joshglasspool wants to merge 1 commit into
mainfrom
sec/dev-1693
Open

joshglasspool wants to merge 1 commit into
mainfrom
sec/dev-1693

Conversation

@joshglasspool

@joshglasspool joshglasspool commented Oct 1, 2026 •

Copy link
Copy Markdown

Context

This PR replaces the 17 open spur-vuln-author PRs (#56–#72) with one change. All of them edit pnpm-lock.yaml, and 15 add a root pnpm.overrides block in the same place in package.json, so merging them one at a time would force the rest to be rebuilt and re-approved after every merge. It also lands the next 15.5.24 bump that DEV-1693 records as blocked on tooling. No bot PR existed for it.

The bot PRs' changes are merged into one pnpm.overrides block, and the lockfile is regenerated once with pnpm@10.8.0 (the packageManager pin). Re-checking the live Dependabot alerts on 2026-10-01 led to some deliberate departures from the bot PRs.

Overrides scoped by major line, so no consumer is moved across a major version:

Overrides for vulnerable lines the bot PRs left open: glob@11 ^11.1.0, minimatch@9 ^9.0.7, minimatch@10 ^10.2.3 and js-yaml@3 ^3.15.2.

Other changes:

  • packages/monocle-backend: devDependency vitest ^1.3.1 → ^4.1.11. This clears the critical vitest alert (<3.2.6) and removes the vite 5 / esbuild 0.21 tree behind the vite and esbuild alerts.
  • Root devDependency @vitejs/plugin-react ^4.4.1 → ^4.7.0, the first 4.x whose peer range includes vite 7, now that vite 5 is gone. It also moves @babel/core to 7.29.7.
  • An empty changeset, because monocle-backend's manifest changed but nothing published changes.
Package From To
next (auto-installed peer of monocle-nextjs) 15.3.1 15.5.24
vitest 1.6.1, 3.2.6 4.1.11
@vitest/mocker 3.2.6 4.1.11
vite 5.4.21, 7.3.5 7.3.5
esbuild 0.21.5, 0.25.2, 0.27.7 0.25.2, 0.28.2
zx (catalog) 8.4.1 8.8.5
@humanfs/node 0.16.6 0.16.8
tmp 0.0.33 0.2.7
browserslist 4.24.4 4.29.3
lodash 4.17.21 4.18.1
ws 8.18.1 8.22.0
sharp 0.34.1 0.35.5
flatted 3.3.3 3.4.4
rollup 4.40.0, 4.61.1 4.61.1
brace-expansion 1.1.11, 2.0.1 1.1.21, 2.1.7 (plus 5.0.12 via minimatch 10)
postcss 8.4.31, 8.5.15 8.5.28
glob 7.2.3, 10.4.5, 11.0.2 7.2.3, 10.5.0, 11.1.0
minimatch 3.1.2, 9.0.5, 10.0.1 3.1.5, 9.0.9, 10.2.6
js-yaml 3.14.1, 4.1.0 3.15.2, 4.3.2
nanoid 3.3.11, 3.3.12 3.3.19
@vitejs/plugin-react 4.4.1 4.7.0
@babel/core 7.26.10 7.29.7

Checked against the lockfile, this clears all 81 open alerts, 5 of them critical. glob 7.2.3 stays, because no open alert covers it.

Fixes DEV-1693, DEV-1687, DEV-1695, DEV-1696, DEV-1698, DEV-1699, DEV-1700, DEV-1701, DEV-1702, DEV-1705, DEV-1707, DEV-1709, DEV-1711, DEV-1712, DEV-1713, DEV-1714, DEV-1715, DEV-1716

Supersedes #56, #57, #58, #59, #60, #61, #62, #63, #64, #65, #66, #67, #68, #69, #70, #71, #72. Close them once this merges.

Test evidence

Run locally with Node 25.2.1 and npx pnpm@10.8.0, following the steps in ci.yml:

  • pnpm install --lockfile-only on unmodified main: no lockfile drift. Regenerating twice from main's lockfile gives identical output.
  • pnpm install --frozen-lockfile: OK
  • pnpm lint: OK
  • pnpm build: OK, 5/5 turbo tasks
  • pnpm changeset status --since=origin/main: OK, no packages to bump
  • pnpm test: OK. monocle-backend 9/9 tests pass on vitest 4, and monocle-react 7/7.
  • Each package's resolved lockfile versions were checked against every open alert's vulnerable_version_range: 0 remaining.

CI (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check) runs on this PR. CI uses Node 22, while the local runs used Node 25.

Risk

Medium. This is a dependency-only change with no source edits, but it is broad. The notable moves:

  • monocle-backend's vitest goes 1 → 4 (dev only; its tests pass).
  • tmp goes 0.0.33 → 0.2.7, the only patched line.
  • The auto-installed next peer used to build monocle-nextjs goes 15.3 → 15.5.
  • The esbuild 0.27 → 0.28 move inside vite 7.

Published package contents do not change. No published package's dependencies or peerDependencies move, and every packages/*/dist builds byte-identical to main (built both and diffed). pnpm reports one cosmetic peer warning: bundle-require (inside tsup) shows esbuild@^0.28.1 unmet against 0.25.2, because the scoped override also rewrites its >=0.18 peer range. Its real peer range is satisfied, and the build passes.

🤖 Generated with Claude Code

@joshglasspool joshglasspool changed the title chore(dev-1693): bump vulnerable npm dependencies in pnpm-lock.yaml fix(DEV-1693): bump vulnerable npm dependencies in pnpm-lock.yaml Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant