Repository navigation
fix(DEV-1693): bump vulnerable npm dependencies in pnpm-lock.yaml - #73
Open
joshglasspool wants to merge 1 commit into
Open
joshglasspool wants to merge 1 commit into
joshglasspool wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
This PR replaces the 17 open spur-vuln-author PRs (#56–#72) with one change. All of them edit
pnpm-lock.yaml, and 15 add a rootpnpm.overridesblock in the same place inpackage.json, so merging them one at a time would force the rest to be rebuilt and re-approved after every merge. It also lands thenext15.5.24 bump that DEV-1693 records as blocked on tooling. No bot PR existed for it.The bot PRs' changes are merged into one
pnpm.overridesblock, and the lockfile is regenerated once withpnpm@10.8.0(thepackageManagerpin). Re-checking the live Dependabot alerts on 2026-10-01 led to some deliberate departures from the bot PRs.Overrides scoped by major line, so no consumer is moved across a major version:
brace-expansion@1/@2: fix(dev-1701): bump brace-expansion to 2.1.2 #65 forced every 1.x consumer onto 2.x.glob@10/@11: fix(dev-1715): bump glob to 10.5.0 #67'sglob@<10.5.0would have forced glob 7 onto 10.esbuild@0.27: fix(dev-1716): bump esbuild to 0.28.1 #71's unscoped override would also have moved tsup's esbuild 0.25.Overrides for vulnerable lines the bot PRs left open:
glob@11^11.1.0,minimatch@9^9.0.7,minimatch@10^10.2.3andjs-yaml@3^3.15.2.Other changes:
packages/monocle-backend: devDependencyvitest^1.3.1→^4.1.11. This clears the critical vitest alert (<3.2.6) and removes the vite 5 / esbuild 0.21 tree behind the vite and esbuild alerts.@vitejs/plugin-react^4.4.1→^4.7.0, the first 4.x whose peer range includes vite 7, now that vite 5 is gone. It also moves@babel/coreto 7.29.7.monocle-backend's manifest changed but nothing published changes.Checked against the lockfile, this clears all 81 open alerts, 5 of them critical. glob 7.2.3 stays, because no open alert covers it.
Fixes DEV-1693, DEV-1687, DEV-1695, DEV-1696, DEV-1698, DEV-1699, DEV-1700, DEV-1701, DEV-1702, DEV-1705, DEV-1707, DEV-1709, DEV-1711, DEV-1712, DEV-1713, DEV-1714, DEV-1715, DEV-1716
Supersedes #56, #57, #58, #59, #60, #61, #62, #63, #64, #65, #66, #67, #68, #69, #70, #71, #72. Close them once this merges.
Test evidence
Run locally with Node 25.2.1 and
npx pnpm@10.8.0, following the steps inci.yml:pnpm install --lockfile-onlyon unmodifiedmain: no lockfile drift. Regenerating twice frommain's lockfile gives identical output.pnpm install --frozen-lockfile: OKpnpm lint: OKpnpm build: OK, 5/5 turbo taskspnpm changeset status --since=origin/main: OK, no packages to bumppnpm test: OK. monocle-backend 9/9 tests pass on vitest 4, and monocle-react 7/7.vulnerable_version_range: 0 remaining.CI (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check) runs on this PR. CI uses Node 22, while the local runs used Node 25.
Risk
Medium. This is a dependency-only change with no source edits, but it is broad. The notable moves:
vitestgoes 1 → 4 (dev only; its tests pass).tmpgoes 0.0.33 → 0.2.7, the only patched line.nextpeer used to build monocle-nextjs goes 15.3 → 15.5.Published package contents do not change. No published package's
dependenciesorpeerDependenciesmove, and everypackages/*/distbuilds byte-identical tomain(built both and diffed). pnpm reports one cosmetic peer warning:bundle-require(inside tsup) showsesbuild@^0.28.1unmet against 0.25.2, because the scoped override also rewrites its>=0.18peer range. Its real peer range is satisfied, and the build passes.🤖 Generated with Claude Code