fix(FFESUPPORT-752): address open Dependabot vulnerabilities - #330
Conversation
There was a problem hiding this comment.
Pull request overview
Addresses Dependabot vulnerabilities by forcing the transitive fast-uri dependency to a patched version via a Yarn resolution, and refreshes lockfile entries for brace-expansion. Bumps the package patch version accordingly.
Changes:
- Adds
resolutionsentry pinningfast-urito^3.1.2to address GHSA-v39h-62p7-jpjc and GHSA-q3j6-qgpj-74h6. - Refreshes
brace-expansionlockfile entries (1.1.14→1.1.15, 2.1.0→2.1.1, 5.0.5→5.0.6). - Bumps package version 5.0.0 → 5.0.1.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| package.json | Bumps version to 5.0.1 and adds a Yarn resolutions block pinning fast-uri to ^3.1.2. |
| yarn.lock | Updates fast-uri to 3.1.2 and refreshes brace-expansion entries to patched versions. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
cbcb1a0 to
078a0d0
Compare
|
🤖 Context from Codex: This resolves the fast-uri alerts with a targeted Yarn resolution/lockfile refresh and patch version bump to 5.0.1. The public SDK API surface is unchanged. Local |
078a0d0 to
fd60f3b
Compare
| "webpack": "^5.107.2", | ||
| "webpack-cli": "^7.0.3" | ||
| }, |
There was a problem hiding this comment.
🤖 Response from Codex: Agreed. The branch no longer uses an explicit fast-uri resolution; fast-uri@3.1.2 comes from the dev-dependency and lockfile refresh. I updated the PR description to match the implementation rather than adding a resolution back, keeping the reduced-resolutions approach.
Summary
fast-uripatched through the refreshed dev dependency graph instead of carrying an explicit Yarn resolution.brace-expansionlockfile entries to patched versions.Dependabot alerts addressed
fast-uriGHSA-v39h-62p7-jpjc, patched in 3.1.2.fast-uriGHSA-q3j6-qgpj-74h6, patched in 3.1.2.brace-expansionGHSA-v6h2-p8h4-qcjw, patched in 5.0.6.Verification
yarn install --frozen-lockfilemake preparevia Yarn prepare hook.yarn lintyarn typecheckyarn testyarn audit --level moderateTest and lint SDKworkflow is green across Node 20/22/24.🤖 Generated with Codex