Skip to content

fix(FFESUPPORT-752): address open Dependabot vulnerabilities - #330

Merged
aarsilv merged 1 commit into
mainfrom
aarsilv/ffesupport-752/fix-vulnerabilities
Jun 2, 2026
Merged

aarsilv merged 1 commit into
mainfrom
aarsilv/ffesupport-752/fix-vulnerabilities

Conversation

@aarsilv

@aarsilv aarsilv commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades dev-only build/test dependencies and refreshes the lockfile.
  • Keeps fast-uri patched through the refreshed dev dependency graph instead of carrying an explicit Yarn resolution.
  • Refreshes vulnerable brace-expansion lockfile entries to patched versions.
  • Bumps the package patch version from 5.0.0 to 5.0.1 for the SDK dependency update.

Dependabot alerts addressed

Verification

  • yarn install --frozen-lockfile
  • make prepare via Yarn prepare hook.
  • yarn lint
  • yarn typecheck
  • yarn test
  • yarn audit --level moderate
  • GitHub Test and lint SDK workflow is green across Node 20/22/24.

🤖 Generated with Codex

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Addresses Dependabot vulnerabilities by forcing the transitive fast-uri dependency to a patched version via a Yarn resolution, and refreshes lockfile entries for brace-expansion. Bumps the package patch version accordingly.

Changes:

  • Adds resolutions entry pinning fast-uri to ^3.1.2 to address GHSA-v39h-62p7-jpjc and GHSA-q3j6-qgpj-74h6.
  • Refreshes brace-expansion lockfile entries (1.1.14→1.1.15, 2.1.0→2.1.1, 5.0.5→5.0.6).
  • Bumps package version 5.0.0 → 5.0.1.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
package.json Bumps version to 5.0.1 and adds a Yarn resolutions block pinning fast-uri to ^3.1.2.
yarn.lock Updates fast-uri to 3.1.2 and refreshes brace-expansion entries to patched versions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@aarsilv
aarsilv force-pushed the aarsilv/ffesupport-752/fix-vulnerabilities branch from cbcb1a0 to 078a0d0 Compare May 29, 2026 03:05
@aarsilv
aarsilv requested a review from Copilot May 29, 2026 03:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.

@aarsilv

aarsilv commented May 29, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 Context from Codex: This resolves the fast-uri alerts with a targeted Yarn resolution/lockfile refresh and patch version bump to 5.0.1. The public SDK API surface is unchanged. Local yarn install --frozen-lockfile, lint, typecheck, tests, and audit passed; CI is green across Node 20/22/24.

@aarsilv
aarsilv force-pushed the aarsilv/ffesupport-752/fix-vulnerabilities branch from 078a0d0 to fd60f3b Compare May 29, 2026 15:34
@aarsilv
aarsilv requested a review from Copilot May 29, 2026 15:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

Comment thread package.json
Comment on lines +68 to 70
"webpack": "^5.107.2",
"webpack-cli": "^7.0.3"
},

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Response from Codex: Agreed. The branch no longer uses an explicit fast-uri resolution; fast-uri@3.1.2 comes from the dev-dependency and lockfile refresh. I updated the PR description to match the implementation rather than adding a resolution back, keeping the reduced-resolutions approach.

@aarsilv
aarsilv merged commit 2840b4e into main Jun 2, 2026
13 checks passed
@aarsilv
aarsilv deleted the aarsilv/ffesupport-752/fix-vulnerabilities branch June 2, 2026 14:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants