Skip to content

fix(FFESUPPORT-991): remediate September 2026 dependabot vulnerabilities - #332

Open
aarsilv wants to merge 3 commits into
mainfrom
aarsilv/ffesupport-991/fix-vulnerabilities
Open

aarsilv wants to merge 3 commits into
mainfrom
aarsilv/ffesupport-991/fix-vulnerabilities

Conversation

@aarsilv

@aarsilv aarsilv commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated from Claude

This PR closes the 15 open Dependabot alerts on js-sdk-common (@eppo/js-client-sdk-common). It also closes 7 related alerts that Dependabot auto-dismissed but yarn audit still reports. All vulnerable packages are dev-only transitive dependencies. The PR also raises the devDependency floors in package.json to the latest in-range releases and bumps the package version to 5.0.2.

Jira: https://datadoghq.atlassian.net/browse/FFESUPPORT-991

Commits

  1. Remediate vulnerabilities — lockfile-only re-resolution of the vulnerable packages.
  2. Bump devDependencies to latest in range — package.json floors, the lockfile, and a prettier 3.9 reformat of two type aliases.
  3. Bump version to 5.0.2.

Advisories closed

Package Severity Before → After First patched Advisories Pulled via
fast-uri high 3.1.2 → 3.1.8 3.1.6 GHSA-4c8g-83qw-93j6, GHSA-v2hh-gcrm-f6hx, GHSA-7p8r-x3mc-p8w7, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc, GHSA-jqff-g426-hqxp webpack, terser-webpack-plugin → schema-utils → ajv@8
js-yaml 3.x high 3.15.0 → 3.15.2 3.15.2 GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh jest → @istanbuljs/load-nyc-config
js-yaml 4.x high 4.3.0 → 4.3.2 4.3.2 GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh eslint@8, @eslint/eslintrc
brace-expansion 1.x high 1.1.15 → 1.1.21 1.1.18 GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg¹, GHSA-rgw5-rvv9-x895¹ minimatch@3
brace-expansion 2.x high 2.1.1 → 2.1.7 2.1.4 same as 1.x glob → minimatch@9
brace-expansion 5.x high 5.0.6 → 5.0.12 5.0.9 same as 1.x @typescript-eslint/typescript-estree → minimatch@10
browserslist high 4.28.2 → 4.29.1 4.28.7 GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx¹ webpack, @babel/helper-compilation-targets
baseline-browser-mapping medium 2.10.25 → 2.11.26 2.11.0 GHSA-w5vr-8v7q-w6rv browserslist

¹ Dependabot auto-dismissed this alert. yarn audit still reported it, so this PR closes it too.

"First patched" is the lowest version that fixes every listed advisory for that line.

devDependency floors raised (commit 2)

@types/lodash ^4.17.25, @types/semver ^7.8.0, @typescript-eslint/eslint-plugin and @typescript-eslint/parser ^8.70.1, eslint-import-resolver-typescript ^4.4.5, eslint-plugin-unused-imports ^4.4.1, jest ^30.5.2, prettier ^3.9.9, testdouble ^3.21.0, ts-jest ^29.4.14, ts-loader ^9.6.2, typescript ^5.9.3, webpack ^5.111.1, webpack-cli ^7.2.3.

All are in-range (minor or patch). Major upgrades are deferred; see below.

Prettier 3.9 prints short union types on one line. Commit 2 reformats Entry and BanditActions. The change is whitespace only.

Runtime impact

  • No runtime dependency changes. The transitive tree of the dependencies (buffer, js-base64, pino, semver, spark-md5, yargs) is identical to main: 38 lockfile entries at the same versions.
  • The tsc output does not change. Every .js and .d.ts file in dist/ is byte-identical to main. Only the source maps of the two reformatted files differ. The Node and React Native SDKs consume this output.
  • The webpack bundle changes. dist/eppo-sdk.js (the jsdelivr build) differs because webpack moves from 5.107.2 to 5.111.1. A side-by-side run of the main bundle and the new bundle gives:
    • the same 29 exports;
    • identical results for all 225 UFC shared-test-case evaluations (scalar and details). Both bundles match the expected values in the test data.

How the tests/CI protect this change

Local runs use Node 24.

  • yarn install --frozen-lockfile passes. The lockfile agrees with package.json.
  • eslint '**/*.{ts,tsx}' passes with 0 problems.
  • yarn typecheck passes.
  • yarn test passes: 758 tests / 36 suites, the same as main.
  • make prepare (tsc + webpack) passes.
  • yarn audit reports 0 advisories (main: 114 high, 11 moderate).
  • CI runs lint-test-sdk and typecheck on Node 20, 22, and 24.

Dependabot closes the alerts when it scans main after the merge.

Note for reviewers: the required checks lint-test-sdk (18), lint-test-sdk (23), typecheck (18), and typecheck (23) stay "Expected". They are stale branch-protection entries. #327 changed the workflow matrix from Node 18/20/22/23 to 20/22/24, so these jobs never run.

Deferred

Advisories: none. This PR closes all open alerts. No alert stays dismissed or auto-dismissed without a fix.

Major devDependency upgrades:

  • eslint 8 → 10. eslint 8 and 9 are out of support. eslint 10 needs flat config, and eslint-plugin-import does not support eslint 10, so the migration also swaps in eslint-plugin-import-x. Two new recommended rules need source edits, one of them in src/override-validator.ts. This is a tooling migration, not a version bump, so it goes in a separate PR.
  • TypeScript 5.9 → 6/7. TypeScript 7 does not export the compiler API that ts-jest, ts-loader, ts-node, and typescript-eslint use. TypeScript 6 always enables esModuleInterop. This changes the emitted JavaScript in 12 dist/ files, so it needs its own PR and review.

🤖 Generated with Claude Code

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments; changes are limited to dependency remediation and a version bump.

Review effort: Lite
Findings: None

What changed in this PR

Updates vulnerable dev-only transitive dependencies and bumps the package version to 5.1.0.

Changes:

  • Refreshes patched dependency versions in yarn.lock.
  • Updates the package version in package.json.
File Description
yarn.lock Resolves patched transitive dependency versions.
package.json Bumps the package version to 5.1.0.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@aarsilv

aarsilv commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Response from codex:

Second-opinion review of f8f22a7: no blocking issues found.

  • Every advisory line resolves to a patched version in yarn.lock. Each new version satisfies its previous semver range.
  • The lockfile changes only the 8 table rows plus the 4 browserslist sub-dependencies. No other entry changes.
  • package.json changes only version (5.0.1 → 5.1.0). No dependency declaration changes. No resolutions.
  • The commit message agrees with the diff.

Codex found one wrong claim and four gaps in the first PR description. The current description fixes them:

  • "The shipped build does not change" conflicted with the version-string change. It now says "shipped code".
  • The description now adds a "First patched" column, the CI results on Node 20/22/24, the engines changes, the trace scope, and the reason for the minor bump.

(codex ran locally via codex exec --sandbox read-only; Claude relays the result here. codex cannot post to GitHub from its sandbox.)

aarsilv and others added 3 commits September 26, 2026 14:57
Re-resolve dev-only transitive deps to patched, in-range versions:
- fast-uri 3.1.2 -> 3.1.8 (6 GHSAs, via webpack/terser-webpack-plugin > ajv@8)
- js-yaml 3.15.0 -> 3.15.2, 4.3.0 -> 4.3.2
  (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh)
- brace-expansion 1.1.15 -> 1.1.21, 2.1.1 -> 2.1.7, 5.0.6 -> 5.0.12
  (GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895)
- browserslist 4.28.2 -> 4.29.1 (GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx)
- baseline-browser-mapping 2.10.25 -> 2.11.26 (GHSA-w5vr-8v7q-w6rv)

browserslist 4.29.1 requires newer caniuse-lite, electron-to-chromium,
node-releases, and update-browserslist-db. The lockfile updates them too.

No package.json changes. No resolutions. No runtime dependency moves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Raise devDependency floors in package.json to the latest in-range
releases: @types/lodash, @types/semver, @typescript-eslint/*,
eslint-import-resolver-typescript, eslint-plugin-unused-imports, jest,
prettier, testdouble, ts-jest, ts-loader, typescript, webpack,
webpack-cli.

Prettier 3.9 prints short union types on one line. Reformat the two
affected type aliases. No runtime dependency changes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aarsilv
aarsilv force-pushed the aarsilv/ffesupport-991/fix-vulnerabilities branch from f8f22a7 to 5a370f0 Compare September 26, 2026 19:01
@aarsilv
aarsilv requested a lite review from Copilot September 26, 2026 19:01
@aarsilv

aarsilv commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Response from codex:

Second review after the branch changed to 3 commits (5a370f0): no blocking issues found.

  • The package.json dependencies do not change. No direct devDependency crosses a major version. All raised floors satisfy their previous ranges.
  • The src/ changes are formatting only. The union members and their order do not change (configuration-store-utils.ts:13, types.ts:11).
  • The commit messages agree with the diff, including the version change 5.0.1 → 5.0.2.
  • Low risk: dist/eppo-sdk.js changes because webpack moves to 5.111.1. The export and fixture comparison supports compatibility for the tested cases. It does not prove equivalence in every browser.

Claude checked the final lockfile separately. Each vulnerable package resolves to a patched version: fast-uri 3.1.8, js-yaml 3.15.2 / 4.3.2, brace-expansion 1.1.21 / 2.1.7 / 5.0.12, browserslist 4.29.1, baseline-browser-mapping 2.11.26.

(codex ran locally via codex exec --sandbox read-only; Claude relays the result here. codex cannot post to GitHub from its sandbox.)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues remain, and all reviewers assessed it as ready.

Review effort: Lite
Findings: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants