fix(FFESUPPORT-996): remediate September 2026 vulnerabilities - #127
Conversation
Re-resolve dev-only transitive dependencies to the latest patched version in their existing ranges: - fast-uri 3.1.2 -> 3.1.8 (6 GHSAs, via ajv@8 in api-extractor/documenter) - js-yaml 3.15.0 -> 3.15.2 and 4.3.0 -> 4.3.2 (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh) - brace-expansion 1.1.15 -> 1.1.21, 2.1.1 -> 2.1.7, 5.0.6 -> 5.0.12 (GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895) - browserslist 4.28.2 -> 4.29.1 (GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx) - baseline-browser-mapping 2.10.27 -> 2.11.26 (GHSA-w5vr-8v7q-w6rv) @microsoft/api-documenter 7.30.16 still pins js-yaml ~4.1.0, so keep the scoped resolution and raise its floor to ^4.3.2. No runtime dependency changes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e releases Raise every devDependency floor to its latest release that installs on Node 20, 22, and 24: - @microsoft/api-documenter ^7.30.16, @microsoft/api-extractor ^7.59.2 - @typescript-eslint/eslint-plugin and parser ^8.70.1 - eslint-import-resolver-typescript ^4.4.5, eslint-plugin-prettier ^5.5.6 - jest ^30.5.2, ts-jest ^29.4.14, testdouble ^3.21.0, prettier ^3.9.9 - Explicit floors for packages already at their latest in-range release. Drop stale lock entries for expect, pretty-format, unrs-resolver, and synckit so each range dedupes onto the new version. Majors stay deferred: eslint 10 (flat config), TypeScript 6/7, and lint-staged 17 (needs Node >= 22.22.1). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The release version bump lacks the required changelog entry and warrants human approval.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Remediates vulnerable dev-only dependencies and bumps the SDK version to 4.0.3.
Changes:
- Updates patched transitive dependencies in the lockfile.
- Raises development dependency floors.
- Preserves the
js-yamlresolution override. - Updates the package version.
| File | Description |
|---|---|
yarn.lock |
Re-resolves vulnerable and transitive dependency trees. |
package.json |
Updates devDependencies, resolutions, and version. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| { | ||
| "name": "@eppo/node-server-sdk", | ||
| "version": "4.0.2", | ||
| "version": "4.0.3", |
There was a problem hiding this comment.
🤖 Response from Claude:
I keep the bump without a changelog entry. The repo has no CHANGELOG.md: commit b46936c (#16) deleted it. CONTRIBUTING.md:9 still mentions the file, but that text is out of date. The recent version bumps (#119, #120, #124, #125) added no changelog. A version bump does not publish the package. publish.yml runs only when someone publishes a GitHub release, and the release notes go there.
codex checked this claim independently and returned INVALID, with the same evidence.
The bump is in its own commit (b7fd946), so a maintainer can drop it. The PR description has a follow-up for the out-of-date release steps in CONTRIBUTING.md.
|
🤖 Response from codex: Fact-check of the PR description against the branch diff, Pre-push review (branch diff): no blocking issues found. Advisory status in
Description fact-check:
Copilot comment (CHANGELOG.md): INVALID. |

🤖 Generated from Claude
This PR closes the 15 open Dependabot alerts on
node-server-sdk(@eppo/node-server-sdk). It also closes 7 related alerts that Dependabot auto-dismissed butyarn auditstill reports. All vulnerable packages are dev-only transitive dependencies. The PR also raises the devDependency floors inpackage.jsonand bumps the package version to 4.0.3.Jira: https://datadoghq.atlassian.net/browse/FFESUPPORT-996
Commits
yarn.lock. Raise the floor of the existingjs-yamlresolution.package.jsonfloors and the lockfile. Drop stale lock entries so the new jest and eslint trees dedupe.Advisories closed
¹ Dependabot auto-dismissed this alert.
yarn auditstill reported it, so this PR closes it too.All rows are in
yarn.lock. None ships: the lockfile does not publish, and none of these packages is in the runtime dependency tree.The js-yaml resolution stays
@microsoft/api-documenter7.30.16 (latest) still pinsjs-yaml ~4.1.0. This PR keeps the existing scoped resolution"@microsoft/api-documenter/js-yaml"and raises it from^4.2.0to^4.3.2.resolutionRationalesrecords the reason. The@types/noderesolution does not change. The PR adds no resolution.devDependency floors raised (commit 2)
@microsoft/api-documenter^7.30.16,@microsoft/api-extractor^7.59.2,@typescript-eslint/eslint-pluginand@typescript-eslint/parser^8.70.1,eslint-import-resolver-typescript^4.4.5,eslint-plugin-prettier^5.5.6,jest^30.5.2,prettier^3.9.9,testdouble^3.21.0,ts-jest^29.4.14.The other devDependencies already resolve their latest in-range release. Their bare major floors (for example
^8) become explicit (for example^8.57.1). All changes are in-range. Major upgrades are deferred; see below.yarn.lockchanges by 919 insertions and 808 deletions. Commit 1 changes 47 insertions and 47 deletions. Commit 2 changes 871 insertions and 760 deletions. In commit 2, 131 package names change: 65 in the jest tree, 26 inunrs-resolverand related packages, 10@typescript-eslint/*packages, 8@microsoft/*and@rushstack/*packages, and 22 others. The lockfile has 621 packages (main: 604).jest-haste-map30.5.1 (from jest 30.5) adds@parcel/watcher, a native addon with prebuilt binaries per platform. Its install script does nothing unlessnpm_config_build_from_source=true.Runtime impact
dependenciesis still@eppo/js-client-sdk-common: ^5. Its transitive tree inyarn.lockhas the same 36 packages at the same versions asmain.dist/build is identical to amainbuild, except one string. Thetscoutput and the API Extractor rollupdist/node-server-sdk.d.tsare identical.dist/tsdoc-metadata.jsonrecords the API Extractor version (7.58.7 → 7.59.2).node-server-sdk.api.mdanddocs/do not change.sdkVersion, whichsrc/sdk-data.tsreads frompackage.json.How the tests and CI protect this change
Local runs on Node 20.20.2 and 24.15.0 (host) and Node 22.23.3 (docker
node:22):yarn install --frozen-lockfilepasses on all three. The lockfile agrees withpackage.json. No engine error on Node 20. The install runsprepare:tscand API Extractor 7.59.2.eslint '**/*.{ts,tsx}'passes with 0 problems.yarn typecheckpasses.main.yarn docs(api-documenter 7.30.16) passes on Node 20 and 24.yarn test, the command thatpublish.ymlruns, passes on Node 20.yarn auditreports 0 advisories (main: 121 high, 10 moderate).yarn.lock(621 packages) reports 0 advisories. The OSV data includes the OpenSSF malicious-package feed. It finds only known entries.lint-test-sdkandtypecheckon Node 20, 22, and 24.Dependabot closes the alerts when it scans
mainafter the merge.Not validated before merge
publish.ymlruns only on a release. Itspublishjob runsyarn installandyarn teston Node 20. The local Node 20 run covers these commands. Itstest-packaged-node-sdkjob (the sdk-test-data relay) and the npm publish step did not run.ts-jest29.4.14 floor (2026-09-25), theprettier3.9.9 floor (2026-09-23), and the transitivebrowserslist4.29.1 (2026-09-24).yarn auditand OSV report only known advisories and known malicious packages.Deferred
Advisories: none. This PR closes all open alerts. No alert stays dismissed or auto-dismissed without a fix.
Major devDependency upgrades:
eslint-plugin-import2.32.0 accepts eslint up to ^9 only. This is a tooling migration for a separate PR.ts-jest29.4.14 (<7) andtypescript-eslint8.70.1 (<6.1.0). TypeScript 6 is a compiler major, and the compiler emits the publisheddist/. It needs its own PR with adist/review.enginesat install, and CI installs on Node 20.Runtime:
@eppo/js-client-sdk-common5.0.2 is not released yet (Eppo-exp/js-sdk-common#332). A later PR can raise the floor.Notes
mainis at 4.0.2. It has no tag, and npm does not have it. The newest tag isv4.0.1. Its publish run failed at "Publish Latest" (the job logs now return HTTP 410), so npm does not have 4.0.1 either; the newest npm version is 4.0.0. Commit 3 is separate, so a reviewer can drop it and release as 4.0.2 instead.@eppo/js-client-sdk-common4.15.5. This PR does not touch it.CONTRIBUTING.mdstill describes a manualnpm publishand aCHANGELOG.mdupdate. The repo has noCHANGELOG.md(deleted in Assignment logging callback #16), andpublish.ymlpublishes on a GitHub release.🤖 Generated with Claude Code