Skip to content

[Snyk] Fix for 2 vulnerabilities - #204

Closed
jplanckeel wants to merge 1 commit into
mainfrom
snyk-fix-38514ca56fffc87348b5ce1bf98b2a41
Closed

jplanckeel wants to merge 1 commit into
mainfrom
snyk-fix-38514ca56fffc87348b5ce1bf98b2a41

Conversation

@jplanckeel

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • web/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue
high severity Uncontrolled Recursion
SNYK-JS-BRACES-19963945
high severity Infinite loop
SNYK-JS-URIJS-19963963

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled Recursion

@jplanckeel

Copy link
Copy Markdown
Contributor Author

Merge Risk: High

This update includes two major version upgrades, eslint to v10.0.0 and tailwindcss to v4.0.0. Both introduce significant and mandatory breaking changes to their configuration models, requiring developer action to migrate.

eslint 9.39.4 → 10.0.0 (High Risk)

ESLint v10 completely removes the legacy .eslintrc.* configuration system in favor of the "flat config" (eslint.config.js) format. This change was introduced in v9 but is now mandatory. [4, 5, 8, 11]

Key Breaking Changes:

  • Mandatory Flat Config: All projects must migrate from .eslintrc.js (or similar) to eslint.config.js. [11] The ESLINT_USE_FLAT_CONFIG environment variable is no longer supported. [4]
  • Node.js Requirement: Support for Node.js versions older than v20.19.0 has been dropped. [1, 4]
  • API and CLI Changes: Deprecated API methods for plugin developers and CLI flags related to the old config system have been removed. [1, 4, 8]
  • New Config Lookup: The configuration file is now located by searching up from the directory of each linted file, improving behavior in monorepos. [4, 8]

Recommendation: Projects must follow the official migration guide to convert their existing .eslintrc files to the new eslint.config.js format. ESLint provides a codemod (@eslint/v9-to-v10) to help automate this process. [8]

tailwindcss 3.4.19 → 4.0.0 (High Risk)

Tailwind CSS v4 introduces a new, high-performance engine and moves configuration from JavaScript into CSS. [3, 10, 12]

Key Breaking Changes:

  • CSS-first Configuration: The tailwind.config.js file is replaced by a CSS-native @theme block inside your main CSS file. [2, 3, 12]
  • New Build Engine: v4 uses Lightning CSS (built in Rust), resulting in significantly faster builds. As a result, postcss-import and autoprefixer are no longer needed in your PostCSS configuration. [12, 15]
  • Package Changes: The PostCSS plugin is now a separate package (@tailwindcss/postcss). [9, 12]
  • Modern Browser Support: v4 targets modern browsers (Safari 16.4+, Chrome 111+, Firefox 128+). If you need to support older browsers, you should remain on v3.4. [15]
  • Deprecated Utilities Removed: Utilities deprecated in v3, such as text-opacity-*, have been removed. [9]

Recommendation: Use the official upgrade tool (npx @tailwindcss/upgrade) to automate the migration of your configuration and dependencies. [13, 15] Carefully review the changes and test your project, as manual adjustments may be necessary.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@TartanLeGrand

Copy link
Copy Markdown
Contributor

This one would break the web build if merged as is:

  • only package.json changes, package-lock.json stays on eslint 9 / tailwind 3, so npm ci fails with a lockfile out of sync;
  • Tailwind 4 no longer reads tailwind.config.js and moved its PostCSS plugin to @tailwindcss/postcss, so vite build fails even after a fresh install;
  • ESLint 10 is outside the peer range of the installed eslint-plugin-react-hooks 5.

On the advisories: braces only comes in through Tailwind 3 (chokidar, micromatch), at build time, and has no patched release, so dropping Tailwind 3 is indeed the fix. urijs is not in the dependency tree (npm ls urijs is empty).

#206 does the complete upgrade: lockfile, Tailwind 4 migration checked page by page against main in light and dark mode, ESLint 10 with react-hooks 7. npm audit is at 0 and tsc / eslint counts are unchanged. I would suggest closing this one in favor of #206.

@jplanckeel

Copy link
Copy Markdown
Contributor Author

Already Fixed

@jplanckeel jplanckeel closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants