Skip to content

fix(deps): resolve 7 Dependabot alerts (6 high, 1 moderate) - #3

Merged
Printaga merged 1 commit into
mainfrom
fix/dependabot-alerts
Sep 13, 2026
Merged

Printaga merged 1 commit into
mainfrom
fix/dependabot-alerts

Conversation

@Printaga

Copy link
Copy Markdown
Owner

Summary

Resolves all 7 currently open Dependabot alerts on main (6 high, 1 moderate). All affected packages are transitive devDependencies (test/packaging tooling), so there is no runtime exposure, but the alerts are resolved at the lockfile level.

Alert Package Severity Advisory Fixed by
#2 serialize-javascript ≤ 7.0.2 high (RCE) GHSA-5c6j-r48x-rmvq mocha ^11.8.0 → ^12.0.1 (now 7.1.1)
#3 serialize-javascript < 7.0.5 moderate (DoS) GHSA-qj8w-gfj5-8c6v mocha ^11.8.0 → ^12.0.1 (now 7.1.1)
#60 fast-uri < 3.1.6 high GHSA-5jgf-p345-68v8 override → 3.1.6
#61 fast-uri < 3.1.6 high GHSA-fph4-wmhf-6fwf override → 3.1.6
#63 fast-uri < 3.1.6 high GHSA-f65p-4m7j-42xc override → 3.1.6
#64 fast-uri < 3.1.6 high GHSA-jqff-g426-hqxp override → 3.1.6
#66 js-yaml < 4.3.2 high GHSA-2883-xcg3-v3hh override → 4.3.2

Changes (3 files)

  • package.json — bump devDependency mocha ^11.8.0 → ^12.0.1. Mocha 12 natively depends on patched serialize-javascript ^7.1.1, diff ^9.0.0, and js-yaml ^5.0.0, resolving both serialize-javascript alerts without overrides. The programmatic Mocha API used by src/test/suite/index.ts is stable across the major.

  • pnpm-workspace.yaml — add range-scoped overrides pinning the first patched versions for transitive deps under @vscode/vsce whose parents have not yet released compatible fixes:

    • js-yaml@<4.3.2 → 4.3.2
    • fast-uri@<3.1.6 → 3.1.6
    • qs@<6.16.0 → 6.16.0 (qs DoS advisory; no separate Dependabot alert was open for it)

    Range-scoped so only vulnerable resolutions are forced; exact versions (not >=) to keep the blast radius minimal. Remove the overrides once upstream parents bump their ranges.

  • pnpm-lock.yaml — regenerated accordingly.

Verification

  • pnpm audit → "No known vulnerabilities found" (previously 7 findings, matching the Dependabot alerts 1:1 via the same GitHub Advisory Database)
  • pnpm run lint → pass
  • pnpm run compile (tsc) → pass
  • Test suite: PASS: 518, FAIL: 35 — byte-for-byte identical to a baseline run on a pristine checkout of main (mocha 11.8.0); the 35 failures are pre-existing on main (unrelated read only property 'createDirectory' vscode-mock hook errors) and unaffected by this change
  • Dependency diff otherwise limited to the mocha subtree and the overridden transitive pins

Notes

  • Do not merge until CI checks have run.
  • The overrides in pnpm-workspace.yaml are intended as a temporary measure; they should be dropped when @vscode/vsce (or its dependencies) release versions with compatible patched ranges.

Bump mocha ^11.8.0 -> ^12.0.1 (pulls patched serialize-javascript 7.1.1,
diff 9.0.0, js-yaml 5.4.1) and add range-scoped pnpm overrides pinning
first patched versions of transitive deps under @vscode/vsce whose
parents have not released fixes: js-yaml@<4.3.2 -> 4.3.2,
fast-uri@<3.1.6 -> 3.1.6, qs@<6.16.0 -> 6.16.0.

Closes:
- GHSA-5c6j-r48x-rmvq (serialize-javascript RCE, high)
- GHSA-qj8w-gfj5-8c6v (serialize-javascript DoS, moderate)
- GHSA-jqff-g426-hqxp, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf,
  GHSA-5jgf-p345-68v8 (fast-uri host confusion / SSRF, high)
- GHSA-2883-xcg3-v3hh (js-yaml CPU exhaustion, high)

Verified: pnpm audit clean, lint and compile pass, test suite results
identical to pristine-main baseline (pre-existing failures unrelated).

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
@Printaga
Printaga merged commit 56e432a into main Sep 13, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant