Skip to content

chore(deps): fix the npm advisories; shadcn is a dev dependency - #262

Merged
fylorn merged 1 commit into
devfrom
deps-npm-advisories
Oct 1, 2026
Merged

fylorn merged 1 commit into
devfrom
deps-npm-advisories

Conversation

@fylorn

@fylorn fylorn commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Dependabot reports six advisories on the default branch (two high: brace-expansion stack exhaustion; four moderate). All of them are in packages that come in through the shadcn CLI:

  • brace-expansion, via minimatch and ts-morph;
  • fast-uri, via ajv;
  • ip-address, via express-rate-limit in the MCP SDK.

None of them is bundled into the app.

  • Updated to the fixed releases: brace-expansion 5.0.12, fast-uri 3.1.8, ip-address 10.7.2 (lockfile only).
  • shadcn moves from dependencies to devDependencies. It only adds components from the command line and provides the stylesheet imported at build time (@import "shadcn/tailwind.css"), so nothing at run time depends on it.

The remaining alert, glib 0.18's VariantStrIter, comes from Tauri's GTK 3 bindings on Linux and cannot be updated until Tauri moves to GTK 4. The app does not use that iterator.

Checked: vite build, tsc and the full test suite pass.

🤖 Generated with Claude Code

Dependabot reported six advisories on the default branch, all in
packages that reach the project through the `shadcn` CLI
(brace-expansion via minimatch/ts-morph, fast-uri via ajv, ip-address
via express-rate-limit in the MCP SDK). None of them is bundled into the
app. They are updated to the fixed releases: brace-expansion 5.0.12,
fast-uri 3.1.8, ip-address 10.7.2.

`shadcn` only adds components from the command line and provides the
stylesheet imported at build time (`shadcn/tailwind.css`), so it moves
to devDependencies.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@fylorn
fylorn merged commit d915769 into dev Oct 1, 2026
4 checks passed
@fylorn
fylorn deleted the deps-npm-advisories branch October 1, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant