Skip to content

Refresh the web lockfile to clear 56 Dependabot alerts - #21

Merged
fylorn merged 1 commit into
mainfrom
dev
Sep 14, 2026
Merged

fylorn merged 1 commit into
mainfrom
dev

Conversation

@fylorn

@fylorn fylorn commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

What

A pure re-resolution of transitive dependencies within the ranges already declared — pnpm-lock.yaml deleted and reinstalled. package.json is untouched, so no declared range moved.

It clears every open alert on the repository: 1 critical, 23 high, 27 moderate, 5 low.

Nothing here reached anyone

The Rust workspace has no alerts at all. All 56 were npm and all were transitive — not one was a direct dependency. The count is inflated by per-CVE alerts on the same package: hono alone accounted for 13, undici for 11.

Of the 18 affected packages, only two sat anywhere in the production dependency graph:

  • @tailwindcss/vite → postcss / nanoid / vite. Build-time; that code is not shipped.
  • @tanstack/react-router → seroval, the one critical (GHSA-mv8w-475r-vwqw, CVSS 9.8).

That advisory needs fromJSON() to deserialize untrusted input with plugins enabled, which is a server-side SSR path. This console is a plain SPA (createRouter + RouterProvider, no Start, no renderToString), and seroval does not appear in the built bundle at all — the sourcemaps name every @tanstack/router-core module that made it in and contain no seroval module. It is tree-shaken away.

Everything else came through dev and build tooling: shadcn → @modelcontextprotocol/sdk (~28 alerts on its own), vitest/jsdom (~15), and the vite/postcss/eslint/babel toolchain.

Fixing it anyway, because 56 standing alerts are where a real one goes to hide.

Notable version moves

seroval 1.5.1 → 1.6.7 · undici 7.24.7 → 7.29.1 · hono 4.12.23 → 4.13.7 · fast-uri 3.1.2 → 3.1.7 · js-yaml 4.1.1 → 4.3.2 · nanoid 3.3.11 → 3.3.19 · ip-address 10.2.0 → 10.7.0

Verification

The same four steps the Frontend Build job runs: pnpm install --frozen-lockfile, pnpm check:i18n (1386 keys), pnpm test (96 tests), pnpm build.

🤖 Generated with Claude Code

`package.json` is untouched. This is a pure re-resolution of transitive
dependencies within the ranges already declared, done by deleting
`pnpm-lock.yaml` and reinstalling.

It clears every open alert on the repository: 1 critical, 23 high, 27
moderate, 5 low. All 56 were npm and all were transitive — not one was a
direct dependency. The count is inflated by per-CVE alerts on the same
package: `hono` alone accounted for 13 and `undici` for 11.

Notable moves: seroval 1.5.1 -> 1.6.7, undici 7.24.7 -> 7.29.1,
hono 4.12.23 -> 4.13.7, fast-uri 3.1.2 -> 3.1.7, js-yaml 4.1.1 -> 4.3.2,
nanoid 3.3.11 -> 3.3.19, ip-address 10.2.0 -> 10.7.0.

**None of these reached anyone.** The Rust workspace has no alerts at
all, and of the 18 affected packages only two sat anywhere in the
production dependency graph: `@tailwindcss/vite` (build-time; its code
is not shipped) and `@tanstack/react-router`, which pulls `seroval` —
the one critical. That advisory needs `fromJSON()` to deserialize
untrusted input with plugins enabled, which is a server-side SSR path.
This console is a plain SPA, and seroval does not appear in the built
bundle at all: the sourcemaps name every `@tanstack/router-core` module
that made it in and contain no seroval module. It is tree-shaken away.

Worth fixing anyway. 56 standing alerts are where a real one goes to
hide.

Verified with the same steps CI runs: `pnpm install --frozen-lockfile`,
`pnpm check:i18n` (1386 keys), `pnpm test` (96 tests), `pnpm build`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@fylorn
fylorn merged commit dd0de18 into main Sep 14, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant