PRDCT-585: Dependabot security bumps — safe set (no framework majors) - #1066
Conversation
`npm audit fix` only — lockfile-only, package.json untouched. Closes the 1 critical + 4 high advisories that are fixable without a framework major: - tar 7.5.16 → 7.5.22 (CRITICAL) - astro 6.4.7 → 6.4.8 (high, the 6.4.7-specific advisory) - postcss 8.5.15 → 8.5.25 (high) - js-yaml 4.2.0 → 4.3.1 (high) - brace-expansion, svgo (nested) (high) npm audit: 20 advisories (1 critical / 12 high) → 16 (0 critical / 9 high). Deliberately NOT done here: - astro 7 / starlight 0.41 / mdx 7 / sharp 0.35 — one coupled major upgrade, separate draft PR. Note astro 6.4.8 now warns that `markdown.remarkPlugins` is deprecated in favour of Sätteri, which is exactly what makes that upgrade risky: beacon-transforms is a remark plugin and would silently stop running. - The @vercel/node chain (undici, path-to-regexp, minimatch, ajv, @vercel/build-utils, plus its pinned js-yaml 4.1.1 / smol-toml 1.5.2). Not fixable by bumping — latest 5.9.3 still ships undici 5.28.4 and path-to-regexp 6.1.0, and `audit fix --force` wants to DOWNGRADE to 4.0.0. All development scope; never in the built site. Verified: build clean (306 pages), audit-phase2 147 issues (baseline 151, 0 missing images), check-cli-reference 0 findings, and a preview click-through A/B'd against a pre-bump build of the same commit — search, sidebar, view-transition nav, image zoom, beacon design (check grids, step cards, asides), MDX tabs, 404 all behave identically. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Housekeeping — two corrections to the body above, plus the state of the batch. The majors PR moved. #1041 was closed by Dependabot earlier today ("updatable in another way") and replaced by #1062 — The four bot PRs are closed, not left to auto-close. #1038 (svgo 4.0.2), #1039 (tar 7.5.22), #1040 (js-yaml 4.3.0 — this branch is at 4.3.1), #1058 (postcss 8.5.25). Each was checked against this branch's lockfile before closing, and each comment says to reopen if this PR is rejected. On the HIGH-severity goal: this PR closes 7 of the 8 high alerts. The eighth is Marked as draft per the original ask — it stays draft until the preview has been click-tested by a human. 🤖 |
Manual click-through checklistA green build is not proof — everything automated has been run and reported in the PR body; this is the part that needs eyes. Open the Vercel preview for this PR (not For each row: does it behave the same as production? "Different" is the finding, not "broken".
Rows 4 and 8 are where I'd expect trouble first if anything is wrong. On this PR specifically (safe bumps): nothing here touches the framework, so rows 1–9 are a regression sweep rather than a migration test. Rows 3 (image zoom — Marked draft per the original ask — un-draft it once these pass. |
keboola-pr-reviewer-bot
left a comment
There was a problem hiding this comment.
Verdict: needs_human (risk 3/5) · profile docs
Lockfile dependency bump that affects the site build — escalating to @keboola/docs per the site-configuration rule.
Impact flags: possible rollback re-introduction — see Check Run summary.
Concerns:
package-lock.json: Build-dependency lockfile change; per policy auto-escalates like Gemfile.lock.package-lock.json: Transitive semver majors (remark-directive 3→4, micromark-directive 3→4) may alter build output.package-lock.json: Clean-build/render-parity claims are untrusted and unverifiable from the diff.
Suggested reviewers: @keboola/docs
|
Refreshed onto Still draft, still needs the click-through above before merge. |
Render-parity evidence (answering @keboola-pr-reviewer-bot)The bot's objection was fair: "clean-build/render-parity claims are untrusted and unverifiable from the diff." So here is an actual A/B — clean Build + audit
HTML parity: 499 / 500 pages byte-for-byte identicalAfter normalizing the two expected version strings ( The one page that differs is - <p>Confirm it's on your <code>PATH</code> (all platforms):</p>
+ <p>Confirm it’s on your <code>PATH</code> (all platforms):</p>Prose apostrophes on that page now render as typographic The
|
| main | this branch | |
|---|---|---|
starlight-aside occurrences in dist |
1110 | 1110 |
--caution / --note / --tip |
82 / 111 / 29 | 82 / 111 / 29 |
literal ::: leaked into rendered prose |
0 | 0 |
CSS delta (+89 bytes, common.*.css)
Three rules, all upstream Starlight 0.38.1→0.38.5 patch fixes, none of them ours:
- new
.starlight-aside__content:empty{display:none} .herogainsgrid-template-columns:100%- the banner
pgainstext-align:start
Nothing here changes page content or structure. Marking ready for review — the critical tar advisory is the reason not to sit on it.
keboola-pr-reviewer-bot
left a comment
There was a problem hiding this comment.
Verdict: needs_human (risk 3/5) · profile docs
Dependency lockfile bump — needs a human to confirm the build before merge.
Impact flags: possible rollback re-introduction — see Check Run summary.
Concerns:
package-lock.json: Lockfile-only dependency bumps affect site build/deploy; not docs content.package-lock.json: Build-clean and 306-page claims unverifiable from a lockfile diff.
Suggested reviewers: @keboola/docs
|
One retro-correction to this PR's description, found while click-testing #1067. The description's last verification bullet says the
// Kai only works when the backend env (AI_SERVICE_URL + KBC_STORAGE_API_TOKEN)
// is configured. A static page can't see server env, so probe GET /api/chat
// once per session and hide the entry points unless the backend confirms it.It probes So: no ticket needed, nothing to fix, and it is not a regression in either PR. The drawer markup itself is present and renders correctly (verified on #1067 — 480×760, suggestion chips, textarea, AI-disclosure footnote). The practical consequence for reviewing either PR: row 6 of the checklist can't be fully judged on a preview deploy that lacks The other flagged item in that bullet — the |
The package updates from the 2026-07-30 sync [00:11:38]–[00:14:10] — "you could even ask Claude to kind of combine all of those into one merge… you still have to test the site".
One PR didn't fit, and that's the finding. The 22 open Dependabot alerts split into three groups, and only one of them is safe to land together:
@vercel/nodechainnpm audit: 20 advisories (1 critical / 12 high) → 16 (0 critical / 9 high).package.jsonis untouched — every fix fits our existing ranges, so this is apackage-lock.json-only diff produced bynpm audit fix(never--force).Why the majors are separate
@astrojs/starlight@0.41peersastro ^7(drops v6),@astrojs/mdx@7peersastro ^7,starlight-image-zoom@0.15peersstarlight >=0.41, andastro@7acceptssharp ^0.34 || ^0.35whileastro@6accepts only^0.34— bumping sharp alone on Astro 6 would just install a second nested copy and fix nothing. It's one upgrade or none.And it is genuinely risky: astro 6.4.8 now prints
markdown.remarkPlugins … are deprecated. Pass them to unified({...}) from @astrojs/markdown-remark directly instead.Astro 7 makes Sätteri the default pipeline, where remark plugins don't run — andsrc/integrations/beacon-transforms.mjsis a remark plugin that produces the entire Beacon design (check grids, step cards, pseudo-H4s, legacy<div class="alert">→ asides). It would go quiet with a green build. That upgrade needs its own PR, its own click-through, and a human on the merge button.The
@vercel/nodechain is left alone, on purposeundici, path-to-regexp, minimatch, ajv,
@vercel/build-utils,@vercel/python-analysis(which pinsjs-yaml 4.1.1andsmol-toml 1.5.2exactly — that's why those two still appear innpm auditeven though our own copies are patched).Bumping cannot fix them: the latest
@vercel/node5.9.3 still ships undici 5.28.4 and path-to-regexp 6.1.0, andnpm audit fix --forceproposes a downgrade to 4.0.0. All of it isdevelopmentscope — it never reaches the built site, which is static HTML. Whether to dismiss those alerts on GitHub is a maintainer call, not something this PR should decide.Verification
npm run buildclean, 306 pages (unchanged).node scripts/audit-phase2.mjs: 147 issues vs 151 baseline onmain, 0 missing images, no new broken links.node scripts/check-cli-reference.mjs: 0 findings..beacon-check-grid, 3 step cards, 3 asides on/transformations/snowflake-plain/), MDX tabs + expressive-code on/cli/getting-started/, 404 page.#ak-header-kaiheader button isn't injected on desktop, and thestarlight-image-zoom-zoomablecustom element only upgrades on first interaction.Once this merges, Dependabot should auto-close #1038, #1039, #1040 and #1058. #1041 is the majors — leave it open until the Astro 7 PR is decided, then close it in favour of that one; it lacks the
markdown-remarkfix and would ship the silent design regression.🤖 Generated with Claude Code