Skip to content

PRDCT-585: Dependabot security bumps — safe set (no framework majors) - #1066

Merged
jordanrburger merged 4 commits into
mainfrom
chore/dependabot-safe-bumps
Aug 5, 2026
Merged

jordanrburger merged 4 commits into
mainfrom
chore/dependabot-safe-bumps

Conversation

@Iamfle4ka

Copy link
Copy Markdown
Collaborator

The package updates from the 2026-07-30 sync [00:11:38]–[00:14:10] — "you could even ask Claude to kind of combine all of those into one merge… you still have to test the site".

One PR didn't fit, and that's the finding. The 22 open Dependabot alerts split into three groups, and only one of them is safe to land together:

Group Packages This PR
Fixable in the lockfile tar (critical), astro 6.4.7→6.4.8, postcss, js-yaml, brace-expansion, svgo ✅ done
One coupled major upgrade astro 7 + starlight 0.41 + mdx 7 + sharp 0.35 separate draft PR
Not fixable by us the @vercel/node chain documented below

npm audit: 20 advisories (1 critical / 12 high) → 16 (0 critical / 9 high). package.json is untouched — every fix fits our existing ranges, so this is a package-lock.json-only diff produced by npm audit fix (never --force).

Why the majors are separate

@astrojs/starlight@0.41 peers astro ^7 (drops v6), @astrojs/mdx@7 peers astro ^7, starlight-image-zoom@0.15 peers starlight >=0.41, and astro@7 accepts sharp ^0.34 || ^0.35 while astro@6 accepts only ^0.34 — bumping sharp alone on Astro 6 would just install a second nested copy and fix nothing. It's one upgrade or none.

And it is genuinely risky: astro 6.4.8 now prints markdown.remarkPlugins … are deprecated. Pass them to unified({...}) from @astrojs/markdown-remark directly instead. Astro 7 makes Sätteri the default pipeline, where remark plugins don't run — and src/integrations/beacon-transforms.mjs is a remark plugin that produces the entire Beacon design (check grids, step cards, pseudo-H4s, legacy <div class="alert"> → asides). It would go quiet with a green build. That upgrade needs its own PR, its own click-through, and a human on the merge button.

The @vercel/node chain is left alone, on purpose

undici, path-to-regexp, minimatch, ajv, @vercel/build-utils, @vercel/python-analysis (which pins js-yaml 4.1.1 and smol-toml 1.5.2 exactly — that's why those two still appear in npm audit even though our own copies are patched).

Bumping cannot fix them: the latest @vercel/node 5.9.3 still ships undici 5.28.4 and path-to-regexp 6.1.0, and npm audit fix --force proposes a downgrade to 4.0.0. All of it is development scope — it never reaches the built site, which is static HTML. Whether to dismiss those alerts on GitHub is a maintainer call, not something this PR should decide.

Verification

  • npm run build clean, 306 pages (unchanged).
  • node scripts/audit-phase2.mjs: 147 issues vs 151 baseline on main, 0 missing images, no new broken links.
  • node scripts/check-cli-reference.mjs: 0 findings.
  • Preview click-through, A/B'd against a pre-bump build of the same commit so "works" means "unchanged": Pagefind search (47 results for a test query), sidebar expand + active-state, view-transition navigation keeps styles, click-to-zoom opens and closes, Beacon design intact (.beacon-check-grid, 3 step cards, 3 asides on /transformations/snowflake-plain/), MDX tabs + expressive-code on /cli/getting-started/, 404 page.
  • Two things behave identically in both builds and are therefore not regressions from this PR, but are worth a separate look: the #ak-header-kai header button isn't injected on desktop, and the starlight-image-zoom-zoomable custom element only upgrades on first interaction.

Once this merges, Dependabot should auto-close #1038, #1039, #1040 and #1058. #1041 is the majors — leave it open until the Astro 7 PR is decided, then close it in favour of that one; it lacks the markdown-remark fix and would ship the silent design regression.

🤖 Generated with Claude Code

`npm audit fix` only — lockfile-only, package.json untouched. Closes the
1 critical + 4 high advisories that are fixable without a framework major:

- tar        7.5.16 → 7.5.22  (CRITICAL)
- astro       6.4.7 → 6.4.8   (high, the 6.4.7-specific advisory)
- postcss    8.5.15 → 8.5.25  (high)
- js-yaml     4.2.0 → 4.3.1   (high)
- brace-expansion, svgo (nested)  (high)

npm audit: 20 advisories (1 critical / 12 high) → 16 (0 critical / 9 high).

Deliberately NOT done here:

- astro 7 / starlight 0.41 / mdx 7 / sharp 0.35 — one coupled major
  upgrade, separate draft PR. Note astro 6.4.8 now warns that
  `markdown.remarkPlugins` is deprecated in favour of Sätteri, which is
  exactly what makes that upgrade risky: beacon-transforms is a remark
  plugin and would silently stop running.
- The @vercel/node chain (undici, path-to-regexp, minimatch, ajv,
  @vercel/build-utils, plus its pinned js-yaml 4.1.1 / smol-toml 1.5.2).
  Not fixable by bumping — latest 5.9.3 still ships undici 5.28.4 and
  path-to-regexp 6.1.0, and `audit fix --force` wants to DOWNGRADE to
  4.0.0. All development scope; never in the built site.

Verified: build clean (306 pages), audit-phase2 147 issues (baseline 151,
0 missing images), check-cli-reference 0 findings, and a preview
click-through A/B'd against a pre-bump build of the same commit — search,
sidebar, view-transition nav, image zoom, beacon design (check grids, step
cards, asides), MDX tabs, 404 all behave identically.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
connection-docs Ready Ready Preview Aug 5, 2026 4:34pm

Request Review

@Iamfle4ka

Copy link
Copy Markdown
Collaborator Author

Housekeeping — two corrections to the body above, plus the state of the batch.

The majors PR moved. #1041 was closed by Dependabot earlier today ("updatable in another way") and replaced by #1062 — astro 6.4.7 → 7.1.6 + @astrojs/mdx + @astrojs/starlight. So the closing paragraph's "#1041 is the majors — leave it open" is stale: the Astro 7 work now targets 7.1.6, not the 7.0.x in #1041, and is being built on chore/astro-7-upgrade as a separate draft.

The four bot PRs are closed, not left to auto-close. #1038 (svgo 4.0.2), #1039 (tar 7.5.22), #1040 (js-yaml 4.3.0 — this branch is at 4.3.1), #1058 (postcss 8.5.25). Each was checked against this branch's lockfile before closing, and each comment says to reopen if this PR is rejected.

On the HIGH-severity goal: this PR closes 7 of the 8 high alerts. The eighth is sharp (#54, needs 0.35.0) and it is not fixable here — astro@6 depends on sharp ^0.34, so bumping it alone installs a second nested copy and closes nothing. astro@7.1.6 accepts ^0.34 || ^0.35, so that alert closes with the Astro 7 PR, together with the three astro 7.x advisories (#41, #45, #46).

Marked as draft per the original ask — it stays draft until the preview has been click-tested by a human. 🤖

@Iamfle4ka Iamfle4ka changed the title chore(deps): Dependabot security bumps — safe set (no framework majors) PRDCT-585: Dependabot security bumps — safe set (no framework majors) Aug 3, 2026
@linear-code

linear-code Bot commented Aug 3, 2026

Copy link
Copy Markdown

PRDCT-585

@Iamfle4ka

Copy link
Copy Markdown
Collaborator Author

Manual click-through checklist

A green build is not proof — everything automated has been run and reported in the PR body; this is the part that needs eyes. Open the Vercel preview for this PR (not npm run dev — Pagefind has no index there, and dev injects <style> tags that hide the view-transition bug).

For each row: does it behave the same as production? "Different" is the finding, not "broken".

# Check What to do Watch for
1 Sidebar Expand + collapse a nested group (e.g. Getting Started Tutorial → Part 1), click into a page Group stays open, current page is highlighted, scroll position holds
2 Pagefind search Ctrl/⌘ K, search snowflake Results appear with titles + excerpts; clicking one lands on the right page
3 Image zoom Open /storage/tables/ and click a screenshot Opens in the lightbox; Esc and click-outside both close it
4 View transitions ⚠️ Navigate 4–5 pages in a row without reloading — sidebar link → in-page link → back button Known fragile spot. Styles must not degrade after the first swap: fonts, sidebar chrome, code-block theming
5 404 Go to /does-not-exist/ Renders the styled 404, not a bare Vercel error
6 Ask Kai Click the Ask Kai entry point Drawer opens, input focuses. (The #ak-header-kai desktop header button already doesn't inject on main — pre-existing, not from these PRs. Answers also won't stream on a preview unless AI_SERVICE_URL + KBC_STORAGE_API_TOKEN are set.)
7 Beacon design /transformations/snowflake-plain/ Green check grid, numbered step cards, 3 callout asides — all styled, not plain lists
8 MDX + code blocks /cli/getting-started/ Tabs switch; code blocks have syntax colours + working copy button. (Only .mdx page in the repo, so it's the whole MDX smoke test.)
9 Wide table /storage/tables/csv-files/ Table scrolls horizontally inside its own container; the page body does not scroll sideways

Rows 4 and 8 are where I'd expect trouble first if anything is wrong.

On this PR specifically (safe bumps): nothing here touches the framework, so rows 1–9 are a regression sweep rather than a migration test. Rows 3 (image zoom — sharp/svgo are in this batch) and 2 (search) are the most relevant. This PR was already A/B'd against a pre-bump build of the same commit, so any difference you spot is worth reporting rather than assuming.

Marked draft per the original ask — un-draft it once these pass.

@Iamfle4ka
Iamfle4ka marked this pull request as ready for review August 3, 2026 21:06
@Iamfle4ka
Iamfle4ka requested a review from jordanrburger August 3, 2026 21:06

@keboola-pr-reviewer-bot keboola-pr-reviewer-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: needs_human (risk 3/5) · profile docs

Lockfile dependency bump that affects the site build — escalating to @keboola/docs per the site-configuration rule.

Impact flags: possible rollback re-introduction — see Check Run summary.

Concerns:

  • package-lock.json: Build-dependency lockfile change; per policy auto-escalates like Gemfile.lock.
  • package-lock.json: Transitive semver majors (remark-directive 3→4, micromark-directive 3→4) may alter build output.
  • package-lock.json: Clean-build/render-parity claims are untrusted and unverifiable from the diff.

Suggested reviewers: @keboola/docs

@Iamfle4ka
Iamfle4ka marked this pull request as draft August 3, 2026 21:24
@Iamfle4ka
Iamfle4ka removed the request for review from jordanrburger August 3, 2026 21:24
@Iamfle4ka

Copy link
Copy Markdown
Collaborator Author

Refreshed onto main (#1061 landed). Merged cleanly — one content file, no lockfile conflict, nothing in the dependency surface touched. Re-verified after the merge: build clean at 306 pages, audit-phase2 147 / 0 missing images / 45 broken links, check-cli-reference 0 findings — all unchanged.

Still draft, still needs the click-through above before merge.

@Iamfle4ka

Copy link
Copy Markdown
Collaborator Author

Render-parity evidence (answering @keboola-pr-reviewer-bot)

The bot's objection was fair: "clean-build/render-parity claims are untrusted and unverifiable from the diff." So here is an actual A/B — clean npm ci + npm run build on main (74a4f504) and on this branch, then a file-by-file comparison of the two dist/ trees.

Build + audit

main this branch
build ✅ clean, 306 pages ✅ clean, 306 pages
dist HTML files 500 500 — page set identical (diff of the sorted file lists is empty)
npm audit 20 (1 critical / 12 high) 16 (0 critical / 9 high)

HTML parity: 499 / 500 pages byte-for-byte identical

After normalizing the two expected version strings (Astro v6.4.7→v6.4.8, Starlight v0.38.1→v0.38.5 in the <meta name="generator"> tags) and the one CSS asset hash, 499 of 500 rendered pages are byte-identical.

The one page that differs is /cli/getting-started/ — and the cause is worth stating plainly rather than hand-waving:

- <p>Confirm it&#39;s on your <code>PATH</code> (all platforms):</p>
+ <p>Confirm it’s on your <code>PATH</code> (all platforms):</p>

Prose apostrophes on that page now render as typographic ’ instead of &#39;. It is the only .mdx file in the corpus (src/content/docs/cli/getting-started.mdx); all 307 other pages are .md and were already getting smart quotes on main (199 pages contain ’ before, 200 after). So this bump doesn't introduce new typography — it makes MDX consistent with Markdown. Apostrophes inside <code> are correctly left straight.

The remark-directive 3→4 concern specifically

That's the bump the bot flagged as possibly altering build output. Directive rendering is unchanged:

main this branch
starlight-aside occurrences in dist 1110 1110
--caution / --note / --tip 82 / 111 / 29 82 / 111 / 29
literal ::: leaked into rendered prose 0 0

CSS delta (+89 bytes, common.*.css)

Three rules, all upstream Starlight 0.38.1→0.38.5 patch fixes, none of them ours:

  1. new .starlight-aside__content:empty{display:none}
  2. .hero gains grid-template-columns:100%
  3. the banner p gains text-align:start

Nothing here changes page content or structure. Marking ready for review — the critical tar advisory is the reason not to sit on it.

@Iamfle4ka
Iamfle4ka marked this pull request as ready for review August 4, 2026 00:08
@Iamfle4ka
Iamfle4ka requested a review from jordanrburger August 4, 2026 00:08

@keboola-pr-reviewer-bot keboola-pr-reviewer-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: needs_human (risk 3/5) · profile docs

Dependency lockfile bump — needs a human to confirm the build before merge.

Impact flags: possible rollback re-introduction — see Check Run summary.

Concerns:

  • package-lock.json: Lockfile-only dependency bumps affect site build/deploy; not docs content.
  • package-lock.json: Build-clean and 306-page claims unverifiable from a lockfile diff.

Suggested reviewers: @keboola/docs

@Iamfle4ka

Copy link
Copy Markdown
Collaborator Author

One retro-correction to this PR's description, found while click-testing #1067.

The description's last verification bullet says the #ak-header-kai header button "isn't injected on desktop" and flags it as worth a separate look. That was a misreading on my part — it's intended behaviour, not a defect.

src/components/AskKaiDrawer.astro:356-397 gates the Kai entry points behind a backend probe:

// Kai only works when the backend env (AI_SERVICE_URL + KBC_STORAGE_API_TOKEN)
// is configured. A static page can't see server env, so probe GET /api/chat
// once per session and hide the entry points unless the backend confirms it.

It probes GET /api/chat and fails closed — on a non-ok response or a network error it calls removeKaiEntrypoints(), deleting #ak-header-kai and .ak-search-cta specifically so the UI never advertises a Kai that would 404. /api/chat is a Vercel function, so it doesn't exist on a plain static serve; the probe fails and the button is correctly hidden. On production, where the env vars are set, it is injected.

So: no ticket needed, nothing to fix, and it is not a regression in either PR. The drawer markup itself is present and renders correctly (verified on #1067 — 480×760, suggestion chips, textarea, AI-disclosure footnote).

The practical consequence for reviewing either PR: row 6 of the checklist can't be fully judged on a preview deploy that lacks AI_SERVICE_URL + KBC_STORAGE_API_TOKEN. If the trigger is absent on the Vercel preview, that's the gate working, not a break.

The other flagged item in that bullet — the starlight-image-zoom-zoomable custom element only upgrading on first interaction — is real and benign: I confirmed on #1067 that clicking an image opens the zoom and Esc closes it, so the lazy upgrade has no user-visible effect.

@jordanrburger
jordanrburger enabled auto-merge August 5, 2026 16:33
@jordanrburger
jordanrburger merged commit 1484d80 into main Aug 5, 2026
3 checks passed
@jordanrburger
jordanrburger deleted the chore/dependabot-safe-bumps branch August 5, 2026 16:34

This branch was successfully deployed

1 active deployment
Preview — df043d1c Deployed Aug 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants