Skip to content

build(deps): resolve AC-4477 high security alerts - #1753

Merged
jpyzio123 merged 2 commits into
mainfrom
build/ac-4477-high-dependency-updates
Sep 9, 2026
Merged

jpyzio123 merged 2 commits into
mainfrom
build/ac-4477-high-dependency-updates

Conversation

@jpyzio123

@jpyzio123 jpyzio123 commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • resolve the High-severity Dependabot alerts tracked by AC-4477
  • refresh compatible transitive resolutions for browserslist, fast-uri, js-yaml, and svgo
  • override pacote to ^21.5.1 because both the current and latest Lerna releases pin a vulnerable version
  • leave existing overrides unchanged where their ranges already permit patched releases

Resolved versions

  • browserslist: 4.28.2 → 4.28.9
  • fast-uri: 3.1.5 → 3.1.7
  • js-yaml: 4.3.1 → 4.3.2
  • pacote: 21.0.1 → 21.5.1
  • svgo: 3.3.4 → 3.3.5

Verification

  • npm ci (Node 20.17.0 / npm 10.8.2)
  • npm run check — 517 tests passed
  • npm run build
  • npm audit --audit-level=high — 0 High, 0 Critical

Copilot AI balanced review requested due to automatic review settings September 9, 2026 12:43

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are limited to dependency override + lockfile refresh, and the resulting lockfile resolves pacote to the intended patched version.

Pull request overview

This PR addresses the high-severity Dependabot alerts tracked in AC-4477 by updating/refreshing dependency resolutions and explicitly overriding pacote to a patched release when upstream (Lerna) still depends on a vulnerable line.

Changes:

  • Add an overrides entry to force pacote to ^21.5.1.
  • Refresh lockfile-resolved versions for affected packages (notably browserslist, fast-uri, js-yaml, svgo) and associated transitive metadata.
File summaries
File Description
package.json Adds pacote override to enforce a patched version across the dependency graph.
package-lock.json Updates resolved versions and dedupes/realigns transitive dependencies to match the new overrides and patched releases.
Review details
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jpyzio123
jpyzio123 merged commit 8eda862 into main Sep 9, 2026
8 checks passed
@jpyzio123
jpyzio123 deleted the build/ac-4477-high-dependency-updates branch September 9, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants