Repository navigation
Sweep Dependabot alerts: clear 51 of 52 open advisories - #13
Merged
Merged
Conversation
Closes 51 of the 52 open Dependabot alerts on this repo. The nanoid security email that prompted this was already stale: it reported CVE-2026-73086 (< 3.3.12), but two stricter nanoid advisories had landed since (CVE-2026-67214 < 3.3.16, CVE-2026-67213 < 3.3.18), so the override goes straight to ^3.3.18. Direct dependencies: - next 15.5.18 -> 15.5.21, clearing 16 alerts across 8 CVEs (4 high) - sharp ^0.33.2 -> ^0.35.0 (libvips 8.18.6) for GHSA-f88m-g3jw-g9cj - postcss (dev) ^8.5.10 -> ^8.5.23 Bumped pnpm overrides: - dompurify ^3.4.0 -> ^3.4.13 (11 alerts) - js-yaml ^3.14.2/^4.1.1 -> ^3.15.1/^4.3.1 (6 alerts) - nanoid ^3.3.8 -> ^3.3.18 (3 alerts) - mermaid ^10.9.6 -> ^10.9.8 (3 alerts) - brace-expansion (v2) ^2.0.3 -> ^2.1.4 (3 alerts) - postcss ^8.5.10 -> ^8.5.23, form-data (<3) ^2.5.4 -> ^2.5.6 Added overrides: fflate ^0.4.9, postcss-selector-parser ^6.1.3, uuid ^11.1.1, and sharp ^0.35.0 (next pins sharp 0.34.5 as an optional dep, so the direct bump alone left the advisory open). Removed broken-link-checker, which had no patched release path and was the sole source of request@2.88.2 (unpatchable) and uuid@3.4.0. Its only consumer, scripts/test.js, was dead code: every handler and the enqueue() call were commented out and no npm script referenced it. Link checking is unaffected - scripts/link-check.mjs uses linkinator, and both CI workflows use GitHub Actions rather than this dependency. Overrides stay in package.json rather than moving to pnpm-workspace.yaml: lockfileVersion 9.0 with no packageManager field means Vercel builds with pnpm 9, which reads pnpm.overrides from package.json. Resolution was done with pnpm 9 to keep the lockfile at v9.0 and local resolution identical to production. Note that pnpm 11 ignores these overrides, so local work needs `pnpm@9` until the lockfile is migrated deliberately. Still open: next-mdx-remote 4.4.1 (GHSA high, arbitrary code execution in SSR of untrusted MDX). Patched only in 6.0.0, a major that nextra 2.13.4 does not support. All MDX here is first-party and in-repo, so it is not reachable; it needs a nextra 3 upgrade to resolve properly. Verified: pnpm 9 install clean with lockfile up to date, next build passes, sharp encodes via libvips 8.18.6, and all 51 alerts confirmed cleared against installed versions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears 51 of the 52 open Dependabot alerts on this repo.
The nanoid security email that prompted this was already stale: it reported CVE-2026-73086 (
< 3.3.12), but two stricter nanoid advisories had landed since — CVE-2026-67214 (< 3.3.16) and CVE-2026-67213 (< 3.3.18). Patching to the version the email asked for would have left two highs open, so the override goes straight to^3.3.18.What changed
next15.5.18 → 15.5.21dompurify→ 3.4.14js-yaml→ 3.15.2 / 4.3.2nanoid→ 3.3.18mermaid→ 10.9.8brace-expansion→ 2.1.4sharp→ 0.35.4postcss→ 8.5.28broken-link-checkerremovedrequest,uuid@3.4.0)fflate,postcss-selector-parser,uuidadded as overridesNotes on two non-obvious bits
sharpneeded an override, not just a version bump. Bumping the direct dependency to^0.35.0did not clear the advisory, becausenext@15.5.21pinssharp@0.34.5as its own optional dependency. Only adding asharpoverride displaces it. Confirmed running libvips 8.18.6, above the 8.18.3 that GHSA-f88m-g3jw-g9cj requires.Overrides intentionally stay in
package.json. WithlockfileVersion: 9.0and nopackageManagerfield, Vercel builds with pnpm 9, which readspnpm.overridesfrompackage.json. Note that pnpm 11 no longer reads that field — it warns and continues — so local installs must usenpx --yes pnpm@9 installuntil the lockfile is migrated deliberately. A plainpnpm installon pnpm 11 would silently drop every security pin. Resolution here was done with pnpm 9 so the lockfile stays at v9.0 and local matches production exactly.Removing
broken-link-checkerIt had no patched release path and was the sole source of
request@2.88.2(unpatchable) anduuid@3.4.0. Safe to drop because its only consumer,scripts/test.js, was dead code — every event handler and theenqueue()call were commented out, and no npm script referenced it. That file is deleted here.Link checking is unaffected:
scripts/link-check.mjsuseslinkinator, and both CI workflows (broken-link-check.yml,linkinator.yml) invoke GitHub Actions rather than this dependency.Still open after this PR
next-mdx-remote@4.4.1— high severity, arbitrary code execution in React SSR of untrusted MDX. Deferred deliberately, not missed:nextra@2.13.4does not support; forcing it is expected to break the build.Resolving it properly means a Nextra 2 → 3 migration, which deserves its own scoping rather than riding along in a security sweep.
Verification
pnpm@9 installclean, lockfile reported up to date — so Vercel's frozen-lockfile install will passnext buildcompletes across all pagessharploads its native binary and encodes correctly (libvips 8.18.6)🤖 Generated with Claude Code