Skip to content

Sweep Dependabot alerts: clear 51 of 52 open advisories - #13

Merged
usr-icon-foundation merged 1 commit into
masterfrom
sweep/dependabot-2026-09
Sep 6, 2026
Merged

usr-icon-foundation merged 1 commit into
masterfrom
sweep/dependabot-2026-09

Conversation

@DavidFBD

@DavidFBD DavidFBD commented Sep 6, 2026

Copy link
Copy Markdown
Collaborator

Clears 51 of the 52 open Dependabot alerts on this repo.

The nanoid security email that prompted this was already stale: it reported CVE-2026-73086 (< 3.3.12), but two stricter nanoid advisories had landed since — CVE-2026-67214 (< 3.3.16) and CVE-2026-67213 (< 3.3.18). Patching to the version the email asked for would have left two highs open, so the override goes straight to ^3.3.18.

What changed

Change Alerts cleared
next 15.5.18 → 15.5.21 16 (8 CVEs, 4 high)
dompurify → 3.4.14 11
js-yaml → 3.15.2 / 4.3.2 6
nanoid → 3.3.18 3
mermaid → 10.9.8 3
brace-expansion → 2.1.4 3
sharp → 0.35.4 2
postcss → 8.5.28 2
broken-link-checker removed 2 (request, uuid@3.4.0)
fflate, postcss-selector-parser, uuid added as overrides 3

Notes on two non-obvious bits

sharp needed an override, not just a version bump. Bumping the direct dependency to ^0.35.0 did not clear the advisory, because next@15.5.21 pins sharp@0.34.5 as its own optional dependency. Only adding a sharp override displaces it. Confirmed running libvips 8.18.6, above the 8.18.3 that GHSA-f88m-g3jw-g9cj requires.

Overrides intentionally stay in package.json. With lockfileVersion: 9.0 and no packageManager field, Vercel builds with pnpm 9, which reads pnpm.overrides from package.json. Note that pnpm 11 no longer reads that field — it warns and continues — so local installs must use npx --yes pnpm@9 install until the lockfile is migrated deliberately. A plain pnpm install on pnpm 11 would silently drop every security pin. Resolution here was done with pnpm 9 so the lockfile stays at v9.0 and local matches production exactly.

Removing broken-link-checker

It had no patched release path and was the sole source of request@2.88.2 (unpatchable) and uuid@3.4.0. Safe to drop because its only consumer, scripts/test.js, was dead code — every event handler and the enqueue() call were commented out, and no npm script referenced it. That file is deleted here.

Link checking is unaffected: scripts/link-check.mjs uses linkinator, and both CI workflows (broken-link-check.yml, linkinator.yml) invoke GitHub Actions rather than this dependency.

Still open after this PR

next-mdx-remote@4.4.1 — high severity, arbitrary code execution in React SSR of untrusted MDX. Deferred deliberately, not missed:

  • Patched only in 6.0.0, a major that nextra@2.13.4 does not support; forcing it is expected to break the build.
  • All MDX in this repo is first-party and committed, so the untrusted-input path the advisory describes is not reachable.

Resolving it properly means a Nextra 2 → 3 migration, which deserves its own scoping rather than riding along in a security sweep.

Verification

  • pnpm@9 install clean, lockfile reported up to date — so Vercel's frozen-lockfile install will pass
  • next build completes across all pages
  • sharp loads its native binary and encodes correctly (libvips 8.18.6)
  • All 51 cleared alerts confirmed by semver-matching each advisory's vulnerable range against installed versions, rather than assuming the bumps took

🤖 Generated with Claude Code

Closes 51 of the 52 open Dependabot alerts on this repo. The nanoid
security email that prompted this was already stale: it reported
CVE-2026-73086 (< 3.3.12), but two stricter nanoid advisories had landed
since (CVE-2026-67214 < 3.3.16, CVE-2026-67213 < 3.3.18), so the override
goes straight to ^3.3.18.

Direct dependencies:
- next 15.5.18 -> 15.5.21, clearing 16 alerts across 8 CVEs (4 high)
- sharp ^0.33.2 -> ^0.35.0 (libvips 8.18.6) for GHSA-f88m-g3jw-g9cj
- postcss (dev) ^8.5.10 -> ^8.5.23

Bumped pnpm overrides:
- dompurify ^3.4.0 -> ^3.4.13 (11 alerts)
- js-yaml ^3.14.2/^4.1.1 -> ^3.15.1/^4.3.1 (6 alerts)
- nanoid ^3.3.8 -> ^3.3.18 (3 alerts)
- mermaid ^10.9.6 -> ^10.9.8 (3 alerts)
- brace-expansion (v2) ^2.0.3 -> ^2.1.4 (3 alerts)
- postcss ^8.5.10 -> ^8.5.23, form-data (<3) ^2.5.4 -> ^2.5.6

Added overrides: fflate ^0.4.9, postcss-selector-parser ^6.1.3,
uuid ^11.1.1, and sharp ^0.35.0 (next pins sharp 0.34.5 as an optional
dep, so the direct bump alone left the advisory open).

Removed broken-link-checker, which had no patched release path and was
the sole source of request@2.88.2 (unpatchable) and uuid@3.4.0. Its only
consumer, scripts/test.js, was dead code: every handler and the
enqueue() call were commented out and no npm script referenced it. Link
checking is unaffected - scripts/link-check.mjs uses linkinator, and both
CI workflows use GitHub Actions rather than this dependency.

Overrides stay in package.json rather than moving to pnpm-workspace.yaml:
lockfileVersion 9.0 with no packageManager field means Vercel builds with
pnpm 9, which reads pnpm.overrides from package.json. Resolution was done
with pnpm 9 to keep the lockfile at v9.0 and local resolution identical
to production. Note that pnpm 11 ignores these overrides, so local work
needs `pnpm@9` until the lockfile is migrated deliberately.

Still open: next-mdx-remote 4.4.1 (GHSA high, arbitrary code execution in
SSR of untrusted MDX). Patched only in 6.0.0, a major that nextra 2.13.4
does not support. All MDX here is first-party and in-repo, so it is not
reachable; it needs a nextra 3 upgrade to resolve properly.

Verified: pnpm 9 install clean with lockfile up to date, next build
passes, sharp encodes via libvips 8.18.6, and all 51 alerts confirmed
cleared against installed versions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs-icon-community Ready Ready Preview Sep 6, 2026 6:47am UTC

Request Review

@usr-icon-foundation
usr-icon-foundation merged commit 227e505 into master Sep 6, 2026
3 checks passed

This branch was successfully deployed

1 active deployment
Preview — 9c06bd7d Deployed Sep 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants