Skip to content

Address high severity Dependabot alerts#4914

Draft
ChrisChapman-gh wants to merge 5 commits into
mainfrom
dependabot/high-severity-version-bumps
Draft

Address high severity Dependabot alerts#4914
ChrisChapman-gh wants to merge 5 commits into
mainfrom
dependabot/high-severity-version-bumps

Conversation

@ChrisChapman-gh
Copy link
Copy Markdown
Collaborator

@ChrisChapman-gh ChrisChapman-gh commented May 22, 2026

Resolves

https://github.com/microsoft/AzureTRE/security/dependabot/266
https://github.com/microsoft/AzureTRE/security/dependabot/271
https://github.com/microsoft/AzureTRE/security/dependabot/273
https://github.com/microsoft/AzureTRE/security/dependabot/275
https://github.com/microsoft/AzureTRE/security/dependabot/276
https://github.com/microsoft/AzureTRE/security/dependabot/278
https://github.com/microsoft/AzureTRE/security/dependabot/285
https://github.com/microsoft/AzureTRE/security/dependabot/343
https://github.com/microsoft/AzureTRE/security/dependabot/345
https://github.com/microsoft/AzureTRE/security/dependabot/346
https://github.com/microsoft/AzureTRE/security/dependabot/349
https://github.com/microsoft/AzureTRE/security/dependabot/354
https://github.com/microsoft/AzureTRE/security/dependabot/355

Also covers moderate alerts

https://github.com/microsoft/AzureTRE/security/dependabot/284
https://github.com/microsoft/AzureTRE/security/dependabot/287
https://github.com/microsoft/AzureTRE/security/dependabot/344
https://github.com/microsoft/AzureTRE/security/dependabot/347
https://github.com/microsoft/AzureTRE/security/dependabot/350
https://github.com/microsoft/AzureTRE/security/dependabot/358

What is being addressed

Dependabot high severity vulnerability alerts

These alerts do not seem to have exploitable paths in the codebase but are still worth remediating.

How is this addressed

Bump PyJWT to 2.12.0 in the API and CLI, and refresh the UI lockfile to patched versions for the high severity npm advisories.

Bump PyJWT to 2.12.0 in the API and CLI, and refresh the UI lockfile to patched versions for the high severity npm advisories.

Covered alerts: #355 and #354 for fast-uri; #349 for lodash; #343 for lodash-es; #346 and #345 for vite; #285 for picomatch; #278 for flatted; #276, #275, and #274 for PyJWT; #273 for immutable; #271 and #266 for minimatch.

Left #269 for Rollup unchanged because it already has a separate PR open. The remaining npm audit high is therefore expected on this branch.
@ChrisChapman-gh ChrisChapman-gh self-assigned this May 22, 2026
@ChrisChapman-gh ChrisChapman-gh added api Composition Service API dependencies Pull requests that update a dependency file ui TRE UI labels May 22, 2026
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 22, 2026

Unit Test Results

914 tests   914 ✅  36s ⏱️
 28 suites    0 💤
  2 files      0 ❌

Results for commit b5f7486.

♻️ This comment has been updated with latest results.

…ity vulnerabilities

- Bump versions of `brace-expansion` from 2.0.2 to 2.1.0 and 1.1.12 to 1.1.14
- Update `@rollup` packages from 4.53.3 to 4.60.4 for various platforms
- Upgrade `nanoid` from 3.3.11 to 3.3.12
- Upgrade `postcss` from 8.5.6 to 8.5.15
- Upgrade `ws` from 8.18.3 to 8.20.1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api Composition Service API dependencies Pull requests that update a dependency file ui TRE UI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant