Skip to content

Fix critical and high dependency vulnerabilities - #201

Merged
miguelcalderon merged 1 commit into
masterfrom
miguel/fix-critical-high-dependabot-2026-09
Sep 23, 2026
Merged

miguelcalderon merged 1 commit into
masterfrom
miguel/fix-critical-high-dependabot-2026-09

Conversation

@miguelcalderon

Copy link
Copy Markdown
Contributor

What

  • Upgrade dependencies that currently trigger critical/high Dependabot alerts:
    • Next.js to 16.3.4
    • Sharp to 0.35.4
    • js-yaml to 4.3.2
    • fast-uri to 3.1.7
    • Multer to 2.3.0
  • Synchronize npm/pnpm security overrides and regenerate the affected lockfiles with the 15-day cooldown active.
  • Preserve or upgrade every direct dependency; no direct dependency was downgraded.

Type

  • New playground snippet
  • New local example
  • New external link / resource
  • Update to existing content
  • Repo infrastructure (CI, docs, tooling)

Validation

  • All affected npm and pnpm audits report 0 critical / 0 high findings.
  • Dependency-policy tests: 11/11 passed.
  • Cooldown coverage, override synchronization, and frozen pnpm lockfile checks passed.
  • Clean installs passed for every affected example.
  • Scoped builds, lint checks, and runtime smoke tests passed without any dependency-update regressions; failures reproduced on origin/master remain unchanged.
  • DWS health and multipart-upload smoke tests passed with Multer 2.3.0.
  • Linux x64 / Node 24 Docker validation:
    • Sharp 0.35.4 + libvips 8.18.6 loaded and completed a real image transform in both Next.js examples.
    • AI editing production build passed.
    • Signing compiled successfully before its unchanged baseline TypeScript errors.
  • Final scoped rereview: 0 findings.

Checklist

  • npm run format passes — not run; changes are dependency manifests/generated lockfiles only, and git diff --check passes.
  • README/index updated where needed (category index and/or root README) — not needed for dependency-only maintenance.
  • Example has a README.md with description and quick start (if local example) — existing documentation unchanged.
  • Local example documents its run command and runs successfully with its documented script (if local example) — clean-install and scoped runtime/build validation completed; pre-existing baseline failures are unchanged.
  • No duplicate content (not both playground snippet and local example for the same use case)

Changelog

This repository has no changelog mechanism. This is dependency-security maintenance with no public API or example behavior change.

@miguelcalderon
miguelcalderon merged commit 335a6b7 into master Sep 23, 2026
6 checks passed
@miguelcalderon
miguelcalderon deleted the miguel/fix-critical-high-dependabot-2026-09 branch September 23, 2026 08:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants