Skip to content

chore(deps): resolve dependency vulnerabilities (2026-10-06) - #551

Merged
tkislan merged 3 commits into
mainfrom
chore/resolve-dependency-vulnerabilities-2026-10-06
Oct 7, 2026
Merged

tkislan merged 3 commits into
mainfrom
chore/resolve-dependency-vulnerabilities-2026-10-06

Conversation

@tkislan

@tkislan tkislan commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

npx better-npm-audit audit (Audit - All) and --production (Audit - Production) were failing on main with 42 new advisories (51 npm audit entries) across 16 root packages, plus two more (shell-quote, pbkdf2) published while this PR was open.

Each package was assessed separately against the decision ladder that earlier audit fixes established (#493 / 94b07cc, 2481e2b, eab374b, #469 / f16fb4b):

  1. bump a direct dependency if it is the vulnerable one;
  2. lockfile-only if no override pins the package and every consumer range admits the fix;
  3. delete an override that has become a stale ceiling, or bump it if a consumer still floors a vulnerable range;
  4. add a new override if a consumer floors a vulnerable range;
  5. add an .nsprc exception only if no patched release exists.

None of the 16 is a direct dependency, so rung 1 never applied.

Decisions

Package Advisories Sev Remediation Version
axios 12 (GHSA-vh66…, GHSA-r4gj…) high lockfile-only 1.18.1 → 1.20.0
fast-uri GHSA-hrr3-gc8f-f4qj mod lockfile-only 3.1.7 → 3.1.8
http-cache-semantics GHSA-ch52-4w7c-c8xp high lockfile-only ⚠️ see note 4.2.0 → 4.3.0
markdown-it GHSA-253c-mchw-3w2r mod lockfile-only 14.2.0 → 14.3.2
probe-image-size GHSA-gjj5-9665-rwrc high lockfile-only 7.3.0 → 7.4.0
proxy-addr GHSA-jqcg-44mw-7w3h crit lockfile-only 2.0.7 → 2.0.8
source-map-js GHSA-68fv-2mgg-jv7q high lockfile-only 1.2.1 → 1.2.2
brace-expansion GHSA-q2hr…, GHSA-qhr7…, GHSA-6j4f… high delete 3 stale override keys 1.1.18/2.1.4/5.0.9 → 1.1.21/2.1.7/5.0.12 (11 copies)
dompurify GHSA-p98j…, GHSA-6688… low delete stale override 3.4.15 → 3.4.16
morgan GHSA-9f6g-j8ch-79g4 mod delete stale override 1.12.0 → 1.12.1
smol-toml GHSA-r4xh-jqrq-34v2 mod delete stale override 1.8.0 → 1.9.0
undici 10 (GHSA-rfgv…, GHSA-w293…) high delete 2 stale override keys 6.28.0/7.29.0 → 6.29.0/7.30.0
ip-address GHSA-rpw4…, GHSA-2vr4…, GHSA-j6r3…, GHSA-h3mg… mod bump override (propagated to sql-lsp-modules) 10.4.0 → 10.7.3
katex GHSA-238p-pmpm-9mq7 low new override 0.16.47 → 0.18.2
shell-quote GHSA-pqg4-j6r4-53mv crit delete stale override 1.9.0 → 1.12.0
pbkdf2 GHSA-477h-4r7f-fvrx mod lockfile-only 3.1.5 → 3.1.7
braces GHSA-vfj7-8cjw-p6xm high .nsprc (no fix exists) 3.0.3 (latest)
sprintf-js GHSA-hp3w-g68c-fv3c mod .nsprc (no fix exists) 1.0.3 (1.1.3 latest, also affected)

Details

Lockfile-only: 7 packages

No override key touches these packages, and every consumer's declared range already admits the patched version. This is the browserslist (2481e2b) / fast-uri (#493) shape. In #493's words, "the lockfile is the floor; the drift check enforces it".

  • axios: posthog-node ^1.8.2. It is bundled into extension.node.js, but posthog-node only requires axios when global fetch is missing.
  • proxy-addr (critical): express ^2.0.7; express@latest (5.2.1) declares the same range. Not reachable. Both express apps (oauthLoopbackFlow.node.ts, userpodApiEndpoints.node.ts) keep trust proxy at false, so proxy-addr compiles to trustNone. The fix only touches trustSingle/trustMulti.
  • markdown-it: vsce ^14.1.0. We take 14.3.2 rather than 14.3.1 because 14.3.2 backports a further smartquotes DoS fix that isn't in the advisory DB yet (same reasoning as fast-uri 3.1.7 in chore(deps): resolve fast-uri and qs vulnerabilities #493).
  • fast-uri (ajv ^3.0.1), probe-image-size (less ^7.2.3), source-map-js (postcss ^1.2.1): straightforward patch bumps.
  • ⚠️ http-cache-semantics: this bump clears the gate but does not fix the reported code path.

Deleted stale override ceilings: 5 packages, 8 keys

Each key had become the only thing holding the tree on a vulnerable version, because every consumer range admits the fix. This follows #493: rewriting the keys (e.g. undici@<6.28.1) would resolve identically and then go stale again. The undici keys were on their fourth round of going stale.

-        "smol-toml": "1.8.0",
 ...
-        "undici@<6.28.0": "6.28.0",
-        "undici@>=7.0.0 <7.29.0": "7.29.0",
         "flatted@<3.4.2": "3.4.2",
-        "brace-expansion@<1.1.18": "1.1.18",
-        "brace-expansion@>=2.0.0 <2.1.4": "2.1.4",
-        "brace-expansion@>=5.0.0 <5.0.9": "5.0.9",
         "yaml": "2.8.3",
-        "dompurify": "3.4.15",
 ...
         "js-yaml@3": "3.15.2",
-        "morgan@<1.12.0": "1.12.0",
Package Consumer ranges
brace-expansion minimatch ^1.1.7 / ^2.0.1 / ^2.0.2 / ^5.0.5 / ^5.0.8
dompurify mermaid ^3.3.3
morgan koa-morgan ^1.6.1 (it never pinned morgan; our override caused the fixAvailable: false)
smol-toml cspell-config-lib ^1.6.1 (npm's suggested cspell@10 would not fix it)
undici @actions/* ^6.23.0, cheerio ^7.19.0

How the lockfile was regenerated (this is the non-obvious part):

  • Deleting a key alone moves nothing, because the locked version still satisfies the consumer range. Each package was re-resolved with npm update <pkg>.
  • Even then, npm 10.9.4 kept two brace-expansion copies: the root 1.1.18 and @vscode/test-cli's 5.0.9. Their two lockfile entries were dropped and re-resolved, and all 11 copies are now patched.

Bumped override: ip-address

-        "ip-address": "10.4.0",
+        "ip-address": "10.7.3",
  • Why kept rather than deleted: build/esbuild/build.ts propagates this key into dist/sql-lsp-modules. That directory is installed in isolation with no lockfile, so removing the pin leaves a reused tree on 10.4.0. This is the failure mode measured for mysql2 in 2481e2b.
  • Why 10.7.3: 10.7.1 is the minimum fix. 10.7.3 is the latest patch and what an unpinned resolve picks.
  • Correction to eab374b: that copy is reached only via sqlite3 → node-gyp → make-fetch-happen → socks. It is not used for the SQL LSP's database or SSH-tunnel host resolution.

New override: katex

-        "uuid@8": "11.1.1"
+        "uuid@8": "11.1.1",
+        "katex": "0.18.2"
  • Why it needs an override: mermaid declares katex: ^0.16.45, and every mermaid release up to 12.1.0 declares ^0.16.x. The 0.16 line has no backport, so the consumer itself floors a vulnerable range.
  • Why the 0.16 → 0.18 jump is safe:
    • 0.17 only removed the private __defineFunction API, and 0.18 only prefixed internal CSS classes.
    • mermaid makes one renderToString call and its CSS targets only .katex.
    • The mathml output is byte-identical across both versions.
    • mermaid's own upgrade PR (chore: update to KaTeX v0.18 mermaid-js/mermaid#8216) moves to ^0.18.0 with no source change.
  • When to remove it: katex ships in no bundle. Once a mermaid release admits ^0.18, delete this key.

.nsprc accepted risk: braces, sprintf-js (expiry 2026-11-06)

There is no patched release on any line for either package:

  • braces: <=3.0.3, and 3.0.3 (2024-05-21) is the latest.
  • sprintf-js: <=1.1.3, and 1.1.3 (2023-09-11) is the latest.

Both show up in the production tree only because @deepnote/sql-language-server lists jest under dependencies. Neither reaches any esbuild metafile, dist/sqlLanguageServer.cjs or dist/sql-lsp-modules, and node_modules/** is excluded from the VSIX. The notes record the exact chains and the upgrade path.

  • braces: one .nsprc key clears the whole chained set (micromatch, chokidar, fast-glob, jest-*, gulp, mocha, vsce…), because better-npm-audit only rows root advisories. Upstream fix PRs (feat: add an opt-in nesting depth limit micromatch/braces#77–feat: Package the extension. #79) are open. When 3.0.4 ships, raise or delete the exact braces override and remove this entry.
  • sprintf-js: an alternative was considered and set aside in favour of the exception: overriding "argparse@1": "2.0.1" would remove sprintf-js entirely, since js-yaml 3's load() never touches argparse. The .nsprc note records it as the remediation path.

Added after the first CI run: shell-quote, pbkdf2

These two advisories were published after the first commit and turned Audit - All red again. Both packages are dev-only.

  • shell-quote (critical): deleted "shell-quote@<1.9.0": "1.9.0", which had become a stale ceiling. The only consumer, concurrently@8.2.2, declares ^1.8.1.
    • It is not reachable here: concurrently calls quote() only for --passthrough-arguments, which no script uses.
    • Every concurrently release from 9.2.1 on pins a vulnerable shell-quote exactly, so a future concurrently major will need an override again.
  • pbkdf2 (moderate): lockfile-only (crypto-browserify ^3.1.2, parse-asn1 ^3.1.5). It pulls to-buffer 1.2.1 → 1.2.2.
    • It is reached only via node-stdlib-browser in the web test bundle, whose browser mapping avoids the vulnerable lib/sync.js.
         "sanitize-html": "2.17.7",
-        "shell-quote@<1.9.0": "1.9.0",
         "@babel/core@<7.29.6": "7.29.6",

Perf-fixture lockfile (Qlty Check)

Qlty Check's osv-scanner step gates src/test/vscode-notebook-perf/package-lock.json. That is the fixture's own lockfile, which root npm ci and better-npm-audit never see (#497). It failed on the same brace-expansion advisories, plus one fixture-only finding.

The fix is lockfile-only, as in #497. The fixture has no override for these packages, and every consumer range admits the fix:

Package Change Advisories Consumer range
brace-expansion 2.1.4 → 2.1.7, 5.0.9 → 5.0.12 GHSA-6j4f…, GHSA-q2hr…, GHSA-qhr7… minimatch ^2.0.2 / ^5.0.8
serialize-javascript 7.1.1 → 7.1.2 (under mocha@12) GHSA-gfhx-hw2g-v5hg (low, >=7.1.1 <7.1.2) mocha ^7.1.1

The other serialize-javascript copy (7.0.5, held by the existing override for mocha 11) is outside the advisory range.

Verification

  • npx better-npm-audit audit and npx better-npm-audit audit --production both exit 0. Only the elliptic, braces and sprintf-js exceptions are applied. Production mode prints the existing "unused exception" notice for dev-only elliptic, as before.
  • Exactly the intended lockfile entries move: 25 in the first commit, 3 in the shell-quote/pbkdf2 commit. None are added or removed.
  • Drift check: a fresh clone plus npm install (npm 10.9.4, Node 22.21.1) leaves package-lock.json unchanged, and a second install in the work tree is byte-identical.
  • A clean npm run compile (with dist/sql-lsp-modules removed first) writes ip-address: 10.7.3 into the generated manifest. npm audit of that shipped tree reports 0 vulnerabilities, and it also resolves http-cache-semantics 4.3.0 and brace-expansion 1.1.21.
  • Perf fixture: a local qlty check --all --filter=osv-scanner reports the same 7 issues as CI against the old fixture lockfile and none against the new one. npm ci installs the fixture cleanly, and the lockfile is stable on re-install.
  • npm run typecheck ✅, npm run lint ✅ (only existing warnings), npm test: 2826 passing, 0 failing.

Follow-ups (not in this PR)

  • @deepnote/sql-language-server lists jest in dependencies as well as devDependencies. Removing it there would drop the whole jest/micromatch/braces/sprintf-js chain from audit-prod, for this and every future jest-tree advisory.
  • posthog-node ^5 drops axios entirely, which would remove ~173 KB of dead fallback code from extension.node.js. That is a semver-major change to the telemetry client.

🤖 Generated with Claude Code

https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ

Summary by CodeRabbit

  • Maintenance
    • Updated dependency resolutions for IP address handling and KaTeX, removed several other explicit resolutions, and adjusted additional dependency resolution rules.
  • Security
    • Recorded time-limited risk acceptances for two dependency advisories, expiring November 6, 2026, with reachability assessments and remediation conditions.

`npx better-npm-audit audit` (audit-all) and `--production` (audit-prod)
were red with 42 new advisories (51 npm audit entries) across 16 root
packages. Each package was assessed separately against the decision
ladder earlier audit fixes used (94b07cc, 2481e2b, eab374b,
f16fb4b): lockfile-only where nothing pins the package, delete an
override that has become a stale ceiling, bump or add an override only
where a consumer floors a vulnerable range, and an .nsprc exception only
where no patched release exists.

Lockfile-only (no override key, every consumer range admits the fix):
- axios 1.18.1 -> 1.20.0 (12 advisories; via posthog-node ^1.8.2)
- fast-uri 3.1.7 -> 3.1.8 (GHSA-hrr3-gc8f-f4qj; ajv ^3.0.1)
- http-cache-semantics 4.2.0 -> 4.3.0 (GHSA-ch52-4w7c-c8xp). The advisory
  is disputed upstream (issue #56 closed not_planned, withdrawal requested
  in github/advisory-database#10139) and 4.3.0 leaves the max-stale path
  unchanged; it only falls outside the `<=4.2.0` range. Unreachable here:
  make-fetch-happen builds its CachePolicy with `shared: false`. 4.3.0 does
  carry the merged Vary fix.
- markdown-it 14.2.0 -> 14.3.2 (GHSA-253c-mchw-3w2r; vsce ^14.1.0). 14.3.2
  rather than 14.3.1 because it backports a further smartquotes DoS fix.
- probe-image-size 7.3.0 -> 7.4.0 (GHSA-gjj5-9665-rwrc; less ^7.2.3)
- proxy-addr 2.0.7 -> 2.0.8 (GHSA-jqcg-44mw-7w3h, critical; express
  ^2.0.7). Not reachable: both express apps keep `trust proxy` false, so
  proxy-addr compiles to trustNone and the patched trustSingle/trustMulti
  matchers never run.
- source-map-js 1.2.1 -> 1.2.2 (GHSA-68fv-2mgg-jv7q; postcss ^1.2.1)

Deleted overrides that had become stale ceilings (94b07cc: "the
lockfile is the floor; the drift check enforces it"). Every consumer
range admits the patched release, so only our own key held the tree down:
- brace-expansion: all three ranged keys. 1.1.18/2.1.4/5.0.9 ->
  1.1.21/2.1.7/5.0.12 across all 11 copies (GHSA-q2hr-2g5m-vwhr,
  GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p).
- dompurify 3.4.15 -> 3.4.16 (GHSA-p98j-92pf-mc4p, GHSA-6688-9rhm-gjv2;
  mermaid ^3.3.3).
- morgan 1.12.0 -> 1.12.1 (GHSA-9f6g-j8ch-79g4; koa-morgan ^1.6.1).
- smol-toml 1.8.0 -> 1.9.0 (GHSA-r4xh-jqrq-34v2; cspell-config-lib ^1.6.1).
- undici: both ranged keys. 6.28.0/7.29.0 -> 6.29.0/7.30.0 (10
  advisories; @actions/* ^6.23.0, cheerio ^7.19.0).

Deleting a key alone leaves the lockfile untouched, because the locked
version still satisfies the consumer range, so each package was
re-resolved with `npm update`. npm 10.9.4 kept the root brace-expansion
1.1.18 and @vscode/test-cli's 5.0.9 even then, so those two lockfile
entries were dropped and re-resolved.

Bumped override:
- ip-address 10.4.0 -> 10.7.3 (GHSA-rpw4-54j3-4h4q, GHSA-2vr4-cq9g-pvrc,
  GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw; 10.7.1 is the minimum fix).
  Kept rather than deleted: build.ts propagates this key into
  dist/sql-lsp-modules, an isolated install with no lockfile, where
  removing the pin leaves a reused tree on 10.4.0. 10.7.3 is the latest
  patch and what an unpinned resolve picks. Correction to eab374b: that
  copy is reached only via sqlite3 -> node-gyp -> make-fetch-happen ->
  socks, not by the SQL LSP's host resolution.

New override:
- katex "0.18.2" (GHSA-238p-pmpm-9mq7, low). mermaid declares
  ^0.16.45 and every mermaid up to 12.1.0 declares ^0.16.x, a line with no
  backport, so the consumer itself floors a vulnerable range. 0.16 -> 0.18
  only renames internal CSS classes and the private __defineFunction
  API; mermaid makes a single renderToString call and its CSS targets only
  `.katex`. katex ships in no bundle.

.nsprc accepted risk (no patched release on any line), expiry 2026-11-06:
- braces GHSA-vfj7-8cjw-p6xm (high): <=3.0.3, and 3.0.3 is latest.
- sprintf-js GHSA-hp3w-g68c-fv3c (moderate): <=1.1.3, and 1.1.3 is latest.
Both are in the production tree only because @deepnote/sql-language-server
lists jest under `dependencies`. Neither reaches any esbuild metafile,
dist/sqlLanguageServer.cjs or dist/sql-lsp-modules.

Verified: `better-npm-audit audit` and `--production` both exit 0 with
only the elliptic, braces and sprintf-js exceptions applied; exactly the
25 intended lockfile entries move and none are added or removed; a second
`npm install` leaves package-lock.json byte-identical; a clean build
writes ip-address 10.7.3 into dist/sql-lsp-modules, whose own audit
reports 0 vulnerabilities; typecheck, lint and 2826 unit tests pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 0ca27ce7-c9c2-44b3-8717-8a737bd57850
📥 Commits

Reviewing files that changed from the base of the PR and between 04ab050 and 54b6007.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json
💤 Files with no reviewable changes (1)
  • package.json

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

package.json removes several dependency overrides, adds a katex override, and updates the ip-address override. .nsprc gains accepted-risk entries for two advisories, each with an expiry date of 2026-11-06.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: jamesbhobbs

Merge Risk: ⚪ Minimal · up to 54b60

The inspected dependency versions are consistent with the changed overrides. No actionable merge-blocking risk remains after normal checks.

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Updates Docs ✅ Passed This PR changes dependency configuration and lockfiles only; it does not implement a feature that requires documentation updates. The available checkout exposes only the vscode-deepnote repository, no…
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the dependency vulnerability fixes and includes a date.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 37%. Comparing base (36fff08) to head (54b6007).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@          Coverage Diff          @@
##            main    #551   +/-   ##
=====================================
  Coverage     37%     37%           
=====================================
  Files        820     820           
  Lines      40939   40939           
  Branches    9010    9010           
=====================================
  Hits       15411   15411           
  Misses     23460   23460           
  Partials    2068    2068           
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 6, 2026
…rialize-javascript

Qlty Check's osv-scanner step (`qlty check --all --filter=osv-scanner`)
gates src/test/vscode-notebook-perf/package-lock.json, the fixture's own
lockfile that root `npm ci` and better-npm-audit never see (#497). It
failed on the same brace-expansion advisories fixed in the root tree,
plus one fixture-only finding:

- brace-expansion 2.1.4 -> 2.1.7 and 5.0.9 -> 5.0.12
  (GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7)
- serialize-javascript 7.1.1 -> 7.1.2 under mocha@12
  (GHSA-gfhx-hw2g-v5hg, low, >=7.1.1 <7.1.2)

Lockfile-only, as in #497. The fixture has no override for either
package and every consumer range admits the fix (minimatch ^2.0.2 /
^5.0.8, mocha ^7.1.1). The other serialize-javascript copy (7.0.5, held
by the existing `serialize-javascript@<7.0.5` override for mocha 11's
^6.0.2) is outside the advisory range. npm 10.9.4's `npm update` kept the
hoisted brace-expansion 2.1.4, so that one lockfile entry was dropped and
re-resolved.

Verified: a local `qlty check --all --filter=osv-scanner` reports the same
7 issues as CI against the old lockfile and none against the new one;
`npm ci` installs the fixture cleanly; a second
`npm install --package-lock-only` leaves the lockfile byte-identical.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 6, 2026
Two advisories published after 2be57dd turned Audit - All red again.
Both packages are dev-only, so Audit - Production stayed green.

- shell-quote 1.9.0 -> 1.12.0 (GHSA-pqg4-j6r4-53mv, critical,
  >=1.8.4 <1.11.0). Deleted the `shell-quote@<1.9.0` override, which had
  become a stale ceiling: the only consumer, concurrently@8.2.2, declares
  ^1.8.1. Same reasoning as the overrides deleted in 2be57dd. 1.12.0 is
  what the re-resolve picks; its only change past the 1.11.0 fix is extra
  parse() syntax and quote() operator support. Not reachable here:
  concurrently calls quote() only for --passthrough-arguments, which no
  script uses. Every concurrently release from 9.2.1 on pins a vulnerable
  shell-quote exactly, so a future concurrently major will need an
  override again.
- pbkdf2 3.1.5 -> 3.1.7 (GHSA-477h-4r7f-fvrx, moderate, <=3.1.6).
  Lockfile-only: no override, and both consumers (crypto-browserify
  ^3.1.2, parse-asn1 ^3.1.5) admit it. Pulls to-buffer 1.2.1 -> 1.2.2,
  which 3.1.7 requires. Reached only through node-stdlib-browser in the
  web test bundle, whose browser mapping uses lib/sync-browser.js rather
  than the vulnerable lib/sync.js.

Verified: `better-npm-audit audit` and `--production` both exit 0 with
only the elliptic, braces and sprintf-js exceptions applied; only those
three lockfile entries move; a second `npm install` leaves the lockfile
byte-identical; `npm run compile` (driven by concurrently) and 2826 unit
tests pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
@tkislan
tkislan marked this pull request as ready for review October 6, 2026 17:00
@tkislan
tkislan requested a review from a team as a code owner October 6, 2026 17:00
@tkislan
tkislan merged commit b3ba088 into main Oct 7, 2026
20 checks passed
@tkislan
tkislan deleted the chore/resolve-dependency-vulnerabilities-2026-10-06 branch October 7, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants