Skip to content

chore: resolve open dependabot security alerts - #1560

Closed
jonathannorris wants to merge 2 commits into
mainfrom
chore/dependabot-alerts-2026-09-28
Closed

jonathannorris wants to merge 2 commits into
mainfrom
chore/dependabot-alerts-2026-09-28

Conversation

@jonathannorris

Copy link
Copy Markdown
Member

Summary

  • Bumped image-size (transitive dependency of @docusaurus/mdx-loader) to the patched version via a targeted resolutions entry in package.json, since a plain yarn install alone would not force the fix past the parent's existing ^2.0.2 range.

Dependabot Alerts Resolved

Alert Package Severity Fix
#308 image-size high Resolved to 2.0.4 (patched: 2.0.3) via resolutions in package.json (GHSA-w3rx-r6r6-pgpr)
#307 image-size high Resolved to 2.0.4 (patched: 2.0.3) via resolutions in package.json (GHSA-5p2g-fcmc-qvqq)

Unresolvable

Alert Package Severity Reason
#80 tsup low No patched version published yet (GHSA-3mv9-4h5g-vhg3) — cannot be fixed until upstream releases a fix.

Verification

  • yarn install regenerated the lockfile; image-size now resolves to 2.0.4 everywhere it's referenced.
  • yarn typecheck was run and compared against a clean origin/main checkout: the same pre-existing type errors appear on both, confirming this change introduces no new type errors.
  • yarn lint:es could not be run cleanly in this environment due to a duplicate @typescript-eslint plugin resolution caused by running from a nested git worktree picking up the parent repo's node_modules; this is an environment artifact unrelated to the change (worth a clean checkout to confirm on CI).

🤖 Generated with Claude Code

- image-size 2.0.2 -> 2.0.4 (high, alert #308, GHSA-w3rx-r6r6-pgpr)
- image-size 2.0.2 -> 2.0.4 (high, alert #307, GHSA-5p2g-fcmc-qvqq)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for openfeature ready!

Name Link
🔨 Latest commit 6e9ddaa
🔍 Latest deploy log https://app.netlify.com/projects/openfeature/deploys/6abd6f89f64a700008aaefd8
😎 Deploy Preview https://deploy-preview-1560--openfeature.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@jonathannorris

Copy link
Copy Markdown
Member Author

@copilot resolve the merge conflicts in this pull request

…ts-2026-09-28

# Conflicts:
#	yarn.lock

Co-authored-by: jonathannorris <1219069+jonathannorris@users.noreply.github.com>

Copilot AI commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Merged main and resolved the yarn.lock conflict, retaining the patched image-size@2.0.4 resolution. Merge commit: 6e9ddaa.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants