Skip to content

Upgrade dependencies to clear the five critical alerts - #318

Merged
RubenHalman merged 1 commit into
mainfrom
fix/pin-vulnerable-transitives
Aug 30, 2026
Merged

RubenHalman merged 1 commit into
mainfrom
fix/pin-vulnerable-transitives

Conversation

@RubenHalman

@RubenHalman RubenHalman commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

Clears all five critical Dependabot alerts by upgrading five stale direct dev dependencies. No overrides, no pins. Six lines of manifest change plus the refreshed lockfile.

Why upgrading the parents is enough

None of the five criticals is a package we declare. Each arrives underneath a direct dev dependency that had gone stale, so bumping that parent drops the vulnerable copy on its own:

Direct dependency Bump Clears
oclif (cli) 4.22.5 → 4.24.0 fast-xml-parser 5.2.5 gone
@swc/cli (core, regex-scanner) 0.7.7 → 0.8.1 @xhmikosr/decompress 10.2.0 → 11.1.4
ts-jest (vsx) ^29.3.2 → ^29.4.12 handlebars 4.7.8 → 4.7.9
concurrently (vsx) ^9.1.2 → ^10.0.5 shell-quote 1.8.3 → 1.10.0
npm-run-all2 (vsx) ^8.0.2 → ^9.0.3 shell-quote 1.8.3 → 1.9.0

The fifth, websocket-driver 0.7.4 → 0.7.5, is the only one that ships. faye-websocket declares websocket-driver: ">=0.5.1", and the lockfile — untouched since December 2025 — was simply holding it at 0.7.4. A refresh picks up the patch. @salesforce/core is not touched, so the out-of-scope 8 → 9 bump is avoided entirely.

Two things this deliberately does not do

packages/core's fast-xml-parser stays at 5.5.10. The vulnerable 5.2.5 was a separate copy underneath oclif in the cli package. Core's own direct dependency was never affected, and this PR leaves it exactly where it is.

packages/action/dist is not rebuilt. None of the five criticals is reachable from the action bundle — it depends on core, @actions/*, cosmiconfig and minimatch, and never pulls in cli or vsx. Rebuilding the bundle belongs to the release cycle, which pins the action to a released core.

Scope

Criticals only. The 63 high-severity alerts are all transitives with no stale parent to bump — clearing them needs a different mechanism and should be its own PR. This change pins nothing, so it does not constrain how that is done.

Verification

  • All five criticals confirmed clear in the refreshed lockfile.
  • pnpm turbo run test — 8/8 tasks green. Core 149 passed / 3 skipped across 39 suites; CLI 14 passing; vsx and action build clean.
  • pnpm run build:all — 5/5 successful.

@RubenHalman
RubenHalman force-pushed the fix/pin-vulnerable-transitives branch from 83f57b1 to 50833ae Compare August 30, 2026 21:50
None of the five critical Dependabot alerts are on a package we declare.
Each arrives underneath a direct dev dependency that had gone stale, so
upgrading those parents clears all five without pinning anything:

  oclif         4.22.5  -> 4.24.0    drops fast-xml-parser 5.2.5
  @swc/cli      0.7.7   -> 0.8.1     @xhmikosr/decompress 10.2.0 -> 11.1.4
  ts-jest       ^29.3.2 -> ^29.4.12  handlebars 4.7.8 -> 4.7.9
  concurrently  ^9.1.2  -> ^10.0.5   shell-quote 1.8.3 -> 1.10.0
  npm-run-all2  ^8.0.2  -> ^9.0.3    shell-quote 1.8.3 -> 1.9.0

The fifth, websocket-driver, is the only one that ships. faye-websocket
asks for ">=0.5.1" and the stale lockfile was holding it at 0.7.4, so a
plain refresh moves it to 0.7.5. @salesforce/core is untouched.

core's own fast-xml-parser stays at 5.5.10. The vulnerable 5.2.5 was a
separate copy under oclif; core's was never affected.

Manifests move by six lines and no package is pinned, so nothing
constrains future resolution. The high-severity alerts are transitives
with no stale parent to bump and are left for a follow-up.
@RubenHalman
RubenHalman force-pushed the fix/pin-vulnerable-transitives branch from 50833ae to 38e7b4e Compare August 30, 2026 21:56
@RubenHalman RubenHalman changed the title Pin vulnerable transitive dependencies Upgrade dependencies to clear the five critical alerts Aug 30, 2026
@RubenHalman
RubenHalman merged commit a9f72f2 into main Aug 30, 2026
1 check passed
@RubenHalman
RubenHalman deleted the fix/pin-vulnerable-transitives branch August 30, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant