Upgrade dependencies to clear the five critical alerts - #318
Merged
Merged
Conversation
RubenHalman
force-pushed
the
fix/pin-vulnerable-transitives
branch
from
August 30, 2026 21:50
83f57b1 to
50833ae
Compare
None of the five critical Dependabot alerts are on a package we declare. Each arrives underneath a direct dev dependency that had gone stale, so upgrading those parents clears all five without pinning anything: oclif 4.22.5 -> 4.24.0 drops fast-xml-parser 5.2.5 @swc/cli 0.7.7 -> 0.8.1 @xhmikosr/decompress 10.2.0 -> 11.1.4 ts-jest ^29.3.2 -> ^29.4.12 handlebars 4.7.8 -> 4.7.9 concurrently ^9.1.2 -> ^10.0.5 shell-quote 1.8.3 -> 1.10.0 npm-run-all2 ^8.0.2 -> ^9.0.3 shell-quote 1.8.3 -> 1.9.0 The fifth, websocket-driver, is the only one that ships. faye-websocket asks for ">=0.5.1" and the stale lockfile was holding it at 0.7.4, so a plain refresh moves it to 0.7.5. @salesforce/core is untouched. core's own fast-xml-parser stays at 5.5.10. The vulnerable 5.2.5 was a separate copy under oclif; core's was never affected. Manifests move by six lines and no package is pinned, so nothing constrains future resolution. The high-severity alerts are transitives with no stale parent to bump and are left for a follow-up.
RubenHalman
force-pushed
the
fix/pin-vulnerable-transitives
branch
from
August 30, 2026 21:56
50833ae to
38e7b4e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears all five critical Dependabot alerts by upgrading five stale direct dev dependencies. No overrides, no pins. Six lines of manifest change plus the refreshed lockfile.
Why upgrading the parents is enough
None of the five criticals is a package we declare. Each arrives underneath a direct dev dependency that had gone stale, so bumping that parent drops the vulnerable copy on its own:
oclif(cli)fast-xml-parser5.2.5 gone@swc/cli(core, regex-scanner)@xhmikosr/decompress10.2.0 → 11.1.4ts-jest(vsx)handlebars4.7.8 → 4.7.9concurrently(vsx)shell-quote1.8.3 → 1.10.0npm-run-all2(vsx)shell-quote1.8.3 → 1.9.0The fifth,
websocket-driver0.7.4 → 0.7.5, is the only one that ships.faye-websocketdeclareswebsocket-driver: ">=0.5.1", and the lockfile — untouched since December 2025 — was simply holding it at 0.7.4. A refresh picks up the patch.@salesforce/coreis not touched, so the out-of-scope 8 → 9 bump is avoided entirely.Two things this deliberately does not do
packages/core'sfast-xml-parserstays at 5.5.10. The vulnerable 5.2.5 was a separate copy underneathoclifin the cli package. Core's own direct dependency was never affected, and this PR leaves it exactly where it is.packages/action/distis not rebuilt. None of the five criticals is reachable from the action bundle — it depends on core,@actions/*,cosmiconfigandminimatch, and never pulls in cli or vsx. Rebuilding the bundle belongs to the release cycle, which pins the action to a released core.Scope
Criticals only. The 63 high-severity alerts are all transitives with no stale parent to bump — clearing them needs a different mechanism and should be its own PR. This change pins nothing, so it does not constrain how that is done.
Verification
pnpm turbo run test— 8/8 tasks green. Core 149 passed / 3 skipped across 39 suites; CLI 14 passing; vsx and action build clean.pnpm run build:all— 5/5 successful.