Skip to content

chore(deps): resolve Dependabot #110, #115, #116 (dev-tooling transitive deps) - #982

Merged
khaira777 merged 2 commits into
mainfrom
chore/resolve-dependabot-110-115-116
Oct 6, 2026
Merged

khaira777 merged 2 commits into
mainfrom
chore/resolve-dependabot-110-115-116

Conversation

@khaira777

Copy link
Copy Markdown
Contributor

What

Pins three transitive devDependencies to their patched releases via npm overrides, resolving Dependabot alerts #110, #115 and #116.

Alert Package Vulnerable range After Dependency path
#110 (high, CVE-2026-93748) http-cache-semantics <= 4.2.0 4.3.0 electron-builder -> app-builder-lib -> @electron/get -> got -> cacheable-request
#115 (low, CVE-2026-103923) katex >= 0.11.0, < 0.18.2 0.18.10 markdownlint-cli2 -> markdownlint -> micromark-extension-math
#116 (medium, GHSA-r4xh-jqrq-34v2) smol-toml <= 1.8.0 1.9.0 markdownlint-cli2

Impact on FloCafe

None of these packages ships in the desktop package, the frontend export, or the runtime servers. All three are pull-only on electron-builder (Electron binary download during packaging) and markdownlint-cli2 (docs lint), so the only affected local commands are npm run docs:check and packaging. No production code path changes.

http-cache-semantics is already allowed by cacheable-request (^4.0.0); it is overridden anyway so the resolved version is deterministic rather than left to the lockfile. katex is held at ^0.18.2 (not 0.19.x) to keep the change conservative.

Verification

  • npm ls http-cache-semantics katex smol-toml sprintf-js -> clean, exit 0
  • npm audit -> no longer reports http-cache-semantics, katex or smol-toml
  • npm ci (root) -> lockfile in sync, exit 0
  • npm ci (frontend) + npm run lint -> 0 errors
  • npm run docs:check -> 52 files, 0 issues; links, index and policy checks OK
  • npm run build -> pass

Remaining alert

Alert #117 (sprintf-js, medium, CVE-2026-97058) is not addressed: no patched release exists upstream (1.1.3 is the latest), and forcing @electron/get to a version that drops global-agent breaks electron-builder at load time (ESM vs CJS). Recommend dismissing it in Dependabot as tolerable risk / vulnerable code not used, since its only format strings are static literals in build tooling.

Override http-cache-semantics to ^4.3.0, katex to ^0.18.2 and smol-toml to ^1.9.0 so the resolved tree clears Dependabot alerts #110, #115 and #116 (CVE-2026-93748, CVE-2026-103923, GHSA-r4xh-jqrq-34v2).

All three arrive only through dev tooling (the electron-builder download path and markdownlint-cli2) and none ship in the desktop package or the runtime servers. Effect on FloCafe is limited to npm run docs:check and packaging; the katex jump stays inside 0.18.x to keep the range micromark-extension-math expects.

sprintf-js (alert #117) has no patched release upstream, so it is left for a Dependabot dismissal.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: FreeOpenSourcePOS/FloCafe/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9e99b187-0d53-4f24-ad0a-f42880bcd34a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@khaira777
khaira777 enabled auto-merge (squash) October 6, 2026 17:20
@khaira777
khaira777 merged commit b2ba4e6 into main Oct 6, 2026
16 checks passed
@khaira777
khaira777 deleted the chore/resolve-dependabot-110-115-116 branch October 6, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant