fix(deps): resolve all fixable Dependabot advisories - #180
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
This PR reduces Dependabot/npm-audit findings by updating several dependencies and introducing scoped overrides, including vendoring a CommonJS-compatible build of decode-uri-component@0.5.0 to mitigate a reachable CPU-exhaustion issue through query-string@7/Expo Router.
Changes:
- Add a vendored CommonJS
decode-uri-component@0.5.0and wire it in via a rootfile:dependency +overrides. - Add scoped
overridesto force patched versions ofuuid(underxcode) andesbuild(under@esbuild-kit/core-utils). - Update lockfiles (root and
screenshots/frame) to reflect dependency bumps (includingsharp).
Reviewed changes
Copilot reviewed 2 out of 9 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
package.json |
Adds vendored decode-uri-component and scoped overrides to force patched transitive deps. |
package-lock.json |
Reflects dedupes/updates and links decode-uri-component to the vendored directory. |
.prettierignore |
Ignores the new vendor/ directory from formatting. |
vendor/decode-uri-component/index.js |
Vendored CommonJS implementation of decode-uri-component@0.5.0. |
vendor/decode-uri-component/index.d.ts |
Type declarations for the vendored CommonJS export. |
vendor/decode-uri-component/package.json |
Package metadata for local file: dependency resolution. |
vendor/decode-uri-component/README.md |
Documents why the module is vendored and removal criteria. |
vendor/decode-uri-component/license |
MIT license text for the vendored module. |
screenshots/frame/package-lock.json |
Updates sharp and related platform packages for the screenshots subpackage. |
Files not reviewed (1)
- screenshots/frame/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
morepriyam
force-pushed
the
fix/dependency-vulns
branch
2 times, most recently
from
September 9, 2026 14:24
953081b to
c5017f1
Compare
Root project (28 npm audit findings -> 8): - @xmldom/xmldom 0.8.13 -> 0.8.15 and 0.9.10 -> 0.9.12 (14 advisories; supersedes Dependabot PR #179) - browserslist 4.28.2 -> 4.28.9, baseline-browser-mapping 2.10.36 -> 2.11.21 - js-yaml 4.3.1 -> 4.3.2 and 3.15.1 -> 3.15.2 - uuid 7.0.3 -> 11.1.1 via a scoped override on xcode (uuid 11 still ships a CJS build; xcode only calls v4) - esbuild 0.18.20 removed by overriding @esbuild-kit/core-utils to share drizzle-kit's 0.25.12 screenshots/frame: sharp 0.35.3 -> 0.35.4 (GHSA-rgj7-g3m4-5g8c). Left open: - decode-uri-component <= 0.4.2 (GHSA-vcc3-ghjq-m6fr): the fixed 0.5.0 is ESM-only and expo-router (main included) still pins the CommonJS query-string@7. query-string 9.5.x now carries the fix and named exports, so this resolves once expo-router moves to it. - image-size <= 2.0.2 (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq): no patched release; metro dropped the dependency in 0.84.5, which the follow-up SDK 57 patch bump picks up. Verified: jest, tsc, expo lint, prettier, drizzle-kit check (esm-loader through esbuild 0.25), xcode generateUuid on uuid 11, clean npm ci reproduces the lockfile.
morepriyam
force-pushed
the
fix/dependency-vulns
branch
from
September 9, 2026 14:26
c5017f1 to
f73d9b3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Clears every Dependabot alert that has a usable upstream fix.
npm auditgoes from 28 findings (8 high, 20 moderate) to 8, all of which come from two packages that are left open on purpose (see below).@xmldom/xmldombrowserslistbaseline-browser-mappingjs-yamluuid(viaxcode)overridesonxcodeesbuild(via@esbuild-kit/core-utils)overridessharp(screenshots/frame)Bumping Expo SDK 57 to its latest patches would not have fixed uuid or esbuild:
@expo/config-plugins@57.0.9still usesxcode@^3.0.1(uuid@^7), and drizzle-kit still depends on the deprecated@esbuild-kit/esm-loader.Left open
decode-uri-component<= 0.4.2 (GHSA-vcc3-ghjq-m6fr, moderate, viaexpo-router→query-string@7). The fixed0.5.0is ESM-only, andquery-string@7is CommonJS, so it cannot be swapped in with an override.query-string9.5.0 carries the fix and 9.5.1 added the named exportsexpo-routerneeds, butexpo-router(includingmain) still pins^7.1.3. This resolves once expo-router moves to query-string 9.image-size<= 2.0.2 (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) has no patched release. metro dropped the dependency in 0.84.5, which the stacked SDK 57 patch bump in chore(deps): bump packages to Expo SDK 57 recommended versions #181 picks up.Verification
jest: 126 passed, 16 skippedtsc --noEmit,expo lint,prettier --checkdrizzle-kit checkloadsdrizzle.config.tsthrough@esbuild-kit/esm-loaderon esbuild 0.25.12xcodegenerateUuid()produces valid unique IDs on uuid 11.1.1rm -rf node_modules && npm cireproduces the lockfile with no diffSupersedes #179 (this branch includes the same xmldom bumps plus the rest).