Skip to content

fix(deps): resolve all fixable Dependabot advisories - #180

Merged
morepriyam merged 1 commit into
mainfrom
fix/dependency-vulns
Sep 9, 2026
Merged

morepriyam merged 1 commit into
mainfrom
fix/dependency-vulns

Conversation

@morepriyam

@morepriyam morepriyam commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Clears every Dependabot alert that has a usable upstream fix. npm audit goes from 28 findings (8 high, 20 moderate) to 8, all of which come from two packages that are left open on purpose (see below).

Package Before After How Alerts
@xmldom/xmldom 0.8.13 / 0.9.10 0.8.15 / 0.9.12 in-range update (same as #179) 14
browserslist 4.28.2 4.28.9 in-range update 2
baseline-browser-mapping 2.10.36 2.11.21 in-range update (audit only)
js-yaml 4.3.1 / 3.15.1 4.3.2 / 3.15.2 in-range update (audit only)
uuid (via xcode) 7.0.3 11.1.1 scoped overrides on xcode 1
esbuild (via @esbuild-kit/core-utils) 0.18.20 0.25.12 (deduped) scoped overrides 1
sharp (screenshots/frame) 0.35.3 0.35.4 in-range update 1

Bumping Expo SDK 57 to its latest patches would not have fixed uuid or esbuild: @expo/config-plugins@57.0.9 still uses xcode@^3.0.1 (uuid@^7), and drizzle-kit still depends on the deprecated @esbuild-kit/esm-loader.

Left open

  • decode-uri-component <= 0.4.2 (GHSA-vcc3-ghjq-m6fr, moderate, via expo-router → query-string@7). The fixed 0.5.0 is ESM-only, and query-string@7 is CommonJS, so it cannot be swapped in with an override. query-string 9.5.0 carries the fix and 9.5.1 added the named exports expo-router needs, but expo-router (including main) still pins ^7.1.3. This resolves once expo-router moves to query-string 9.
  • image-size <= 2.0.2 (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) has no patched release. metro dropped the dependency in 0.84.5, which the stacked SDK 57 patch bump in chore(deps): bump packages to Expo SDK 57 recommended versions #181 picks up.

Verification

  • jest: 126 passed, 16 skipped
  • tsc --noEmit, expo lint, prettier --check
  • drizzle-kit check loads drizzle.config.ts through @esbuild-kit/esm-loader on esbuild 0.25.12
  • xcode generateUuid() produces valid unique IDs on uuid 11.1.1
  • rm -rf node_modules && npm ci reproduces the lockfile with no diff

Supersedes #179 (this branch includes the same xmldom bumps plus the rest).

Copilot AI lite review requested due to automatic review settings September 9, 2026 14:10

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR reduces Dependabot/npm-audit findings by updating several dependencies and introducing scoped overrides, including vendoring a CommonJS-compatible build of decode-uri-component@0.5.0 to mitigate a reachable CPU-exhaustion issue through query-string@7/Expo Router.

Changes:

  • Add a vendored CommonJS decode-uri-component@0.5.0 and wire it in via a root file: dependency + overrides.
  • Add scoped overrides to force patched versions of uuid (under xcode) and esbuild (under @esbuild-kit/core-utils).
  • Update lockfiles (root and screenshots/frame) to reflect dependency bumps (including sharp).

Reviewed changes

Copilot reviewed 2 out of 9 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
package.json Adds vendored decode-uri-component and scoped overrides to force patched transitive deps.
package-lock.json Reflects dedupes/updates and links decode-uri-component to the vendored directory.
.prettierignore Ignores the new vendor/ directory from formatting.
vendor/decode-uri-component/index.js Vendored CommonJS implementation of decode-uri-component@0.5.0.
vendor/decode-uri-component/index.d.ts Type declarations for the vendored CommonJS export.
vendor/decode-uri-component/package.json Package metadata for local file: dependency resolution.
vendor/decode-uri-component/README.md Documents why the module is vendored and removal criteria.
vendor/decode-uri-component/license MIT license text for the vendored module.
screenshots/frame/package-lock.json Updates sharp and related platform packages for the screenshots subpackage.
Files not reviewed (1)
  • screenshots/frame/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .prettierignore Outdated
Root project (28 npm audit findings -> 8):

- @xmldom/xmldom 0.8.13 -> 0.8.15 and 0.9.10 -> 0.9.12 (14 advisories; supersedes Dependabot PR #179)
- browserslist 4.28.2 -> 4.28.9, baseline-browser-mapping 2.10.36 -> 2.11.21
- js-yaml 4.3.1 -> 4.3.2 and 3.15.1 -> 3.15.2
- uuid 7.0.3 -> 11.1.1 via a scoped override on xcode (uuid 11 still ships a CJS build; xcode only calls v4)
- esbuild 0.18.20 removed by overriding @esbuild-kit/core-utils to share drizzle-kit's 0.25.12

screenshots/frame: sharp 0.35.3 -> 0.35.4 (GHSA-rgj7-g3m4-5g8c).

Left open:
- decode-uri-component <= 0.4.2 (GHSA-vcc3-ghjq-m6fr): the fixed 0.5.0 is ESM-only and
  expo-router (main included) still pins the CommonJS query-string@7. query-string 9.5.x now carries
  the fix and named exports, so this resolves once expo-router moves to it.
- image-size <= 2.0.2 (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq): no patched release; metro dropped
  the dependency in 0.84.5, which the follow-up SDK 57 patch bump picks up.

Verified: jest, tsc, expo lint, prettier, drizzle-kit check (esm-loader through esbuild 0.25),
xcode generateUuid on uuid 11, clean npm ci reproduces the lockfile.
Copilot AI review requested due to automatic review settings September 9, 2026 14:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 3 changed files in this pull request and generated no new comments.

Files not reviewed (1)
  • screenshots/frame/package-lock.json: Generated file

@morepriyam
morepriyam merged commit dabafc5 into main Sep 9, 2026
1 check passed
morepriyam added a commit that referenced this pull request Sep 9, 2026
Patch release carrying the dependency advisory fixes (#180, #181) and the segment-thumb
strand fix (#175). Android versionCode base moves to 20001 so CI-stamped codes stay above
every 2.0.0 build. Prebuild carries both into the native projects.
@morepriyam
morepriyam deleted the fix/dependency-vulns branch September 10, 2026 14:40
@morepriyam morepriyam self-assigned this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants