Skip to content

security(deps): resolve 18 Dependabot alerts in frontend and backend lockfiles - #162

Open
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
mainfrom
fix/deps-lockfile-sweep
Open

NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
mainfrom
fix/deps-lockfile-sweep

Conversation

@NetworkTheoryAppliedResearchInstitute

Copy link
Copy Markdown
Collaborator

Closes 18 of the 24 open Dependabot alerts. npm audit reports 0 vulnerabilities in both frontend/ and backend/ after this change.

Why the existing Dependabot PRs could not do this

The postcss alerts are unfixable by a version bump. next pins postcss to an exact 8.4.31, and postcss in turn pulls nanoid: ^3.3.6. Dependabot cannot move an exact transitive pin, so it has been refiling postcss alerts since May — four are now stacked (81, 128, 131, 150). The same applies to minimatch 9.0.3, pinned exactly by @typescript-eslint/typescript-estree. These need overrides entries, which Dependabot does not propose.

The remaining transitives had simply gone stale. js-yaml, flatted and picomatch all sit behind caret ranges that npm had left at their originally-resolved versions; npm update moves them.

qs needed the override raised. express and body-parser pin qs to ~6.15.1, so the patched 6.16.0 is out of range. The existing qs override goes from ^6.14.1 to ^6.16.0.

Changes

frontend — 15 alerts

Package Before After Alerts
postcss 8.4.31 8.5.28 81, 128, 131, 150
js-yaml 4.1.1 4.3.2 120, 127, 156, 168
nanoid 3.3.11 3.3.19 153, 159, 164
picomatch 2.3.1 4.0.7 56, 61
minimatch 9.0.3 9.0.9 48
flatted 3.3.3 3.4.4 51

backend — 3 alerts

Package Before After Alerts
qs 6.15.3 6.16.0 167, 175
js-yaml 3.15.1 3.15.2 176 (CVE-2026-84375, CVSS 7.5)

Manifest changes are limited to overrides (postcss, minimatch, nanoid added to frontend; qs raised in backend). No declared dependency versions change.

Supersedes

This makes these Dependabot PRs redundant — all five are currently CONFLICTING against main after the 09-14 merges (#153, #158, #160) rewrote the same lockfiles:

Worth noting that rebasing them individually would not have resolved this: #149, #150 and #151 all touch frontend/package-lock.json, so merging any one re-conflicts the other two.

Not addressed

aws-sdk v2 (alert 173) and uuid 8.0.0 (alert 174). uuid is pinned exactly by aws-sdk v2, which is genuinely imported at backend/lib/dynamodbClient.js:1. Clearing these needs the v2 → v3 migration, not a lockfile bump. Separately, aws-sdk is declared in devDependencies despite that runtime import.

🤖 Generated with Claude Code

…lockfiles

The frontend postcss alerts could never be fixed by a version bump: next
pins postcss to an exact 8.4.31, and postcss in turn pulls nanoid ^3.3.6.
Add overrides so these transitive pins can move, then refresh the caret-
ranged transitives that npm had left at their originally-resolved versions.

frontend, 15 alerts (npm audit: 0 vulnerabilities)
  postcss    8.4.31  -> 8.5.28   (alerts 81, 128, 131, 150)
  js-yaml    4.1.1   -> 4.3.2    (alerts 120, 127, 156, 168)
  nanoid     3.3.11  -> 3.3.19   (alerts 153, 159, 164)
  picomatch  2.3.1   -> 4.0.7    (alerts 56, 61)
  minimatch  9.0.3   -> 9.0.9    (alert 48)
  flatted    3.3.3   -> 3.4.4    (alert 51)

backend, 3 alerts
  qs         6.15.3  -> 6.16.0   (alerts 167, 175)
  js-yaml    3.15.1  -> 3.15.2   (alert 176, CVE-2026-84375)

express/body-parser pin qs to ~6.15.1, so the existing qs override is
raised to ^6.16.0 to reach the patched release.

Not addressed here: backend uuid 8.0.0 is pinned exactly by aws-sdk v2
(alerts 173, 174). Both need the v2 -> v3 migration in
backend/lib/dynamodbClient.js, not a lockfile bump.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Jodson Graves <info@ntari.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant