security(deps): resolve 18 Dependabot alerts in frontend and backend lockfiles - #162
Open
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
Open
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
Conversation
…lockfiles The frontend postcss alerts could never be fixed by a version bump: next pins postcss to an exact 8.4.31, and postcss in turn pulls nanoid ^3.3.6. Add overrides so these transitive pins can move, then refresh the caret- ranged transitives that npm had left at their originally-resolved versions. frontend, 15 alerts (npm audit: 0 vulnerabilities) postcss 8.4.31 -> 8.5.28 (alerts 81, 128, 131, 150) js-yaml 4.1.1 -> 4.3.2 (alerts 120, 127, 156, 168) nanoid 3.3.11 -> 3.3.19 (alerts 153, 159, 164) picomatch 2.3.1 -> 4.0.7 (alerts 56, 61) minimatch 9.0.3 -> 9.0.9 (alert 48) flatted 3.3.3 -> 3.4.4 (alert 51) backend, 3 alerts qs 6.15.3 -> 6.16.0 (alerts 167, 175) js-yaml 3.15.1 -> 3.15.2 (alert 176, CVE-2026-84375) express/body-parser pin qs to ~6.15.1, so the existing qs override is raised to ^6.16.0 to reach the patched release. Not addressed here: backend uuid 8.0.0 is pinned exactly by aws-sdk v2 (alerts 173, 174). Both need the v2 -> v3 migration in backend/lib/dynamodbClient.js, not a lockfile bump. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Jodson Graves <info@ntari.org>
This was referenced Sep 16, 2026
NetworkTheoryAppliedResearchInstitute
force-pushed
the
fix/deps-lockfile-sweep
branch
from
September 16, 2026 17:14
ae0ede7 to
2c21bbf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes 18 of the 24 open Dependabot alerts.
npm auditreports 0 vulnerabilities in bothfrontend/andbackend/after this change.Why the existing Dependabot PRs could not do this
The postcss alerts are unfixable by a version bump.
nextpins postcss to an exact8.4.31, and postcss in turn pullsnanoid: ^3.3.6. Dependabot cannot move an exact transitive pin, so it has been refiling postcss alerts since May — four are now stacked (81, 128, 131, 150). The same applies tominimatch 9.0.3, pinned exactly by@typescript-eslint/typescript-estree. These needoverridesentries, which Dependabot does not propose.The remaining transitives had simply gone stale.
js-yaml,flattedandpicomatchall sit behind caret ranges that npm had left at their originally-resolved versions;npm updatemoves them.qsneeded the override raised.expressandbody-parserpinqsto~6.15.1, so the patched 6.16.0 is out of range. The existingqsoverride goes from^6.14.1to^6.16.0.Changes
frontend — 15 alerts
backend — 3 alerts
Manifest changes are limited to
overrides(postcss,minimatch,nanoidadded to frontend;qsraised in backend). No declared dependency versions change.Supersedes
This makes these Dependabot PRs redundant — all five are currently
CONFLICTINGagainstmainafter the 09-14 merges (#153, #158, #160) rewrote the same lockfiles:main; postcss covered hereWorth noting that rebasing them individually would not have resolved this: #149, #150 and #151 all touch
frontend/package-lock.json, so merging any one re-conflicts the other two.Not addressed
aws-sdkv2 (alert 173) anduuid 8.0.0(alert 174).uuidis pinned exactly by aws-sdk v2, which is genuinely imported atbackend/lib/dynamodbClient.js:1. Clearing these needs the v2 → v3 migration, not a lockfile bump. Separately,aws-sdkis declared indevDependenciesdespite that runtime import.🤖 Generated with Claude Code