Repository navigation
fix(deps): clear dependabot alerts and unblock monthly dependabot prs - #270
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deploying website with
|
| Latest commit: |
dfe1cfd
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://1e79d3cf.website-70y.pages.dev |
| Branch Preview URL: | https://claude-dependabot-security-r.website-70y.pages.dev |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Clears all 26 open Dependabot alerts plus 8 newer advisories that
pnpm auditreports but the alerts page doesn't show yet. Also fixes the Dependabot config so its monthly PRs can merge again.None of the 26 alerts reached site visitors: the site is a static export, and every affected package is build or dev tooling.
Why the alerts piled up
package.json, and Dependabot's security-fix PRs never appeared, so packages pulled in by other packages stayed on old versions.reactwas bumped withoutreact-dom, which fails React's version-mismatch check (chore(deps): bump react and @types/react #265).eslint-config-nexthad fallen behindnext.Changes
fix(deps): patch vulnerable transitive dependenciesmarkdownlint-cli20.23.3 brings in patched js-yaml 5.4.1, markdown-it 15.0.1 and smol-toml 1.8.0.viteis now listed directly as a dev dependency (^8.3.4). Neitherpnpm update --depth Infinitynorpnpm.overrideswould move it while it was only pulled in by vitest.vitest5.0.3.nextandeslint-config-next16.3.8. This fixes sixpnpm auditadvisories, including a high-severity SSRF in image optimization. sharp moves to 0.35.5 as part of it.ci(dependabot): group react and next, keep majors out of the dev groupreact,react-dom,@types/reactand@types/react-domare now one group.nextandeslint-config-nextare now one group.reactandnextsit abovedev-dependencies, so@types/react*andeslint-config-nextstay with their runtime packages; a comment in the file says so.docs: clarify nav intercept and dependabot group commentsChrome.tsxhandler comment now leads with what the same-page intercept still does: a single-hashreplaceState, a native scroll, and moving focus into the section. It describes chrome: nav hash duplicates on repeated click → reload → click #116 as fixed upstream in Next 16.3.8, so the intercept won't look like dead code. Thedependabot.ymlcomments explain the group order, why thenextgroup exists, and that the "majors stay out" rule only applies to the dev group.Notes for the reviewer
New lint rule → workaround removed (
fix(nav)commit):eslint-config-next16.3.8 flaggedwindow.location.assignincomponents/site/Chrome.tsx. It was a full-reload workaround for the nav hash-appending bug (chrome: nav hash duplicates on repeated click → reload → click #116). I tested the static export in headless Chrome. On Next 16.2.6,router.push('/#method')after a reload still reproduces/#method#method. On 16.3.8 it doesn't. Cross-route section links now fall through to the native<Link>without a reload, the same way the home link already did. Clicking from/blog/, a post and/legal/privacy/lands on the right section with a clean hash. Same-page clicks keep thereplaceStateintercept.MobileMenu.tsxhas the same reload workaround, which the rule doesn't flag; it's left alone here and tracked in fix(nav): soft-nav cross-route mobile drawer links instead of a full reload #272.Still flagged by
pnpm audit, none fixable on our side yet:bracesandsprintf-jshave no patched release.smol-tomlneeds 1.9, and the latest markdownlint-cli2 still uses 1.8.katexneeds 0.18, and markdownlint's math extension still uses 0.16.All four are dev or build-time only.
After this merges, close chore(deps-dev): bump the dev-dependencies group with 11 updates #264 and chore(deps): bump react and @types/react #265 so Dependabot regenerates them under the new groups.
Test plan
pnpm install --frozen-lockfilepnpm lint: cleanpnpm format:checkpnpm typecheckpnpm test: 521/521 passpnpm build, including check:out and check:og-image🤖 Generated with Claude Code