Skip to content

fix(deps): clear dependabot alerts and unblock monthly dependabot prs - #270

Merged
yigitdot merged 4 commits into
mainfrom
claude/dependabot-security-review-8d4574
Oct 9, 2026
Merged

yigitdot merged 4 commits into
mainfrom
claude/dependabot-security-review-8d4574

Conversation

@yigitdot

@yigitdot yigitdot commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Clears all 26 open Dependabot alerts plus 8 newer advisories that pnpm audit reports but the alerts page doesn't show yet. Also fixes the Dependabot config so its monthly PRs can merge again.

None of the 26 alerts reached site visitors: the site is a static export, and every affected package is build or dev tooling.

Why the alerts piled up

Changes

fix(deps): patch vulnerable transitive dependencies

  • markdownlint-cli2 0.23.3 brings in patched js-yaml 5.4.1, markdown-it 15.0.1 and smol-toml 1.8.0.
  • vite is now listed directly as a dev dependency (^8.3.4). Neither pnpm update --depth Infinity nor pnpm.overrides would move it while it was only pulled in by vitest.
  • vitest 5.0.3.
  • next and eslint-config-next 16.3.8. This fixes six pnpm audit advisories, including a high-severity SSRF in image optimization. sharp moves to 0.35.5 as part of it.
  • Indirect packages refreshed within their allowed ranges: fast-uri 3.1.8, brace-expansion 1.1.21/5.0.12, js-yaml 3.15.2/4.3.2, browserslist 4.29.3, postcss 8.5.23+, source-map-js 1.2.2.

ci(dependabot): group react and next, keep majors out of the dev group

  • react, react-dom, @types/react and @types/react-dom are now one group.
  • next and eslint-config-next are now one group.
  • The dev group now only takes minor and patch updates, so a major version arrives as its own PR. The TypeScript 7 PR will stay open as the tracker (see deps: hold typescript at 6 until typescript-eslint supports 7 #235): its CI goes green once typescript-eslint supports TS 7.
  • Group order matters, because Dependabot puts each package in the first group it matches. react and next sit above dev-dependencies, so @types/react* and eslint-config-next stay with their runtime packages; a comment in the file says so.

docs: clarify nav intercept and dependabot group comments

  • Comment-only follow-up from a review pass. The Chrome.tsx handler comment now leads with what the same-page intercept still does: a single-hash replaceState, a native scroll, and moving focus into the section. It describes chrome: nav hash duplicates on repeated click → reload → click #116 as fixed upstream in Next 16.3.8, so the intercept won't look like dead code. The dependabot.yml comments explain the group order, why the next group exists, and that the "majors stay out" rule only applies to the dev group.

Notes for the reviewer

  • New lint rule → workaround removed (fix(nav) commit): eslint-config-next 16.3.8 flagged window.location.assign in components/site/Chrome.tsx. It was a full-reload workaround for the nav hash-appending bug (chrome: nav hash duplicates on repeated click → reload → click #116). I tested the static export in headless Chrome. On Next 16.2.6, router.push('/#method') after a reload still reproduces /#method#method. On 16.3.8 it doesn't. Cross-route section links now fall through to the native <Link> without a reload, the same way the home link already did. Clicking from /blog/, a post and /legal/privacy/ lands on the right section with a clean hash. Same-page clicks keep the replaceState intercept. MobileMenu.tsx has the same reload workaround, which the rule doesn't flag; it's left alone here and tracked in fix(nav): soft-nav cross-route mobile drawer links instead of a full reload #272.

  • Still flagged by pnpm audit, none fixable on our side yet:

    • braces and sprintf-js have no patched release.
    • smol-toml needs 1.9, and the latest markdownlint-cli2 still uses 1.8.
    • katex needs 0.18, and markdownlint's math extension still uses 0.16.

    All four are dev or build-time only.

  • After this merges, close chore(deps-dev): bump the dev-dependencies group with 11 updates #264 and chore(deps): bump react and @types/react #265 so Dependabot regenerates them under the new groups.

Test plan

  • pnpm install --frozen-lockfile
  • pnpm lint: clean
  • pnpm format:check
  • pnpm typecheck
  • pnpm test: 521/521 pass
  • pnpm build, including check:out and check:og-image
  • Nav section links from /blog/, a post and /legal/privacy/ soft-nav to the right section (headless Chrome)
  • After merge, the open Dependabot alert count is 0

🤖 Generated with Claude Code

yigitdot and others added 2 commits October 9, 2026 02:50
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 23:50

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Deploying website with  Cloudflare Pages  Cloudflare Pages

Latest commit: dfe1cfd
Status: ✅  Deploy successful!
Preview URL: https://1e79d3cf.website-70y.pages.dev
Branch Preview URL: https://claude-dependabot-security-r.website-70y.pages.dev

View logs

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@yigitdot
yigitdot merged commit e962b7d into main Oct 9, 2026
8 checks passed
@yigitdot
yigitdot deleted the claude/dependabot-security-review-8d4574 branch October 9, 2026 01:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants