Skip to content

Resolve 56 of 68 website Dependabot vulnerabilities via yarn resolutions - #191

Merged
StefanSteiner merged 1 commit into
upcomingfrom
fix/website-dependabot-vulns
Sep 22, 2026
Merged

StefanSteiner merged 1 commit into
upcomingfrom
fix/website-dependabot-vulns

Conversation

@StefanSteiner

Copy link
Copy Markdown
Collaborator

Summary

All 68 Dependabot alerts on the website stem from transitive dependencies of Docusaurus 2.4.3 — none are direct dependencies that can be bumped in package.json. This PR adds scoped yarn resolutions to pull the fixable transitive deps up to patched versions, clearing 56 of the 68 advisories while keeping the site building on Docusaurus 2.4.3.

Fixed (12 packages, build + lint verified)

@babel/core, axios, body-parser, cookie, got, minimatch, on-headers, qs, serialize-javascript, trim, uuid, ws

Remaining 12 advisories (4 packages) — require a Docusaurus 2 → 3 upgrade

Package Why it can't be fixed on Docusaurus 2.4.3
image-size No patched version exists (advisory patched: <0.0.0)
webpack Pinned at 5.94.0 — bumping reintroduces the schema-utils v4 ProgressPlugin build break fixed in the earlier PR
webpack-dev-server Patched line is a major (4→5/6); breaks the Docusaurus 2.4.3 build (verified). Dev-server only — not in the deployed artifact
path-to-regexp Multi-major in the tree (0.1.x / 1.x / 2.x); yarn 1 can't version-scope, and forcing it breaks the build (verified)

The cross-major forces (ajv, js-yaml, webpack-dev-server) were tested and confirmed to break the build, so they were left out.

Test plan

  • yarn install regenerates lockfile with all resolutions applied
  • yarn build (docusaurus production build) succeeds
  • yarn lint:check (prettier) passes
  • yarn audit confirms 68 → 12 unique advisories
  • CI build job passes

Follow-up

Fully clearing the remaining 12 requires upgrading Docusaurus 2.4.3 → 3.x, which refreshes the whole dependency tree (webpack 5.9x+, webpack-dev-server 5, path-to-regexp 8) and is a separate, larger change with breaking config/MDX migration.

Adds yarn `resolutions` pins bumping transitive dependencies of
Docusaurus 2.4.3 to patched versions. All 68 alerts stem from
Docusaurus 2.4.3's dependency tree; none are direct dependencies.

Fixed (build + lint verified): @babel/core, axios, body-parser,
cookie, got, minimatch, on-headers, qs, serialize-javascript, trim,
uuid, ws — clearing 56 of the 68 advisories.

Remaining 12 advisories (4 packages) cannot be fixed without
upgrading Docusaurus 2 -> 3:
- image-size: no patched version exists
- webpack: pinned at 5.94.0 (bumping reintroduces the schema-utils v4
  ProgressPlugin build break)
- webpack-dev-server (dev-only) and path-to-regexp: patched versions
  require majors that break the Docusaurus 2.4.3 build (verified)
@StefanSteiner
StefanSteiner merged commit aac7246 into upcoming Sep 22, 2026
4 checks passed
@StefanSteiner
StefanSteiner deleted the fix/website-dependabot-vulns branch September 22, 2026 03:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant