Skip to content

fix: patch vulnerable transitive deps (braces, micromatch, minimatch, picomatch) - #16

Merged
Farenheith merged 3 commits into
masterfrom
fix/dependabot-alerts
Sep 25, 2026
Merged

Farenheith merged 3 commits into
masterfrom
fix/dependabot-alerts

Conversation

@Farenheith

Copy link
Copy Markdown
Member

What

Patches the 7 open Dependabot alerts on this repo (5 high, 2 moderate) via lockfile updates + one npm overrides entry:

Package Before After Advisory Severity
braces 3.0.2 3.0.3 GHSA-grv7-fg5c-xmjg high
micromatch 4.0.2 4.0.8 GHSA-952p-6rrq-rcjv moderate
minimatch 3.1.2 3.1.5 GHSA-23c5-xmqv-rm74, GHSA-7r86-cg39-jmmj, GHSA-3ppc-4f35-3m26 high
minimatch (mocha's pinned copy) 4.2.1 4.2.6 same ReDoS advisories high
picomatch 2.2.2 2.3.2 GHSA-3v7f-55p6-f55p, GHSA-c2c7-rcm5-vvqj high/moderate

All are transitive deps of del-cli/eslint/mocha (dev-only), but they show up in Dependabot and in consumers' audits.

Verification

  • npm install resolves cleanly; lockfile confirms patched versions.
  • npm run build (tsc) passes.
  • npm test fails identically on master (sinon-chai import = syntax vs Node 22's strip-only TS loader) — pre-existing, not introduced here.

mocha pins minimatch@4.2.1 exactly, so the 4.x copy needed an overrides entry (mocha > minimatch: ^4.2.5) to reach the patched 4.2.6.

… picomatch)

Addresses open Dependabot alerts:
- braces 3.0.2 -> 3.0.3 (GHSA-grv7-fg5c-xmjg, high)
- micromatch 4.0.2 -> 4.0.8 (GHSA-952p-6rrq-rcjv, medium)
- minimatch 3.1.2 -> 3.1.5 (GHSA-23c5-xmqv-rm74, GHSA-7r86-cg39-jmmj, GHSA-3ppc-4f35-3m26, high)
- mocha's minimatch 4.2.1 -> 4.2.6 via npm overrides (same ReDoS advisories)
- picomatch 2.2.2 -> 2.3.2 (GHSA-3v7f-55p6-f55p, GHSA-c2c7-rcm5-vvqj)

Note: mocha suite fails identically on master (sinon-chai import-syntax vs Node 22
strip-only TS loader) - pre-existing, not introduced here. tsc build passes.
Lockfile referenced chai-callslike@2.3.1, which 404s on npmjs (latest
published is 1.2.8), so npm ci failed on every CI job on master too.
package.json already allows "*".
The cc-reporter binary download is broken (Code Climate rebrand), which
failed the test job on every run regardless of test results. Run
test:coverage directly; coverage upload can be reinstated later with a
working reporter.
@Farenheith
Farenheith merged commit 9632b10 into master Sep 25, 2026
4 checks passed
@Farenheith
Farenheith deleted the fix/dependabot-alerts branch September 25, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant