Pin transitive deps that lockfile refresh cannot reach - #303
Open
dunningdan wants to merge 1 commit into
Open
Conversation
#302 cleared 42 of 51 Dependabot alerts by refreshing yarn.lock, but 9 survive because re-resolution provably cannot reach them - their parents either pin an exact version or cap below the patched release: minimatch parent pins 9.0.3 exactly -> 9.0.9 yaml parent pins 2.8.1 exactly -> 2.9.0 serialize-javascript parent caps at ^6.0.0 -> 7.1.1 uuid parent caps at ^8.3.2 -> 11.1.1 qs parent caps at ~6.15.1 -> 6.16.0 yarn resolutions are the only lever here, following the existing `got` entry. This clears 9 of the 11 currently open alerts. qs is the newest of these: GHSA for it was published Sep 2 and GitHub raised alerts #197/#198 three minutes after #302 merged, against the freshly refreshed lockfile. `~6.15.1` excludes 6.16.0, so no future lockFileMaintenance pass would have fixed it either. Remaining open after this: #186/#187 image-size, which has no patched version published upstream. Reached via @docusaurus/mdx-loader at build time only; tracked for risk acceptance rather than code change. Verified on Node 24.20.0: yarn build passes (59 documents) and the dev server serves HTTP 200, which exercises sockjs -> uuid@11, the one bump here that crosses major versions and that a production build would not otherwise cover. Also refreshes the lockFileMaintenance description - it still told the reader to restore a weekly schedule, which is no longer the intent. No behavior change; schedule stays "at any time". Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #301 / #302. Clears 9 of the 11 currently open Dependabot alerts.
Why these need pinning
#302's lockfile refresh took the repo from 51 alerts to 11. The survivors aren't stragglers that a later refresh will catch — re-resolution provably cannot reach them, because their parents either pin an exact version or cap below the patched release:
minimatch9.0.3— exact pinyaml2.8.1— exact pinserialize-javascript^6.0.0uuid^8.3.2qs~6.15.1resolutionsis the only lever for this class, following thegotentry already inpackage.json.The
qsone is worth a lookAlerts #197/#198 were raised three minutes after #302 merged — GitHub rescanned the freshly refreshed lockfile against an advisory published Sep 2.
~6.15.1means>=6.15.1 <6.16.0, so 6.16.0 is out of range and no futurelockFileMaintenancepass would have fixed it either. Good illustration of why the refresh and the pins are complementary rather than redundant.Verification
Node 24.20.0:
yarn buildpasses, 59 documents ✅The dev-server check matters here:
uuid8 → 11 crosses three majors and is consumed bysockjs, which only runs underyarn start. A production build would not have exercised it.Remaining after this
#186 / #187
image-size— no patched version published upstream, so no code change can close these. Reached via@docusaurus/mdx-loader@3.10.2at build time only; DoS on a malformed.icns, all images are committed and PR-reviewed, so there is no untrusted input path. For risk acceptance, not remediation.Also in here
One-line refresh of the
lockFileMaintenancedescription — it still instructed the reader to restore a weekly schedule, which is no longer the intent. No behavior change;schedulestaysat any time, so transitive advisories get picked up as they land rather than waiting for Monday. A pass with no drift produces no PR.🤖 Generated with Claude Code