Skip to content

fix: bump vulnerable transitive dependencies - #91

Merged
Jiseoup merged 1 commit into
mainfrom
fix/bump-vulnerable-transitive-deps
Sep 17, 2026
Merged

Jiseoup merged 1 commit into
mainfrom
fix/bump-vulnerable-transitive-deps

Conversation

@Jiseoup

@Jiseoup Jiseoup commented Sep 17, 2026

Copy link
Copy Markdown
Owner

What & Why

#88, #87 and #81 each bump one vulnerable transitive dependency, and each changes nothing but package-lock.json. Merging them in sequence forces a rebase of the other two every time, and #85/#84 already showed where that goes: merging #86 closed both and Dependabot reopened them at newer versions as #88 (2.11.22 → 2.11.24) and #87 (4.28.9 → 4.29.0). This resolves all three advisories in one lockfile change instead.

Package From To Advisory Scope
browserslist 4.28.4 4.29.0 high, needs >= 4.28.7 development
baseline-browser-mapping 2.10.41 2.11.24 medium, needs >= 2.11.0 runtime
@humanfs/node 0.16.7 0.16.8 medium, needs >= 0.16.8 development

All three are transitive — none of them appear in package.json:

browserslist              <- @babel/helper-compilation-targets  ^4.24.0
baseline-browser-mapping  <- browserslist ^2.10.38, next ^2.9.19
@humanfs/node             <- eslint ^0.16.6

Every patched version already falls inside those parent ranges, so npm update reaches them on its own. No package.json change and no overrides entry is needed.

Neither #86 nor #90 covered these. #86 did close the sharp advisory as a side effect of regenerating the lockfile, so #90 was checked for the same: its lockfile leaves all three at the vulnerable versions, because next 16.3.5 still requests baseline-browser-mapping: ^2.9.19.

Why the lockfile shows nine entries, not three

npm update also moves the children of the three packages. These are cascading updates inside ranges that already existed, not widened scope:

browserslist   ->  caniuse-lite            1.0.30001800 -> 1.0.30001810
                   electron-to-chromium    1.5.387      -> 1.5.430
                   node-releases           2.0.50       -> 2.0.56
                   update-browserslist-db  1.2.3        -> 1.3.3
@humanfs/node  ->  @humanfs/core           0.19.1       -> 0.19.2
                   @humanfs/types          (new)        -> 0.15.0

package-lock.json is the only changed file.

Related Issue

No issue. Supersedes #88, #87 and #81 — close them once this merges, if Dependabot has not already.

How to Verify

Run from a clean checkout of main:

  1. Apply the update:

    npm ci
    npm update browserslist baseline-browser-mapping @humanfs/node
    
  2. Confirm the three targets reached their patched versions:

    node -e 'const l=require("./package-lock.json");
      ["browserslist","baseline-browser-mapping","@humanfs/node"].forEach(p=>
        console.log(p, l.packages["node_modules/"+p].version))'
    # browserslist 4.29.0
    # baseline-browser-mapping 2.11.24
    # @humanfs/node 0.16.8
    
  3. Confirm nothing outside the lockfile moved:

    git status --short        # " M package-lock.json" and nothing else
    
  4. Match CI (npm ci -> format:check -> lint -> typecheck -> build):

    npm run format:check && npm run lint && npm run typecheck && npm run build
    
  5. npm audit reports found 0 vulnerabilities.

After merge, check Security -> Dependabot alerts: the browserslist, baseline-browser-mapping and @humanfs/node advisories should all move to fixed, leaving no open alerts.

Checklist

  • PR title follows Conventional Commits (feat:, fix:, chore:, refactor:, docs:, i18n:)
  • Translations added to both locales/ko.json and locales/en.json (if UI text changed) — N/A, no UI text changed
  • Tested on mobile viewport (if UI changed) — N/A, no UI change

@Jiseoup Jiseoup self-assigned this Sep 17, 2026
@Jiseoup Jiseoup added the fix Bug fix implementation label Sep 17, 2026
@Jiseoup
Jiseoup merged commit e84bc2e into main Sep 17, 2026
4 checks passed
@Jiseoup
Jiseoup deleted the fix/bump-vulnerable-transitive-deps branch September 17, 2026 13:13

This branch was successfully deployed

1 active deployment
Preview — 5869af3a Deployed Sep 17, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fix Bug fix implementation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant