Skip to content

chore(deps)(deps): bump the security group across 1 directory with 4 updates - #1163

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/security-c0667e47bf
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/security-c0667e47bf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the security group with 2 updates in the / directory: @tiptap/core and next.

Updates @tiptap/core from 3.30.4 to 3.30.5

Release notes

Sourced from @​tiptap/core's releases.

v3.30.5

@​tiptap/core

Patch Changes

  • Fix a denial-of-service risk where crafted block or inline Markdown attributes could consume excessive CPU and block the browser or server event loop.
Changelog

Sourced from @​tiptap/core's changelog.

3.30.5

Patch Changes

  • d0d499b: Fix a denial-of-service risk where crafted block or inline Markdown attributes could consume excessive CPU and block the browser or server event loop.
    • @​tiptap/pm@​3.30.5
Commits

Updates next from 16.2.11 to 16.3.3

Release notes

Sourced from next's releases.

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

v16.3.1

What's Changed

Full Changelog: vercel/next.js@v16.3.0...v16.3.1

... (truncated)

Commits
  • a9a1cb7 v16.3.3
  • 968b9fc [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows
  • 3a15b4a [16.3.x] [next/image]: disable avif image optimization
  • 7378b51 Backport/docs fixes 16.3 (#97649)
  • 528c1cd [16.3.x] Stop generating error codes (#97780)
  • d0ac882 v16.3.2
  • 81deb92 [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...
  • cd714d9 [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • 5ac2327 [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • 0ccb3e7 [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • Additional commits viewable in compare view

Updates baseline-browser-mapping from 2.10.31 to 2.11.23

Release notes

Sourced from baseline-browser-mapping's releases.

v2.11.0

What's Changed in 2.11.0

  • feat: Adds a new getTimeline() method for getting the series of minimum browser changes, either grouped by date or by browser.
  • refactor: Substantial refactoring of the data compression process that replaces the full list of browsers from @mdn/browser-compat-data and downstream-browsers.json and features from web-features (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date. Thanks to @​swwind for the idea!
  • refactor: Some common functions have been moved to a util.ts module for use in other scripts.
  • fix: Removes process.exit() calls when unsupported option combinations are passed to getCompatibleVersions() and getAllVersions() in favour of throwing an Error. There is a small security risk with process.exit() calls that sites accepting unsanitised inputs could be the subject of attacks. Unsupported config options now throw and Error which should allow for more graceful handling. Thanks to @​bnbdr for flagging this as vulnerability CVE-2026-45819 .

Fixes #134

Full Changelog: web-platform-dx/baseline-browser-mapping@v2.10.44...v2.11.0

Commits
  • ebdc72f Patch to 2.11.23 because browser or feature data changed
  • 55fa3a1 Browser or feature data changed
  • 5ac60db Updating static site
  • af7c3c4 Patch to 2.11.22 because browser or feature data changed
  • 7e10cad Browser or feature data changed
  • ebb9702 Updating static site
  • ecc57a3 Updating static site
  • 0e5ed80 Patch to 2.11.21 because browser or feature data changed
  • 11da0b6 Browser or feature data changed
  • 69fcc81 Updating static site
  • Additional commits viewable in compare view

Updates sharp from 0.35.3 to 0.35.4

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view

Copilot AI lite review requested due to automatic review settings September 14, 2026 13:10
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 14, 2026 13:10
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@github-actions

github-actions Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Apollo Coded App preview deployments are ready.

Project Status Preview Updated (PT)
apollo-design Skipped Logs Sep 14, 2026, 06:34:09 AM
apollo-docs Skipped Logs Sep 14, 2026, 06:34:09 AM
apollo-landing Skipped Logs Sep 14, 2026, 06:34:09 AM
apollo-vertex Skipped Logs Sep 14, 2026, 06:34:09 AM

@github-actions

Copy link
Copy Markdown
Contributor

📊 Coverage + size by package

Per-package bundle size on this PR (no JS/TS source changes detected under packages/* or web-packages/*).

Package Coverage New-line coverage Packed (gzip) Unpacked vs main
@uipath/apollo-core
@uipath/apollo-react
@uipath/apollo-ui-icons
@uipath/apollo-wind
@uipath/ap-chat

"Coverage" is each package's own coverage.include scope (e.g. apollo-core instruments only scripts/). "Packed"/"Unpacked" come from npm pack --dry-run and only cover built packages — "—" means not measured this run (package not affected / not built). "vs main" is the packed (gzipped) delta against the last successful main build (the package-sizes artifact from the Release workflow); "—" there means no main baseline was available this run. The baseline is main's latest build, not this PR's exact merge-base, so it includes any drift since the branch diverged. Packages with no vitest config are omitted.

@github-actions

github-actions Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Storybook visual diff

⏭️ Skipped: the apollo-design preview deployment did not succeed, so no comparison ran. Logs

Updated (PT): Sep 14, 2026, 06:34:10 AM

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Address the lockfile churn and add or await the required release-age exemptions.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates security-sensitive dependencies across Apollo’s documentation and Vertex apps.

Changes:

  • Upgrades Next.js to 16.3.3.
  • Updates Tiptap Core to 3.30.5.
  • Updates Sharp and baseline browser mapping dependencies.
  • Refreshes the pnpm lockfile.
File summaries
File Summary
pnpm-lock.yaml Contains moderate unreviewed toolchain churn and two critical missing release-age exemptions for @tiptap/core@3.30.5 and next@16.3.3.
apps/apollo-vertex/package.json Updates Next.js.
apps/apollo-docs/package.json Updates Next.js.
Review details

Files not reviewed (1)

  • pnpm-lock.yaml: Generated file
  • Files reviewed: 2/3 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pnpm-lock.yaml
Comment on lines +6263 to +6264
'@tiptap/core@3.30.5':
resolution: {integrity: sha512-3O7N0FyKIfuLV+xrdWyDM3V5eUY/q2CgLjhhMwOAbM1Pu7VPp9VP+TpEYOdH8aRyB+h1vj5hX5A747D8ZrPfHA==}
Comment thread pnpm-lock.yaml
Comment on lines +10507 to +10508
next@16.3.3:
resolution: {integrity: sha512-tuRTx1nQ/yVw83cwJBo9F+njGUgMn3UHQycreWHB8XsStvvAh1AthbI8/4IpKnFaF58F+iSiHejYOlMQ/eq83g==}
Comment thread pnpm-lock.yaml
vite:
specifier: ^7.3.6
version: 7.3.6(@types/node@24.10.1)(jiti@2.7.0)(lightningcss@1.32.0)(terser@5.43.1)(tsx@4.22.4)(yaml@2.8.3)
version: 7.3.6(@types/node@24.10.1)(jiti@2.7.0)(lightningcss@1.33.0)(terser@5.43.1)(tsx@4.22.4)(yaml@2.8.3)
…updates

Bumps the security group with 2 updates in the / directory: [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) and [next](https://github.com/vercel/next.js).


Updates `@tiptap/core` from 3.30.4 to 3.30.5
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.30.5/packages/core/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.5/packages/core)

Updates `next` from 16.2.11 to 16.3.3
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.11...v16.3.3)

Updates `baseline-browser-mapping` from 2.10.31 to 2.11.23
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.10.31...v2.11.23)

Updates `sharp` from 0.35.3 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.3...v0.35.4)

---
updated-dependencies:
- dependency-name: "@tiptap/core"
  dependency-version: 3.30.5
  dependency-type: direct:production
  dependency-group: security
- dependency-name: baseline-browser-mapping
  dependency-version: 2.11.23
  dependency-type: indirect
  dependency-group: security
- dependency-name: next
  dependency-version: 16.3.3
  dependency-type: direct:production
  dependency-group: security
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: indirect
  dependency-group: security
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings September 14, 2026 13:31
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/security-c0667e47bf branch from c4b2118 to f5144d4 Compare September 14, 2026 13:31

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved dependency constraints, quarantine exemptions, and unrelated lockfile churn remain.

Get a fresh assessment by requesting another Copilot review.

Review details

Files not reviewed (1)

  • pnpm-lock.yaml: Generated file

Suppressed comments (3)

pnpm-lock.yaml:672

  • The lockfile now selects @tiptap/core@3.30.5, but pnpm-workspace.yaml only exempts @tiptap/core@3.30.4 from the repository's 14-day release quarantine. Because the override is >=3.30.4, a fresh install can reject or resolve back to the still-vulnerable 3.30.4 instead of reliably installing this security fix. Add a version-scoped exemption for 3.30.5 after vetting that release.
    pnpm-lock.yaml:9912
  • This lockfile update re-resolves unrelated toolchain packages in addition to the four updates described by the PR: for example, Vite's lightningcss moves from 1.32.0 to 1.33.0 even though neither next nor Tiptap requires Vite. Similar unrelated ESLint, Acorn, js-yaml, flatted, and picomatch changes are included elsewhere. Please regenerate the lockfile surgically so the PR does not ship unreviewed dependency churn.
    pnpm-lock.yaml:10508
  • The repository's quarantine configuration has a name-scoped exemption for @next/*, but not for the unscoped next package. This introduces next@16.3.3 without a version-scoped exemption; because this is the new critical security release, add next@16.3.3 after the required vetting (or document that it has aged past 14 days), otherwise clean installs can reject or resolve this update differently.
  • Files reviewed: 2/3 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread pnpm-lock.yaml
'@tiptap/core':
specifier: '>=3.30.4'
version: 3.30.4(@tiptap/pm@3.30.4)
version: 3.30.5(@tiptap/pm@3.30.4)
@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/security-c0667e47bf branch September 15, 2026 04:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app:apollo-vertex dependencies Pull requests that update a dependency file size:XL 500-999 changed lines.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants