chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): bump transitive dependencies - #1092

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps
Apr 3, 2026
Merged

chore(deps): bump transitive dependencies#1092
brendan-kellam merged 2 commits into
mainfrom
brendan/bump-vulnerable-transitive-deps

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add yarn resolution for path-to-regexp to ^8.4.0 (resolved to 8.4.2)
  • Add yarn resolution for picomatch@^4 to ^4.0.4 (scoped to v4 consumers only, v2 consumers unaffected)
  • Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which pulls in a patched fast-xml-parser@5.5.8 via the natural dependency chain

Test plan

  • Verify yarn install succeeds
  • Verify application builds and starts correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated and resolved package dependencies to enhance build stability, compatibility, and security; added additional dependency resolutions to ensure consistent installs across environments.
    • Bumped an AWS SDK dependency used by the web package to a newer patch release to incorporate reliability and compatibility fixes.

Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4
(^4.0.4), and fast-xml-parser (^5.5.6) to patched versions.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated dependency constraints: added Yarn resolutions entries for path-to-regexp and picomatch in the root package.json, and bumped @aws-sdk/credential-providers in packages/web/package.json from ^3.1000.0 to ^3.1023.0.

Changes

Cohort / File(s)Summary
Root package.json (resolutions)
package.json
Added Yarn resolutions entries: path-to-regexp@^8.4.0 and picomatch@^4.0.4; existing @opentelemetry/resources@2.5.1 remains unchanged.
Web package dependency
packages/web/package.json
Bumped @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately describes the main purpose of the PR—bumping vulnerable transitive dependencies through yarn resolutions and SDK upgrades.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bump-vulnerable-transitive-deps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@package.json`:
- Around line 41-43: Replace the caret ranges in the resolutions entry with
exact pinned versions to ensure deterministic builds: remove the leading ^ from
the version strings for "path-to-regexp", "picomatch@^4" and "fast-xml-parser"
so they read as exact versions (e.g., 8.4.0, 4.x.y, 5.5.6 matching the resolved
versions in the PR), updating the values in package.json's resolutions block
accordingly.
- Line 41: The resolutions entry forcing "path-to-regexp": "^8.4.0" conflicts
with express@4.21.2 (which requires path-to-regexp@0.1.12) and will break
routing; fix by removing or changing that resolution in package.json (the
"path-to-regexp": "^8.4.0" line) or alternatively upgrade express to a version
that officially supports path-to-regexp v8+, then run install and test routes to
ensure no runtime failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 47346901-c359-4dc9-853d-6e076373ff28

📥 Commits

Reviewing files that changed from the base of the PR and between 14143e2 and c488280.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment threadpackage.json Outdated
Comment threadpackage.json
… resolution
Bump @aws-sdk/credential-providers from ^3.1000.0 to ^3.1023.0, which
pulls in @aws-sdk/xml-builder@3.972.16 with fast-xml-parser@5.5.8
(patched). This removes the need for a fast-xml-parser resolution override.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

github-actionsBot commented Apr 3, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2122
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft27

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.3.1(MPL-2.0 OR Apache-2.0)
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab (MIT License confirmed via GitHub API)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir (Apache-2.0 confirmed via GitHub API)
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source (MIT License confirmed via GitHub API)
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir (Apache-2.0 confirmed via GitHub API)
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream (MIT License confirmed via GitHub API)
memorystream0.3.1UNKNOWNMITnpm registry — licenses array contains {"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}; extracted type field
pause-stream0.0.11["MIT","Apache2"]MIT AND Apache-2.0npm registry — license field is an array ["MIT","Apache2"]; dual-licensed under both permissive licenses
posthog-js1.345.5SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file confirms Apache License 2.0
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file confirms MIT license

@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencies via resolutionschore(deps): bump vulnerable transitive dependenciesApr 3, 2026
@brendan-kellam
brendan-kellam merged commit 0bb84e7 into mainApr 3, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bump-vulnerable-transitive-deps branch April 3, 2026 00:49
@github-actionsgithub-actionsBot mentioned this pull request Apr 3, 2026
@brendan-kellambrendan-kellam changed the title chore(deps): bump vulnerable transitive dependencieschore(deps): bump transitive dependenciesApr 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam