Skip to content

chore(deps): bump xmldom, browserslist, fast-uri, js-yaml in package lockfiles - #154

Merged
ethanpschoen merged 1 commit into
mainfrom
ethan/chore/dep-security-bumps
Sep 25, 2026
Merged

ethanpschoen merged 1 commit into
mainfrom
ethan/chore/dep-security-bumps

Conversation

@ethanpschoen

@ethanpschoen ethanpschoen commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description of this change

Patch/minor bumps of dev-only transitive dependencies in package/, made with npm audit fix (no --force):

  • @xmldom/xmldom 0.8.13 → 0.8.15
  • browserslist 4.24.2 / 4.25.2 → 4.29.1
  • fast-uri 3.1.5 → 3.1.8
  • js-yaml 4.3.1 → 4.3.2 and 3.15.1 → 3.15.2

No package.json changes and no major version changes. None of these packages ship in the published tarball, because the package has no runtime dependencies.

npm updated package/yarn.lock in step with package-lock.json. CI and release install only from package-lock.json, so the checks below say nothing about the yarn.lock changes.

Not included: the 9 alerts on example/yarn.lock. The example app is never built by CI or published.

Why is this change being made?

  • Chore (non-functional changes)
  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

How was this tested? How can the reviewer verify your testing?

I replayed the CI build job locally in package/ on Node 23.11.0, first on clean main and then on this branch. The job runs npm ci, prepare, lint, typecheck, jest, npm run all, and the npm pack --dry-run tarball check.

  • Every step exits 0 on both.
  • jest --json reports 121 passed, 5 skipped, 0 failed (126 total) on both, the same as CI on main.
  • I diffed every changed lockfile entry against main, and no major version moved.

Node 20 and 22 weren't run locally; CI's matrix covers them. Required status checks aren't enforced on main and auto-merge is enabled, so please confirm the Build job is green before merging.

Related issues

Closes Dependabot alerts #434, #436, #438, #439, #440, #441, #443, #444, #445, #446, #447, #448, #451, #452, #454, #456, #457, #458, #459, #460, #461, #462, #463, #464, #465, #466, #467, #468, #471, #473, #474, #475.

Checklist

  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • I have evaluated the security impact of this change, and OWASP Secure Coding Practices have been observed.
  • I have informed stakeholders of my changes.

Note

Low Risk
Lockfile-only patch/minor dev dependency updates with no application code or published package dependency changes.

Overview
Refreshes dev-only transitive dependency versions in package/package-lock.json and package/yarn.lock via npm audit fix, with no changes to package.json or published runtime deps.

Browserslist stack is consolidated and bumped: browserslist moves to 4.29.1, adds baseline-browser-mapping, and updates caniuse-lite, electron-to-chromium, node-releases, and update-browserslist-db (duplicate nested copies under core-js-compat are removed). Patch bumps elsewhere: @xmldom/xmldom 0.8.15, fast-uri 3.1.8, js-yaml 3.15.2 / 4.3.2.

CI/release installs from package-lock.json only; the yarn lock stays in sync for local workflows.

Reviewed by Cursor Bugbot for commit 30c7181. Configure here.

…lockfiles

npm audit fix (no --force) in package/. Dev-only transitive deps move
within their major; package.json is unchanged.
@ethanpschoen
ethanpschoen marked this pull request as ready for review September 25, 2026 17:13
@ethanpschoen
ethanpschoen requested review from a team as code owners September 25, 2026 17:13
@ethanpschoen
ethanpschoen merged commit 2c8f7c1 into main Sep 25, 2026
13 checks passed
@ethanpschoen
ethanpschoen deleted the ethan/chore/dep-security-bumps branch September 25, 2026 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants