Skip to content

Fix Dependabot security alerts - #259

Open
lio-p wants to merge 2 commits into
clickgemsfrom
fix-dependabot-alerts-sep-2026-clickgems
Open

Fix Dependabot security alerts#259
lio-p wants to merge 2 commits into
clickgemsfrom
fix-dependabot-alerts-sep-2026-clickgems

Conversation

@lio-p

@lio-p lio-p commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Same security bump as ClickPy: Next.js 15.5.25, PostCSS 8.5.23, and patched transitive overrides (brace-expansion, browserslist, nanoid, js-yaml, protobufjs, fflate, sharp).

Left unpatched (breaking majors)

  • echarts 5.6 → 6.1: XSS is in the lines (geo) series tooltip. We only use regular line charts, so this is not reachable.
  • @opentelemetry/core 1.x → 2.8: no 1.x backport; would force HyperDX / @vercel/otel majors.

Test plan

  • Vercel preview builds on Node 22
  • Homepage + a gem dashboard still render (charts, images, date picker)

Made with Cursor

…tives.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clickgems Ready Ready Preview Sep 9, 2026 1:54pm UTC
clickpy Error Error Sep 9, 2026 1:54pm UTC

Request Review

…ing alerts.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant