Skip to content

ENG-2236 Update tooling dependencies for five reviewed security alerts - #1409

Closed
mdroidian wants to merge 1 commit into
mainfrom
eng-2236-update-tooling-dependencies-for-five-reviewed-security
Closed

ENG-2236 Update tooling dependencies for five reviewed security alerts#1409
mdroidian wants to merge 1 commit into
mainfrom
eng-2236-update-tooling-dependencies-for-five-reviewed-security

Conversation

@mdroidian

@mdroidian mdroidian commented Sep 7, 2026

Copy link
Copy Markdown
Member

Reviewer brief

Updates the transitive dependencies for five reviewed alerts from ENG-2235 using version-scoped overrides:

Alerts Dependency Patched version
#515 tar 7.x 7.5.19
#600 browserslist 4.x 4.28.7
#583, #584 brace-expansion 1.x / 2.x 1.1.18 / 2.1.4
#571 js-yaml 4.x 4.3.1

Overrides apply only to affected versions within existing majors, including versions pinned by tooling parents. The lockfile includes Browserslist's required data/helper updates and preserves existing application importers and unrelated peer resolutions.

The js-yaml 3.x shared-import issue (#567) remains separate. JavaScript frontmatter remediation is deferred to the v1 import work tracked in ENG-1925.

Closes ENG-2236.

Verification

  • pnpm install --frozen-lockfile: passed.
  • pnpm exec turbo run test:unit --ui stream: all four workspace tasks passed.
  • Dependency smoke checks: gzip archive create/extract, both brace-expansion majors, YAML load/dump, Browserslist query, and Obsidian's PostCSS/Autoprefixer processing passed.
  • Lockfile graph references, patched version selection, unchanged importers, formatting, and git diff --check: passed.
  • pnpm ci:validate: blocked locally by React type conflicts in @repo/ui. The same errors reproduce with unchanged main's lockfile and workspace configuration using an uncached pnpm --filter @repo/ui check-types. Baseline full validation also reports website React type errors. GitHub CI validation, formatting, and lint checks passed on the PR commit. The Vercel preview build also passed.

Scope check

  • Ran $scope-check against ENG-2236 and the final diff.
  • Scope beyond Done When: None.

Local delegated full review

  • Delegated review was not run. The full two-file diff was reviewed locally.

Loom video

No recording attached.

@linear-code

linear-code Bot commented Sep 7, 2026

Copy link
Copy Markdown

ENG-2236

@vercel

vercel Bot commented Sep 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
discourse-graph Ready Ready Preview Sep 7, 2026 6:17am UTC

Request Review

@supabase

supabase Bot commented Sep 7, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project zytfjzqyijgagqxrzbmz because there are no changes detected in packages/database/supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 7, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-07T06:22:06.572767Z 08cc8bb Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mdroidian mdroidian closed this Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant