Skip to content

fix(deps): patch transitive toolchain advisories - #8

Merged
yairEO merged 1 commit into
masterfrom
security-patch
Sep 25, 2026
Merged

yairEO merged 1 commit into
masterfrom
security-patch

Conversation

@yairEO

@yairEO yairEO commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Summary

  • Clear 22 osv-scanner advisories (15 high) in the dev and example lockfiles. The findings are in Storybook, Vitest, tsup, and the non-TS demo, not in the published package. Rollup and Vite still matter because they cover build-time file writes and the dev server.
  • Pin the vulnerable root copies with pnpm.overrides, staying inside the ranges those parents already allow. Storybook and Vitest stay on Vite 7 (7.2.2 → 7.3.6) rather than moving to Vite 8. Also: Rollup 4.53.2 → 4.63.5, @babel/core 7.28.5 → 7.29.7 (Babel 8 is out of range for react-docgen), browserslist 4.28.0 → 4.29.1, picomatch@^4.0.3 → 4.0.7, and brace-expansion@^5.0.5 → 5.0.12. The picomatch and brace-expansion selectors match only those ranges.
  • Bump examples/react-non-ts-demo from vite@^8.0.11 to ^8.3.1. That release requires postcss@^8.5.28, which requires nanoid@^3.3.18, so the demo lockfile now resolves Vite 8.3.1, PostCSS 8.5.28, and nanoid 3.3.19. pnpm-workspace.yaml excludes vite@8.3.1 from the minimum release-age check, the same exception examples/vanilla-demo already uses.

Test plan

  • osv-scanner scan -r . reports no issues
  • pnpm run build succeeds with the updated Rollup
  • pnpm storybook still starts on Vite 7.3.6
  • pnpm test-storybook passes
  • pnpm --dir examples/react-non-ts-demo dev starts on Vite 8.3.1

Made with Cursor

osv-scanner reported 22 advisories in the dev and example
lockfiles (15 high). They sit in Storybook, Vitest, tsup, and
the non-TS demo, not in the published package. Rollup and Vite
still matter: the findings cover build-time file writes and
the dev server.

Root parents already accepted the patched releases, but the
lockfile had kept older copies. pnpm.overrides forces those
copies without moving Storybook or Vitest onto Vite 8:

- vite 7.2.2 -> 7.3.6
- rollup 4.53.2 (tsup) -> 4.63.5
- @babel/core 7.28.5 -> 7.29.7 (stay on 7; react-docgen
  accepts ^7.28.0)
- browserslist 4.28.0 -> 4.29.1
- picomatch ^4.0.3 -> 4.0.7
- brace-expansion ^5.0.5 -> 5.0.12

The picomatch and brace-expansion selectors match only the
vulnerable ranges, so other majors stay put.

examples/react-non-ts-demo had vite 8.0.11, which pulled
postcss 8.5.14 and nanoid 3.3.11. vite ^8.3.1 requires
postcss ^8.5.28, which requires nanoid ^3.3.18. The lockfile
resolves vite 8.3.1, postcss 8.5.28, and nanoid 3.3.19.
pnpm-workspace.yaml excludes vite@8.3.1 from the minimum
release-age check, the same exception vanilla-demo already
uses.

osv-scanner scan -r . is clean. pnpm run build succeeds.

Co-authored-by: Cursor <cursoragent@cursor.com>
@yairEO
yairEO merged commit e3dd53e into master Sep 25, 2026
4 checks passed
@yairEO yairEO self-assigned this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant