chore(deps): bump the npm_and_yarn group across 3 directories with 6 updates#1150
chore(deps): bump the npm_and_yarn group across 3 directories with 6 updates#1150dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
|
To enable Rovo Dev code reviews, link your GitHub account to your Atlassian account. This is a one-time task that takes less than a minute. Once your account is linked, resubmit the pull request to trigger a code review. |
✅ Deploy Preview for learncarddocs canceled.
|
❌ Deploy Preview for staging-learncardapp failed. Why did it fail? →
|
|
✅ Deploy Preview for app-store-1-basic-launchpad-app canceled.
|
|
👋 Hey there! It looks like you modified code, but didn't update the documentation in If this PR introduces new features, changes APIs, or modifies behavior that users or developers need to know about, please consider updating the docs. 🏄 Windsurf TipYou can ask Windsurf to help:
Windsurf will review your changes and suggest appropriate documentation updates based on what was modified. 📚 Documentation Guide
This is an automated reminder. If no docs are needed, feel free to ignore this message. |
|
This PR is missing a Jira ticket reference in the title or description. |
a095dd3 to
55e7610
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
55e7610 to
c3f079a
Compare
c3f079a to
f577cb1
Compare
f577cb1 to
62c26ee
Compare
62c26ee to
2f32a09
Compare
2f32a09 to
1c3cecd
Compare
1c3cecd to
7fca1e2
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
@claude review |
|
Claude finished @Custard7's task —— View job PR Review Complete ✅Todo List
Review SummaryDecision: Cannot Auto-Approve - Multiple hard-stop rules triggered, requires manual review. This dependabot PR contains critical security updates but cannot be auto-approved due to scope and scale: ✅ Security Benefits
❌ Hard-Stop Rules Triggered
RecommendationManual review required to validate compatibility across the monorepo's 30+ packages before merging these important security updates. |
There was a problem hiding this comment.
This dependabot PR contains critical security updates but cannot be auto-approved due to several hard-stop rules:
Security Updates (Positive)
✅ Critical fixes included:
- axios 0.27.2→1.15.0: DoS vulnerability fix (prototype pollution via proto key)
- node-forge 1.3.1→1.4.0: Multiple HIGH CVEs - DoS, RSA signature forgery, Ed25519 signature malleability, certificate chain validation bypass
- happy-dom 14.12.3→20.8.9: VM context escape fixes, cookie forwarding vulnerability patches
- vite 4.3.8→6.4.2: File system security checks and other security improvements
- rollup 2.79.2→2.80.0: Bundle validation security feature
Hard-Stop Rules Triggered (Blocking Auto-Approval)
❌ Root monorepo lockfile changes: (+3051/-1425 lines)
❌ Major version bumps: Multiple packages with breaking change potential
❌ Change size limit exceeded: 4,554 total lines >> 750 line lane limits
❌ Root workspace dependency impact: Affects core build infrastructure
Recommendation
Requires manual review due to:
- Scale of changes across build toolchain
- Major version bumps needing compatibility validation
- Potential for build/runtime breaking changes despite security benefits
The security fixes are important, but the scope requires human oversight to ensure compatibility across the monorepo's 30+ packages.
There was a problem hiding this comment.
This dependabot PR contains critical security updates but cannot be auto-approved due to several hard-stop rules:
Security Updates (Positive)
✅ Critical fixes included:
- axios 0.27.2→1.15.0: DoS vulnerability fix (prototype pollution via proto key)
- node-forge 1.3.1→1.4.0: Multiple HIGH CVEs - DoS, RSA signature forgery, Ed25519 signature malleability, certificate chain validation bypass
- happy-dom 14.12.3→20.8.9: VM context escape fixes, cookie forwarding vulnerability patches
- vite 4.3.8→6.4.2: File system security checks and other security improvements
- rollup 2.79.2→2.80.0: Bundle validation security feature
Hard-Stop Rules Triggered (Blocking Auto-Approval)
❌ Root monorepo lockfile changes: pnpm-lock.yaml (+3051/-1425 lines)
❌ Major version bumps: Multiple packages with breaking change potential
❌ Change size limit exceeded: 4,554 total lines >> 750 line lane limits
❌ Root workspace dependency impact: Affects core build infrastructure
Recommendation
Requires manual review due to:
- Scale of changes across build toolchain
- Major version bumps needing compatibility validation
- Potential for build/runtime breaking changes despite security benefits
The security fixes are important, but the scope requires human oversight to ensure compatibility across the monorepo's 30+ packages.
7fca1e2 to
faea55a
Compare
|
🥷 Code experts: TaylorBeeston, Custard7 TaylorBeeston, Custard7 have most 👩💻 activity in the files. See details
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame:
Activity based on git-commit:
Knowledge based on git-blame: ✨ Comment |
…updates Bumps the npm_and_yarn group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `4.3.8` | `5.4.21` | | [axios](https://github.com/axios/axios) | `0.27.2` | `0.30.3` | | [rollup](https://github.com/rollup/rollup) | `2.79.2` | `2.80.0` | | [happy-dom](https://github.com/capricorn86/happy-dom) | `14.12.3` | `20.8.9` | | [node-forge](https://github.com/digitalbazaar/forge) | `1.3.1` | `1.4.0` | Bumps the npm_and_yarn group with 1 update in the /packages/react-learn-card directory: [happy-dom](https://github.com/capricorn86/happy-dom). Bumps the npm_and_yarn group with 2 updates in the /scripts/siwa-migration directory: [node-forge](https://github.com/digitalbazaar/forge) and [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser). Updates `vite` from 4.3.8 to 5.4.21 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v5.4.21/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v5.4.21/packages/vite) Updates `axios` from 0.27.2 to 0.30.3 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.27.2...v0.30.3) Updates `rollup` from 2.79.2 to 2.80.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v2.79.2...v2.80.0) Updates `happy-dom` from 14.12.3 to 20.8.9 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v14.12.3...v20.8.9) Updates `node-forge` from 1.3.1 to 1.4.0 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@v1.3.1...v1.4.0) Updates `happy-dom` from 14.12.3 to 20.8.9 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v14.12.3...v20.8.9) Updates `rollup` from 2.79.2 to 2.80.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v2.79.2...v2.80.0) Updates `axios` from 0.27.2 to 0.30.3 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.27.2...v0.30.3) Updates `node-forge` from 1.3.1 to 1.4.0 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@v1.3.1...v1.4.0) Updates `vite` from 4.3.8 to 5.4.21 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v5.4.21/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v5.4.21/packages/vite) Updates `axios` from 0.27.2 to 0.30.3 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.27.2...v0.30.3) Updates `happy-dom` from 14.12.3 to 20.8.9 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v14.12.3...v20.8.9) Updates `node-forge` from 1.3.1 to 1.4.0 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@v1.3.1...v1.4.0) Updates `rollup` from 2.79.2 to 2.80.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v2.79.2...v2.80.0) Updates `vite` from 4.3.8 to 5.4.21 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v5.4.21/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v5.4.21/packages/vite) Updates `happy-dom` from 14.12.3 to 20.8.9 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v14.12.3...v20.8.9) Updates `node-forge` from 1.3.3 to 1.4.0 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@v1.3.1...v1.4.0) Updates `fast-xml-parser` from 5.3.6 to 5.5.10 - [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases) - [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md) - [Commits](NaturalIntelligence/fast-xml-parser@v5.3.6...v5.5.10) --- updated-dependencies: - dependency-name: vite dependency-version: 5.4.21 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 0.30.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.80.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: happy-dom dependency-version: 20.8.9 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: node-forge dependency-version: 1.4.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: happy-dom dependency-version: 20.8.9 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.80.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 0.30.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: node-forge dependency-version: 1.4.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 5.4.21 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 0.30.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: happy-dom dependency-version: 20.8.9 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: node-forge dependency-version: 1.4.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.80.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 5.4.21 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: happy-dom dependency-version: 20.8.9 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: node-forge dependency-version: 1.4.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fast-xml-parser dependency-version: 5.5.10 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
faea55a to
9017420
Compare
Bumps the npm_and_yarn group with 5 updates in the / directory:
4.3.85.4.210.27.20.30.32.79.22.80.014.12.320.8.91.3.11.4.0Bumps the npm_and_yarn group with 1 update in the /packages/react-learn-card directory: happy-dom.
Bumps the npm_and_yarn group with 2 updates in the /scripts/siwa-migration directory: node-forge and fast-xml-parser.
Updates
vitefrom 4.3.8 to 5.4.21Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
adce3c2release: v5.4.21cad1d31fix(dev): trim trailing slash beforeserver.fs.denycheck (#20968) (#20970)ca88ed7chore: update CHANGELOG997700frelease: v5.4.20482000ffix: applyfs.strictcheck to HTML files (#20736)80a333arelease: v5.4.19766947efix: backport #19965, check static serve file inside sirv (#19966)731b77drelease: v5.4.18823675bfix: backport #19830, reject requests with#in request-target (#19831)0a2518arelease: v5.4.17Updates
axiosfrom 0.27.2 to 0.30.3Release notes
Sourced from axios's releases.
... (truncated)
Commits
f53bcf6chore: release 0.30.23ddccd3chore: remove publish as this wont work9ef39d0chore: try with npm token4775de6chore: fix version schemef96f26bchore: fix issues with using replaceead45c2chore: update the publish workflow to run on tag8119265chore: tag version as legacy on v0.x9954985chore: dispatch for first time3f8b70fchore: final renamec665584chore: revert namingUpdates
rollupfrom 2.79.2 to 2.80.0Changelog
Sourced from rollup's changelog.
Commits
d17ae152.80.0d6dee5eValidate bundle stays within output dir (#6277)Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
happy-domfrom 14.12.3 to 20.8.9Release notes
Sourced from happy-dom's releases.
... (truncated)
Commits
68324c2fix: #2117 Fixes issue related to cookies from the current origin being for...5437fdffix: #2113 Fixes issue where export names can be interpolated as executable...7e97acbfix: #1845 Replace implementing Node js Console with common IConsole interf...3373929fix: #2106Request.formData()should honorContent-Typeheader (#2107)55c17bafix: #2110 Fixes error thrown when modifying DOM structure in connectedCall...82a0888fix: #1845 Replace ConsoleConstructor import with indexed access type (#2095)5998eeafix: #2054 Throw error if event is not of type Event in dispatchEvent (#2092)7a11238fix: #2090 Resets cancelBubble and defaultPrevented when calling initEvent ...7d27984fix: #1422 Make inert attribute block focus interactions (#2083)53e4ec9feat: #1733 Adds support for setPointerCapture, hasPointerCapture, and rele...Updates
node-forgefrom 1.3.1 to 1.4.0Changelog
Sourced from node-forge's changelog.
... (truncated)
Commits
fa385f9Release 1.4.0.07d4e16Update changelog.cb90fd9Update changelog.963e7c5Add unit test for "pseudonym"f0b6f5bAdd pseudonym OID3df48a3Fix missing CVE ID.2e49283Add x509basicConstraintscheck.bdecf11Add canonical signature scaler check for S < L.af094e6Add RSA padding and DigestInfo length checks.796eeb1Improve jsbn fix.Updates
happy-domfrom 14.12.3 to 20.8.9Release notes
Sourced from happy-dom's releases.
... (truncated)
Commits
68324c2fix: #2117 Fixes issue related to cookies from the current origin being for...5437fdffix: #2113 Fixes issue where export names can be interpolated as executable...7e97acbfix: #1845 Replace implementing Node js Console with common IConsole interf...3373929fix: #2106Request.formData()should honorContent-Typeheader (#2107)55c17bafix: #2110 Fixes error thrown when modifying DOM structure in connectedCall...82a0888fix: #1845 Replace ConsoleConstructor import with indexed access type (#2095)5998eeafix: #2054 Throw error if event is not of type Event in dispatchEvent (#2092)7a11238fix: #2090 Resets cancelBubble and defaultPrevented when calling initEvent ...7d27984fix: #1422 Make inert attribute block focus interactions (#2083)53e4ec9feat: #1733 Adds support for setPointerCapture, hasPointerCapture, and rele...Updates
rollupfrom 2.79.2 to 2.80.0Changelog
Sourced from rollup's changelog.
Commits
d17ae152.80.0d6dee5eValidate bundle stays within output dir (#6277)Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
axiosfrom 0.27.2 to 0.30.3Release notes
Sourced from axios's releases.
... (truncated)
Commits
f53bcf6chore: release 0.30.23ddccd3chore: remove publish as this wont work9ef39d0chore: try with npm token4775de6chore: fix version schemef96f26bchore: fix issues with using replaceead45c2chore: update the publish workflow to run on tag8119265chore: tag version as legacy on v0.x9954985chore: dispatch for first time3f8b70fchore: final renamec665584chore: revert namingUpdates
node-forgefrom 1.3.1 to 1.4.0Changelog
Sourced from node-forge's changelog.
... (truncated)
Commits
fa385f9Release 1.4.0.07d4e16Update changelog.cb90fd9Update changelog.963e7c5Add unit test for "pseudonym"f0b6f5bAdd pseudonym OID3df48a3Fix missing CVE ID.2e49283Add x509basicConstraintscheck.bdecf11Add canonical signature scaler check for S < L.af094e6Add RSA padding and DigestInfo length checks.796eeb1Improve jsbn fix.Updates
vitefrom 4.3.8 to 5.4.21Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
adce3c2release: v5.4.21cad1d31fix(dev): trim trailing slash beforeserver.fs.denycheck (#20968) (#20970)ca88ed7chore: update CHANGELOG997700frelease: v5.4.20482000ffix: applyfs.strictcheck to HTML files (#20736)80a333arelease: v5.4.19766947efix: backport #19965, check static serve file inside sirv (#19966)731b77drelease: v5.4.18823675bfix: backport #19830, reject requests with#in request-target (#19831)0a2518arelease: v5.4.17Updates
axiosfrom 0.27.2 to 0.30.3Release notes
Sourced from axios's releases.