Skip to content

Refresh vulnerable dev dependencies in the lockfile - #1069

Merged
GaryJones merged 1 commit into
developfrom
GaryJones/refresh-lockfile-security
Oct 10, 2026
Merged

GaryJones merged 1 commit into
developfrom
GaryJones/refresh-lockfile-security

Conversation

@GaryJones

Copy link
Copy Markdown
Contributor

Summary

Eight of the open Dependabot security alerts are for transitive development dependencies whose fixed versions already fit their parents' version ranges, but the lockfile still held older copies and Dependabot never raised updates for them. This PR refreshes js-yaml 4.x, @babel/core, ws and minimatch within their existing ranges, and removes the stale nested copies under cosmiconfig and @wordpress/scripts so the current versions are used everywhere. package.json is untouched.

That should close Dependabot alerts 309, 281, 265 and 238 (js-yaml), 231 (@babel/core), 229 (ws), and 169 and 171 (minimatch). All of these are build and test tooling, so nothing shipped in the plugin changes.

The remaining 13 alerts have been dismissed as a tolerable risk, because each fix needs a major version that the latest upstream parent doesn't allow yet. They cover @wordpress/env (simple-git, got, js-yaml 3), markdownlint-cli's pinned smol-toml and js-yaml 5, katex, cssnano 6's postcss-selector-parser, serialize-javascript via @wordpress/scripts' webpack plugins, and uuid via sockjs. They're all development-only, and can be picked up when Gutenberg updates those packages.

Test plan

  • npm ci from the new lockfile, which resolves only from registry.npmjs.org
  • npm run test-js: 18/18 pass
  • npm run lint-js and npm run build succeed
  • CI green, and the eight alerts close once this reaches develop

Several open Dependabot security alerts were for transitive development
dependencies whose fixed versions already satisfy their parents' version
ranges, but the lockfile still held older copies and Dependabot had not
raised updates for them. Refreshing js-yaml 4.x, @babel/core, ws and
minimatch within their existing ranges, and deduplicating the stale
nested copies under cosmiconfig and @wordpress/scripts, clears those
alerts without touching package.json.

All of these packages are build and test tooling, so nothing shipped in
the plugin changes.
@GaryJones
GaryJones requested a review from a team as a code owner October 10, 2026 16:55
@GaryJones GaryJones added this to the Next milestone Oct 10, 2026
@GaryJones GaryJones added the type: maintenance Routine maintenance and code quality improvements label Oct 10, 2026
@GaryJones GaryJones self-assigned this Oct 10, 2026
@GaryJones
GaryJones merged commit e2055ab into develop Oct 10, 2026
10 checks passed
@GaryJones
GaryJones deleted the GaryJones/refresh-lockfile-security branch October 10, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: maintenance Routine maintenance and code quality improvements

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant