chore(deps): patch and deduplicate browserslist - #4351
martinothamar merged 1 commit into
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
2 failed runs, different tests flaking, so every test has been green once 😅 |
Description
Updates and deduplicates Browserslist 4.24.5, 4.25.2 and 4.28.1 to 4.28.7 to remove the dependency affected by CVE-2026-73089 (unbounded cache growth). Current build queries are repository-controlled, so no exploitable application path was found; this is preventive dependency maintenance.
Updated the Yarn lockfile resolution, ran targeted Browserslist deduplication, and refreshed its required browser-data dependencies. All existing parent ranges accept 4.28.7; no manifest overrides or application changes were needed.
Risk assessment
Low risk. The update stays within all existing dependency ranges and affects build tooling. Refreshed browser data can change the targets selected by queries such as
>0.2%, potentially changing Babel transforms or polyfills. The production Webpack build explicitly targetses2020, which limits this impact. Builds, type checks, lint, and 295 targeted tests passed; deployed behavior in older browsers was not manually tested.Related Issue(s)
Verification/QA
yarn tsc,yarn lint, andyarn build.kind/dependenciesandbackport-ignore(the PR author lacks label permissions).