Skip to content

chore(deps): refresh lockfiles for braces, picomatch, postcss-selector-parser - #169

Open
devtools-agent[bot] wants to merge 1 commit into
mainfrom
deps/lockfile-refresh-dependabot
Open

devtools-agent[bot] wants to merge 1 commit into
mainfrom
deps/lockfile-refresh-dependabot

Conversation

@devtools-agent

Copy link
Copy Markdown

What changed

These are lockfile-only bumps that stay inside the existing semver ranges. No package.json changes.

Lockfile Package From → To Alerts
package-lock.json braces (+ fill-range 7.0.1 → 7.1.1, required by braces) 3.0.2 → 3.0.3 #124 (high)
examples/nextjs/package-lock.json picomatch 2.3.1 → 2.3.2 #433
examples/nextjs/package-lock.json postcss-selector-parser 6.1.2 → 6.1.4 #690
examples/nextjs-approuter/package-lock.json picomatch 2.3.1 → 2.3.2 #434
examples/nextjs-approuter/package-lock.json postcss-selector-parser 6.1.2 → 6.1.4 #691

Why

This clears 5 of the 9 open Dependabot alerts in one PR. Each package is already allowed by its parent's version range: braces via micromatch/chokidar, picomatch via micromatch/anymatch/readdirp/jest-util, and postcss-selector-parser via tailwindcss@3.4 ^6.0.11. A plain npm update <pkg> resolves them.

The Next example lockfiles were missed when #164 bumped picomatch in the root lockfile only.

Supersedes #168. The root package-lock.json diff here matches Dependabot's braces PR line for line (+11/−7). Close #168 once this merges.

The other 4 alerts (react-router in examples/react-17 and examples/typescript, #626/#627/#633/#719) are not addressed here. They're only fixed in react-router 7.18+, which requires React ≥18, so they're being handled separately.

How I validated

I used npm 10.9 on Node 20.19, matching CI's node: 20 / npm: 10 job. I generated the lockfiles with npm run install:all -- ci followed by targeted npm update. I then deleted every node_modules and ran the CI steps from scratch:

  • npm run install:all -- ci ✅ (npm ci accepts all updated lockfiles)
  • npm run lint:examples ✅, eslint --max-warnings 0 ✅
  • npm run typecheck ✅
  • npm run build:all ✅ (includes next build for both Next examples)
  • npm run test ✅ (13 tests), npm run test:examples ✅
  • npm audit no longer reports braces, picomatch or postcss-selector-parser in any of the three projects

I reverted the .yalc/@rollbar/react build-signature hash that the local build rewrote, so the diff contains only the dependency bumps.

🤖 Generated with Claude Code

…r-parser

Lockfile-only bumps within existing semver ranges; no package.json changes.

- package-lock.json: braces 3.0.2 -> 3.0.3 (fill-range 7.0.1 -> 7.1.1)
- examples/nextjs, examples/nextjs-approuter: picomatch 2.3.1 -> 2.3.2,
  postcss-selector-parser 6.1.2 -> 6.1.4

Resolves Dependabot alerts #124, #433, #434, #690, #691.
Supersedes #168.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rollbar-circleci-machine

Copy link
Copy Markdown
Contributor

AI Agent Review LGTM (openai, openai-astra)

LGTM. No blocking findings were found.

LGTM: lockfile-only refresh, nothing to flag

What changed

  • Root package-lock.json: braces goes from 3.0.2 to 3.0.3 and fill-range from 7.0.1 to 7.1.1. braces now requires fill-range ^7.1.1 (package-lock.json:5238-5250, package-lock.json:7180-7192). is-number and to-regex-range only gain "license": "MIT" metadata.
  • examples/nextjs and examples/nextjs-approuter: picomatch goes from 2.3.1 to 2.3.2 and postcss-selector-parser from 6.1.2 to 6.1.4 (examples/nextjs/package-lock.json:8277-8289, :8523-8536; examples/nextjs-approuter/package-lock.json:8377-8389, :8623-8636).

Checks

  • Root install matches the lockfile. The pipeline ran npm ci against the root lockfile, which checks each package's integrity hash. The installed packages are the new versions: node_modules/braces/package.json:4 is 3.0.3, node_modules/fill-range/package.json:4 is 7.1.1, and node_modules/picomatch/package.json:4 is 2.3.2.
  • Every dependent still accepts the new versions.
    • Root: chokidar needs braces ~3.0.2 (package-lock.json:5412), micromatch needs ^3.0.2 (:10918), and all picomatch dependents use ^2.x ranges (:3448, :4772, :10240, :10919, :11868).
    • Examples: postcss-selector-parser dependents need ^6.1.1 or ^6.0.11 (examples/nextjs/package-lock.json:8514, :9710; examples/nextjs-approuter/package-lock.json:8614, :9823). picomatch 2.x dependents use ^2.x ranges.
  • No other copies of these packages were left behind. The examples have no second postcss-selector-parser entry. The only other picomatch there is the separate 4.x line under tinyglobby.
  • The examples' new picomatch 2.3.2 entry is identical to the root's. It has the same resolved URL and integrity hash that the root install already accepted.

What I could not check

  • The postcss-selector-parser@6.1.4 hash. The example projects were not installed and nothing in the root depends on this package, so I had no way to check this hash offline. CI's install of the examples will confirm it.

Outside the changed lines (for information, not a finding)

  • micromatch is still 4.0.5 in the root lockfile (package-lock.json:10912-10924). It depends on braces ^3.0.2, so this PR does not break it. However, 4.0.5 is older than the 4.0.8 the example lockfiles already use (examples/nextjs/package-lock.json:7670-7683), and 4.0.8 is the release that fixed the micromatch ReDoS advisory. Bumping it in a follow-up would bring the root in line with the examples.

I did not run any tests, and the diff does not show CI results.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants