Skip to content

fix: bump dompurify and brace-expansion in lockfile to latest patch releases - #146

Merged
hivecommons-hive[bot] merged 1 commit into
mainfrom
deps/bump-dompurify-brace-expansion
Oct 1, 2026
Merged

hivecommons-hive[bot] merged 1 commit into
mainfrom
deps/bump-dompurify-brace-expansion

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Summary

Raises two overrides floors in package.json and regenerates package-lock.json so the lockfile resolves the latest patch releases:

package from to path
dompurify 3.4.13 3.4.16 runtime, via mermaid (src/lib/Mermaid.tsx)
brace-expansion 2.1.4 2.1.7 dev-only, via minimatch@3.1.4

Ranges are kept conservative (^2.1.7 for brace-expansion, not >=, so minimatch 3 is not pushed onto brace-expansion 5.x).

Files

  • package.json — overrides.dompurify, overrides.brace-expansion
  • package-lock.json — regenerated with npm install --package-lock-only
  • changelog.d/fixed-bump-dompurify-brace-expansion.md

Disjoint from #145 (which only touches src/components/docs/EditPageLink.tsx).

Test plan

  • npm ci --ignore-scripts succeeds
  • npx vitest run src/__tests__/Mermaid.test.tsx — 3 passed
  • npm audit — 0 vulnerabilities

Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.

— hive: agent=sec-check backend=copilot model=claude-fable-5.1 copilot=1.0.88

…eleases

Raise the `overrides` floors in package.json so the lockfile resolves
dompurify 3.4.16 (via mermaid) and brace-expansion 2.1.7 (via minimatch 3),
and regenerate package-lock.json. No code changes; `npm ci` and the
Mermaid tests pass.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will automatically remove the hold label once current policy no longer requires a level hold for "sec-check". If this is an outreach PR, a human must review it and remove the label.

@kubestellar-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign clubanderson for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for hivecommons-docs ready!

Name Link
🔨 Latest commit f555940
🔍 Latest deploy log https://app.netlify.com/projects/hivecommons-docs/deploys/6abdb9ca7d64b70008023d25
😎 Deploy Preview https://deploy-preview-146--hivecommons-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified against the registry, not just the diff. Looks correct to me.

  • package-lock.json integrity hashes for dompurify@3.4.16 and brace-expansion@2.1.7 match registry.npmjs.org exactly.
  • npm ci --ignore-scripts on this head succeeds; npm ls shows a single dompurify@3.4.16 (deduped) and brace-expansion@2.1.7.
  • The ^2.1.7 range for brace-expansion is the right call for the reason the body gives — >= would let minimatch@3 pick up a 5.x major. The override already forced all brace-expansion consumers onto 2.x on main (^2.0.1), so this is a patch bump with no new resolution change; the lockfile diff only drops the now-extraneous brace-expansion/1.1.7 entry.
  • changelog.d/fixed-bump-dompurify-brace-expansion.md follows the <category>-<slug>.md naming.

No findings.

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot removed the hold label Oct 1, 2026
@hivecommons-hive
hivecommons-hive Bot merged commit e1a9718 into main Oct 1, 2026
9 of 10 checks passed
@kubestellar-prow
kubestellar-prow Bot deleted the deps/bump-dompurify-brace-expansion branch October 1, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants