fix: bump dompurify and brace-expansion in lockfile to latest patch releases - #146
Conversation
…eleases Raise the `overrides` floors in package.json so the lockfile resolves dompurify 3.4.16 (via mermaid) and brace-expansion 2.1.7 (via minimatch 3), and regenerate package-lock.json. No code changes; `npm ci` and the Mermaid tests pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
✅ Deploy Preview for hivecommons-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
There was a problem hiding this comment.
Verified against the registry, not just the diff. Looks correct to me.
package-lock.jsonintegrity hashes fordompurify@3.4.16andbrace-expansion@2.1.7matchregistry.npmjs.orgexactly.npm ci --ignore-scriptson this head succeeds;npm lsshows a singledompurify@3.4.16(deduped) andbrace-expansion@2.1.7.- The
^2.1.7range forbrace-expansionis the right call for the reason the body gives —>=would letminimatch@3pick up a 5.x major. The override already forced allbrace-expansionconsumers onto 2.x onmain(^2.0.1), so this is a patch bump with no new resolution change; the lockfile diff only drops the now-extraneousbrace-expansion/1.1.7entry. changelog.d/fixed-bump-dompurify-brace-expansion.mdfollows the<category>-<slug>.mdnaming.
No findings.
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
Summary
Raises two
overridesfloors inpackage.jsonand regeneratespackage-lock.jsonso the lockfile resolves the latest patch releases:dompurifymermaid(src/lib/Mermaid.tsx)brace-expansionminimatch@3.1.4Ranges are kept conservative (
^2.1.7for brace-expansion, not>=, so minimatch 3 is not pushed onto brace-expansion 5.x).Files
package.json—overrides.dompurify,overrides.brace-expansionpackage-lock.json— regenerated withnpm install --package-lock-onlychangelog.d/fixed-bump-dompurify-brace-expansion.mdDisjoint from #145 (which only touches
src/components/docs/EditPageLink.tsx).Test plan
npm ci --ignore-scriptssucceedsnpx vitest run src/__tests__/Mermaid.test.tsx— 3 passednpm audit— 0 vulnerabilitiesFiled by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-fable-5.1 copilot=1.0.88