Skip to content

chore: resolve open dependabot security alerts - #1450

Open
jonathannorris wants to merge 1 commit into
mainfrom
chore/dependabot-alerts
Open

chore: resolve open dependabot security alerts#1450
jonathannorris wants to merge 1 commit into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris

Copy link
Copy Markdown
Member

Summary

  • Resolved 1 of 2 open Dependabot security alerts by bumping a vulnerable transitive dependency

Dependabot Alerts Resolved

Alert Package Severity Fix
#187 esbuild low Bumped ng-packagr 21.2.5 -> 21.2.7 (lockfile-only, within existing ^21.0.0 range), which dedupes esbuild to 0.28.1

Not resolved

Alert Package Severity Reason
#179 uuid (transitive, dev-only) medium No non-override fix available. jest-cucumber@4.5.0 (latest) pins @cucumber/gherkin@^28.0.0, whose accepted @cucumber/messages range (<=28) tops out at @cucumber/messages@28.1.0, which itself pins an exact uuid@11.1.0 (one patch short of the fixed 11.1.1). jest-cucumber also directly pins uuid@^10.0.0. No newer jest-cucumber release exists. Per repo policy this SDK does not use overrides/resolutions. The advisory (GHSA-w5hq-g745-h8pq) only applies when callers pass an external output buffer to uuid v3/v5/v6, which is not how it is used here (dev/test-only, transitive). Left open pending a jest-cucumber upstream update.

@jonathannorris
jonathannorris requested review from a team as code owners August 17, 2026 14:22
@jonathannorris
jonathannorris marked this pull request as draft August 17, 2026 14:22
…g-library peers

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
@jonathannorris
jonathannorris force-pushed the chore/dependabot-alerts branch from 93ccb16 to 10a3576 Compare August 17, 2026 14:30
@coderabbitai

coderabbitai Bot commented Aug 17, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 837b0bec-13fb-4f43-8d4b-3324a6e4a371

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jonathannorris
jonathannorris marked this pull request as ready for review August 17, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant