chore: resolve open dependabot security alerts - #254
Conversation
Address Copilot review feedback on PR #253: @openfeature/angular-sdk 1.3.1 requires @openfeature/web-sdk ^1.9.0 as a peer dependency, but package.json still allowed ^1.7.3. Bump the declared range to match and regenerate the lockfile. Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- postcss <= 8.5.17 -> ^8.5.18 override (high, alert #62) - pin fast-uri override to exact 3.1.4 per CodeRabbit review suggestion Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- fast-uri 3.1.4 -> 3.1.5 (high, alert #64: host confusion via backslash authority introducer) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
- @angular/core 20.3.25 -> 20.3.28 (high, alert #75: XSS via event-handler attributes) - @angular/compiler 20.3.25 -> 20.3.28 (high, alert #74: XSS via event-handler attributes) - @angular/common 20.3.25 -> 20.3.28 (high, alert #73: cache-key ambiguity in HttpTransferCache) - brace-expansion 2.1.0 -> 2.1.4 (high, alert #72: DoS via exponential-time expansion) Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
… main Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Angular integration package updates Angular runtime packages and ChangesAngular integration dependencies
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This PR updates vulnerable dependencies in the Angular integration test fixture; no actionable merge-blocking risk remains after normal checks and review. Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Updates the Angular integration fixture to resolve four Dependabot security alerts.
Changes:
- Updates Angular dependencies to patched versions.
- Refreshes the lockfile, including
brace-expansion2.1.4.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
test/angular-integration/package.json |
Raises Angular dependency ranges. |
test/angular-integration/package-lock.json |
Locks patched Angular and transitive dependencies. |
Files not reviewed (1)
- test/angular-integration/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
Dependabot Alerts Resolved
@angular/core@angular/compiler@angular/commonbrace-expansion