Skip to content

chore: upgrade dependencies and fix vulnerabilities - #109

Merged
fityannugroho merged 2 commits into
mainfrom
chore/deps-security-updates
Sep 12, 2026
Merged

fityannugroho merged 2 commits into
mainfrom
chore/deps-security-updates

Conversation

@fityannugroho

@fityannugroho fityannugroho commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

PR Checklist

Please check if your PR fulfills the following requirements:

Put [x] to check

  • I have read the documentation.
  • I have read and followed the Contributing Guidelines.
  • I have included a pull request description of my changes.
  • I have included the necessary changes to the documentation.
  • I have added tests to cover my changes.

PR Type

What kind of change does this PR introduce?

Please check any kind of changes that applies to this PR using [x]

  • Bug fix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • CI related changes
  • ..... (describe the other type)

What is the current behavior?

Please describe the current behavior that you are modifying, or link to a relevant issue.

Issue Number: N/A

pnpm audit on main reports known vulnerabilities in the dependency tree, including critical Next.js (unauthenticated RCE on Windows), critical MapLibre GL JS (XSS sanitizer bypass), high sharp (libheif), moderate qs (array-limit bypass, isBuffer DoS), moderate Vitest (@vitest/mocker path traversal), and moderate baseline-browser-mapping (DoS). Direct dependency ranges in package.json pin the vulnerable lines (next ^16.3.0, sharp ^0.35.3, vitest/@vitest/coverage-v8 ^4.1.10, @maplibre/maplibre-gl-leaflet ^0.1.3).

What is the new behavior?

Upgrades dependencies to resolve all pnpm audit advisories (zero remaining). Files changed (2 files, +281/−324): package.json (6 version bumps) and pnpm-lock.yaml (regenerated).

Advisories fixed:

  • GHSA-x5fp-wj9c-mxmx (moderate): qs array-limit bypass — patched via lockfile (>=6.15.4)
  • GHSA-4mjr-xmp4-gh2g (moderate): qs DoS via Attacker Controlled isBuffer — patched via lockfile (>=6.16.0)
  • GHSA-p293-qw3h-jr36 (critical): Next.js unauthenticated RCE on Windows — next ^16.3.0 -> ^16.3.4 (plus @next/env ^16.3.0 -> ^16.3.4)
  • GHSA-jrc7-96c5-q579 (critical): MapLibre GL JS XSS sanitizer bypass — @maplibre/maplibre-gl-leaflet ^0.1.3 -> ^0.1.4
  • GHSA-82fw-gwwq-j7x9 (moderate): Vitest path traversal via @vitest/mocker — vitest/@vitest/coverage-v8 ^4.1.10 -> ^4.1.11
  • GHSA-w5vr-8v7q-w6rv (moderate): baseline-browser-mapping DoS — resolved naturally via next 16.3.4 (2.11.22)
  • GHSA-rgj7-g3m4-5g8c (high): sharp libheif vulnerabilities — sharp ^0.35.3 -> ^0.35.4

Overrides dropped: initially added scoped overrides for maplibre-gl and baseline-browser-mapping, but re-tested without them — natural resolution already reaches patched versions, so they were removed. Final override list: none added (pre-existing overrides untouched).

Verification commands and results:

  • pnpm audit: No known vulnerabilities found
  • pnpm lint (biome): clean
  • pnpm test (NODE_ENV=test): 8 files, 58 passed, 1 todo
  • pnpm build: success
  • CI status checks on this PR: all SUCCESS (CodeQL Analyze actions + javascript-typescript, Test and Build build (22.x) and e2e, CodeQL)

Other information

Branch chore/deps-security-updates -> main (2 commits: b025ff5 upgrade dependencies and fix vulnerabilities, d0ceb54 drop unneeded overrides). No code, test, or config changes — dependency versions and lockfile only. No related issue.

@fityannugroho fityannugroho added the dependencies Pull requests that update a dependency file label Sep 12, 2026
@fityannugroho
fityannugroho merged commit 633c025 into main Sep 12, 2026
5 checks passed
@fityannugroho
fityannugroho deleted the chore/deps-security-updates branch September 12, 2026 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant