Repository navigation
deps: package upgrade for 2026 Q3 - #1345
Conversation
There was a problem hiding this comment.
This PR is what it claims to be: a well-documented, low-risk quarterly dependency upgrade (all patch/minor bumps within existing major lines, full CI green, extensive Semgrep ticket cross-referencing). The lockfile/package.json diffs are internally consistent with the PR description's tables — I spot-checked axios, react-router, vite/esbuild, postcss, js-yaml, brace-expansion, qs, express and body-parser and all resolved versions match what's claimed. The real review surface here is the new batch-deps-upgrade agent skill (SKILL.md/README.md), which encodes the policy this and future automated upgrade PRs will follow. Three points there are worth the team's attention before this skill runs unattended in the future: it feeds untrusted JIRA ticket text into decisions about what packages/versions to install (prompt-injection surface), it lets the agent autonomously bump a direct dependency across a major version gated only by automated CI rather than requiring explicit human sign-off, and it temporarily points npm at the public registry (bypassing the internal Artifactory) to work off-VPN — a bit ironic for a skill whose whole purpose is supply-chain remediation.
| For tickets, see **Picking the target and matching results** under "Semgrep tickets" below — several tickets can share one install, and the match is per ticket. | ||
|
|
||
| 6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding. | ||
| 7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), report the full table to the user with root cause explanations and stop — do not proceed to Step 3 or Step 4. |
There was a problem hiding this comment.
Registry left unrestored on early exit. Restore before stopping:
| 7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), report the full table to the user with root cause explanations and stop — do not proceed to Step 3 or Step 4. | |
| report the full table to the user with root cause explanations, restore the registry first, then stop — do not proceed to Step 3 or Step 4. |
| 7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), report the full table to the user with root cause explanations and stop — do not proceed to Step 3 or Step 4. | |
| 7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), restore the original npm registry (see "After Step 3 completes" above), report the full table to the user with root cause explanations, and stop — do not proceed to Step 3 or Step 4. |
|
|
||
| For tickets, see **Picking the target and matching results** under "Semgrep tickets" below — several tickets can share one install, and the match is per ticket. | ||
|
|
||
| 6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding. |
There was a problem hiding this comment.
Registry left unrestored if completeness check fails early. Restore before stopping:
| 6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding. | |
| If any is unaccounted for, restore the registry first, then stop and report it before proceeding. |
| 6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding. | |
| 6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, restore the original npm registry (see "After Step 3 completes" above), then stop and report it before proceeding. |
There was a problem hiding this comment.
This is a well-documented, mechanical quarterly dependency bump (package.json/package-lock.json changes match the PR description exactly, patch/minor bumps only, consistent with npm's own resolved ranges) plus two new agent-skill definition files and a narrowed .gitignore to track them. I didn't find correctness bugs in the dependency diff itself. The one notable issue is in the new SKILL.md: the npm registry is switched to a global, machine-wide setting with no guaranteed restoration path if the run fails partway through.
High Level Overview of Change
Quarterly batch dependency upgrade (2026-Q3). This PR consolidates the open Dependabot dependency PRs and applies the further upgrades needed to resolve the open Semgrep (DGE) supply-chain tickets that a package upgrade can fix.
main(No-op), 0 left open. That includes 7 Critical tickets: DGE-7815 (brace-expansion), DGE-7818 / DGE-7906 (immutable), DGE-7888 / DGE-8143 (js-yaml), DGE-7907 / DGE-7908 (postcss).SKILL.md,README.md) is now tracked (.gitignorenarrowed from.claude/to everything except.claude/skills/) and updated to cover Semgrep tickets and aclosemode. Tickets whose description gives no fix version are now resolved through their GitHub advisory instead of being dropped.Context of Change
Routine maintenance. Direct dependencies were bumped in
package.json; transitive dependencies were updated withnpm update <pkg>;package-lock.jsonwas updated in place (never regenerated from scratch). Nooverridesorresolutionswere added and no parent range was widened. Where a parent blocked a fix, the parent was a direct dependency and was bumped within its own major line (express,body-parser,vite).Type of Change
Codebase Modernization
N/A — no file conversions.
Before / After
Only
package.jsonandpackage-lock.jsonchanged: 66 lockfile entries moved to a newer version, none added or removed.package.jsonrange floors raised:qsexpress@4.22.1pinnedqs ~6.14.0, blocking DGE-7333esbuild ^0.28(DGE-7920)The advisories also cover older major lines that no ticket names, and
npm updatelifted those within range too:js-yaml3.14.2 → 3.15.2 andbrace-expansion1.1.14 → 1.1.21 / 2.1.0 → 2.1.7.Test Plan
Full CI suite run locally, all green:
npm run lint:ci— ESLint, stylelint, prettiernpm run build— Vite production buildnpm run build-ts— TypeScript type checknpm run test:ci— Jest unit tests with coverage: 292 suites, 1707 tests passed; coverage thresholds metSuperseded Dependabot PRs
None — there were no open Dependabot PRs when this batch was built.
Semgrep tickets
Out of scope (not package-upgrade-fixable; not addressed here): DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings); DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843, DGE-7794 (
ripple/explorer-deploy).Tickets whose description gives no fix version (DGE-39xx, DGE-5597) are checked against their GitHub advisory: each is No-op because no installed copy of the package falls inside the advisory's affected range, so they are closed rather than left to reappear every quarter.
Ticket-driven upgrades not proposed by any Dependabot PR (additions)
Since no Dependabot PRs were open, every upgrade above is an addition. The ones worth calling out are the parents bumped to unblock a ticket:
express@4.22.1pinnedqs ~6.14.0body-parser@1.20.4pinnedqs ~6.14.0vite@≤7.3.5declaredesbuild ^0.27.0npm update esbuildafter the vite bumpLeft open — security fixes that did not land
None.
Closing instructions
After merging, run
/batch-deps-upgrade closeto close the superseded PRs and the resolved Semgrep tickets. There are no Dependabot PRs to close. It will close these Upgraded / No-op tickets: DGE-4718, DGE-4867, DGE-3953, DGE-3954, DGE-3955, DGE-3956, DGE-3957, DGE-3926, DGE-3924, DGE-5597, DGE-7329, DGE-7815, DGE-7077, DGE-7293, DGE-7333, DGE-7818, DGE-7906, DGE-7832, DGE-7888, DGE-8143, DGE-7852, DGE-7853, DGE-7855, DGE-7856, DGE-7857, DGE-7858, DGE-7859, DGE-7879, DGE-7882, DGE-7870, DGE-7907, DGE-7908, DGE-7910, DGE-7915, DGE-7933, DGE-7935, DGE-7920, DGE-7925, DGE-7928.No PRs or tickets were Skipped, so nothing needs to stay open.