Skip to content

deps: package upgrade for 2026 Q3 - #1345

Merged
pdp2121 merged 3 commits into
mainfrom
q3-package-updates
Oct 7, 2026
Merged

pdp2121 merged 3 commits into
mainfrom
q3-package-updates

Conversation

@pdp2121

@pdp2121 pdp2121 commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

High Level Overview of Change

Quarterly batch dependency upgrade (2026-Q3). This PR consolidates the open Dependabot dependency PRs and applies the further upgrades needed to resolve the open Semgrep (DGE) supply-chain tickets that a package upgrade can fix.

  • 0 open Dependabot PRs this quarter, so this batch is entirely ticket-driven.
  • 29 Semgrep tickets resolved by an upgrade, 10 already satisfied on main (No-op), 0 left open. That includes 7 Critical tickets: DGE-7815 (brace-expansion), DGE-7818 / DGE-7906 (immutable), DGE-7888 / DGE-8143 (js-yaml), DGE-7907 / DGE-7908 (postcss).
  • Every bump is a patch or minor within the package's current major line. No source code changes were needed.
  • The batch-deps-upgrade skill (SKILL.md, README.md) is now tracked (.gitignore narrowed from .claude/ to everything except .claude/skills/) and updated to cover Semgrep tickets and a close mode. Tickets whose description gives no fix version are now resolved through their GitHub advisory instead of being dropped.

One 0.x breaking-range bump that no ticket names directly: vite's nested esbuild 0.27.7 → 0.28.2. DGE-7920 asks for esbuild ≥ 0.28.1, but vite@≤7.3.5 declares esbuild ^0.27.0, so vite was bumped to 7.3.6, which declares ^0.27.0 || ^0.28.0. In 0.x semver a minor bump is a breaking range, but vite itself declares support for it and the build passed unchanged. The top-level esbuild@0.25.12 (our own direct dep) is outside the advisory range and is unchanged.

Context of Change

Routine maintenance. Direct dependencies were bumped in package.json; transitive dependencies were updated with npm update <pkg>; package-lock.json was updated in place (never regenerated from scratch). No overrides or resolutions were added and no parent range was widened. Where a parent blocked a fix, the parent was a direct dependency and was bumped within its own major line (express, body-parser, vite).

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Refactor (non-breaking change that only restructures code)
  • Tests (You added tests for code that already exists, or your new feature included in this PR)
  • Documentation Updates
  • Translation Updates
  • Release

Codebase Modernization

N/A — no file conversions.

  • Updated files to React Hooks
  • Updated files to TypeScript

Before / After

Only package.json and package-lock.json changed: 66 lockfile entries moved to a newer version, none added or removed.

package.json range floors raised:

Package Before After Resolved Why
axios ^1.16.1 ^1.18.0 1.20.0 DGE-7852/7853/7855/7856/7857/7858/7859/7879/7882
body-parser ^1.20.3 ^1.20.6 1.20.8 DGE-7928; also unpins qs
express ^4.21.2 ^4.22.2 4.22.3 express@4.22.1 pinned qs ~6.14.0, blocking DGE-7333
i18next-http-backend ^3.0.2 ^3.0.5 3.0.6 DGE-7077
react-router ^7.9.5 ^7.18.0 7.18.4 DGE-7910/7915/7933/7935
vite ^7.3.2 ^7.3.6 7.3.6 DGE-7870; 7.3.6 is the first to allow esbuild ^0.28 (DGE-7920)

The advisories also cover older major lines that no ticket names, and npm update lifted those within range too: js-yaml 3.14.2 → 3.15.2 and brace-expansion 1.1.14 → 1.1.21 / 2.1.0 → 2.1.7.

Test Plan

Full CI suite run locally, all green:

  • npm run lint:ci — ESLint, stylelint, prettier
  • npm run build — Vite production build
  • npm run build-ts — TypeScript type check
  • npm run test:ci — Jest unit tests with coverage: 292 suites, 1707 tests passed; coverage thresholds met

Superseded Dependabot PRs

None — there were no open Dependabot PRs when this batch was built.

Semgrep tickets

Out of scope (not package-upgrade-fixable; not addressed here): DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings); DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843, DGE-7794 (ripple/explorer-deploy).

Tickets whose description gives no fix version (DGE-39xx, DGE-5597) are checked against their GitHub advisory: each is No-op because no installed copy of the package falls inside the advisory's affected range, so they are closed rather than left to reappear every quarter.

Ticket Package From Asked for Resolved Status MajorVersionUpgrade
DGE-4718 brace-expansion (2.x) 2.1.0 ≥ 2.0.2 2.1.7 No-op (already satisfied on main) No
DGE-4867 brace-expansion (2.x) 2.1.0 ≥ 2.0.2 2.1.7 No-op (already satisfied on main) No
DGE-3953 es5-ext 0.10.64 ≥ 0.10.63 0.10.64 No-op (vulnerable version no longer installed) No
DGE-3954 cookie 0.7.2 / 1.1.1 ≥ 0.7.0 0.7.2 / 1.1.1 No-op (vulnerable version no longer installed) No
DGE-3955 serve-static 1.16.3 ≥ 1.16.0 1.16.3 No-op (vulnerable version no longer installed) No
DGE-3956 qs 6.14.2 ≥ 6.5.3 6.16.0 No-op (vulnerable version no longer installed) No
DGE-3957 path-to-regexp 0.1.13 ≥ 0.1.10 0.1.13 No-op (vulnerable version no longer installed) No
DGE-3926 braces 3.0.3 ≥ 3.0.3 3.0.3 No-op (vulnerable version no longer installed) No
DGE-3924 semver 5.7.2 / 6.3.1 / 7.7.4 ≥ 5.7.2 5.7.2 / 6.3.1 / 7.7.4 No-op (vulnerable version no longer installed) No
DGE-5597 request not installed no patched version not installed No-op (vulnerable version no longer installed) No
DGE-7329 brace-expansion (5.x) 5.0.5 ≥ 5.0.6 5.0.12 Upgraded No
DGE-7815 brace-expansion (5.x) 5.0.5 ≥ 5.0.7 5.0.12 Upgraded (Critical) No
DGE-7077 i18next-http-backend 3.0.4 ≥ 3.0.5 3.0.6 Upgraded No
DGE-7293 ws 8.20.0 ≥ 8.20.1 8.22.0 Upgraded No
DGE-7333 qs 6.14.2 ≥ 6.15.2 6.16.0 Upgraded No
DGE-7818 immutable 5.1.5 ≥ 5.1.8 5.1.9 Upgraded (Critical) No
DGE-7906 immutable 5.1.5 ≥ 5.1.8 5.1.9 Upgraded (Critical) No
DGE-7832 js-yaml (4.x) 4.1.1 ≥ 4.2.0 4.3.2 Upgraded No
DGE-7888 js-yaml (4.x) 4.1.1 ≥ 4.3.0 4.3.2 Upgraded (Critical) No
DGE-8143 js-yaml (4.x) 4.1.1 ≥ 4.3.2 4.3.2 Upgraded (Critical) No
DGE-7852 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7853 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7855 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7856 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7857 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7858 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7859 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7879 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7882 axios 1.16.1 ≥ 1.18.0 1.20.0 Upgraded No
DGE-7870 vite 7.3.2 ≥ 7.3.5 7.3.6 Upgraded No
DGE-7907 postcss 8.5.10 ≥ 8.5.18 8.5.28 Upgraded (Critical) No
DGE-7908 postcss 8.5.10 ≥ 8.5.12 8.5.28 Upgraded (Critical) No
DGE-7910 react-router 7.14.1 ≥ 7.18.0 7.18.4 Upgraded No
DGE-7915 react-router 7.14.1 ≥ 7.18.0 7.18.4 Upgraded No
DGE-7933 react-router 7.14.1 ≥ 7.18.0 7.18.4 Upgraded No
DGE-7935 react-router 7.14.1 ≥ 7.15.1 7.18.4 Upgraded No
DGE-7920 esbuild (vite's, 0.27.x) 0.27.7 ≥ 0.28.1 0.28.2 Upgraded No (0.x minor; see overview)
DGE-7925 @babel/core 7.29.0 ≥ 7.29.6 7.29.7 Upgraded No
DGE-7928 body-parser 1.20.4 ≥ 1.20.6 1.20.8 Upgraded No

Ticket-driven upgrades not proposed by any Dependabot PR (additions)

Since no Dependabot PRs were open, every upgrade above is an addition. The ones worth calling out are the parents bumped to unblock a ticket:

Package From → To Motivating ticket(s) How
express 4.22.1 → 4.22.3 DGE-7333 direct dep floor raised: express@4.22.1 pinned qs ~6.14.0
body-parser 1.20.4 → 1.20.8 DGE-7333, DGE-7928 direct dep floor raised: body-parser@1.20.4 pinned qs ~6.14.0
vite 7.3.2 → 7.3.6 DGE-7870, DGE-7920 direct dep floor raised: vite@≤7.3.5 declared esbuild ^0.27.0
esbuild (vite's) 0.27.7 → 0.28.2 DGE-7920 npm update esbuild after the vite bump

Left open — security fixes that did not land

None.

Closing instructions

After merging, run /batch-deps-upgrade close to close the superseded PRs and the resolved Semgrep tickets. There are no Dependabot PRs to close. It will close these Upgraded / No-op tickets: DGE-4718, DGE-4867, DGE-3953, DGE-3954, DGE-3955, DGE-3956, DGE-3957, DGE-3926, DGE-3924, DGE-5597, DGE-7329, DGE-7815, DGE-7077, DGE-7293, DGE-7333, DGE-7818, DGE-7906, DGE-7832, DGE-7888, DGE-8143, DGE-7852, DGE-7853, DGE-7855, DGE-7856, DGE-7857, DGE-7858, DGE-7859, DGE-7879, DGE-7882, DGE-7870, DGE-7907, DGE-7908, DGE-7910, DGE-7915, DGE-7933, DGE-7935, DGE-7920, DGE-7925, DGE-7928.

No PRs or tickets were Skipped, so nothing needs to stay open.

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is what it claims to be: a well-documented, low-risk quarterly dependency upgrade (all patch/minor bumps within existing major lines, full CI green, extensive Semgrep ticket cross-referencing). The lockfile/package.json diffs are internally consistent with the PR description's tables — I spot-checked axios, react-router, vite/esbuild, postcss, js-yaml, brace-expansion, qs, express and body-parser and all resolved versions match what's claimed. The real review surface here is the new batch-deps-upgrade agent skill (SKILL.md/README.md), which encodes the policy this and future automated upgrade PRs will follow. Three points there are worth the team's attention before this skill runs unattended in the future: it feeds untrusted JIRA ticket text into decisions about what packages/versions to install (prompt-injection surface), it lets the agent autonomously bump a direct dependency across a major version gated only by automated CI rather than requiring explicit human sign-off, and it temporarily points npm at the public registry (bypassing the internal Artifactory) to work off-VPN — a bit ironic for a skill whose whole purpose is supply-chain remediation.

Comment thread .claude/skills/batch-deps-upgrade/SKILL.md Outdated
@pdp2121
pdp2121 requested a review from kuan121 September 28, 2026 20:31

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Registry not restored on early exits (lines 66–67).

For tickets, see **Picking the target and matching results** under "Semgrep tickets" below — several tickets can share one install, and the match is per ticket.

6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding.
7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), report the full table to the user with root cause explanations and stop — do not proceed to Step 3 or Step 4.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Registry left unrestored on early exit. Restore before stopping:

Suggested change
7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), report the full table to the user with root cause explanations and stop — do not proceed to Step 3 or Step 4.
report the full table to the user with root cause explanations, restore the registry first, then stop — do not proceed to Step 3 or Step 4.
Suggested change
7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), report the full table to the user with root cause explanations and stop — do not proceed to Step 3 or Step 4.
7. **Early exit**: if every PR and ticket is Skipped or No-op (zero upgrades applied), restore the original npm registry (see "After Step 3 completes" above), report the full table to the user with root cause explanations, and stop — do not proceed to Step 3 or Step 4.


For tickets, see **Picking the target and matching results** under "Semgrep tickets" below — several tickets can share one install, and the match is per ticket.

6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Registry left unrestored if completeness check fails early. Restore before stopping:

Suggested change
6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding.
If any is unaccounted for, restore the registry first, then stop and report it before proceeding.
Suggested change
6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, stop and report it before proceeding.
6. Verify completeness: every PR and every ticket from step 1 must have a status (Upgraded, No-op, or Skipped). If any is unaccounted for, restore the original npm registry (see "After Step 3 completes" above), then stop and report it before proceeding.

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a well-documented, mechanical quarterly dependency bump (package.json/package-lock.json changes match the PR description exactly, patch/minor bumps only, consistent with npm's own resolved ranges) plus two new agent-skill definition files and a narrowed .gitignore to track them. I didn't find correctness bugs in the dependency diff itself. The one notable issue is in the new SKILL.md: the npm registry is switched to a global, machine-wide setting with no guaranteed restoration path if the run fails partway through.

@pdp2121
pdp2121 merged commit 02fda11 into main Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants