Repository navigation
deps(npm): bump source-map-js from 1.2.1 to 1.2.2 - #2015
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2. - [Release notes](https://github.com/7rulnik/source-map-js/releases) - [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md) - [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2) --- updated-dependencies: - dependency-name: source-map-js dependency-version: 1.2.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
nadaverell
added a commit
that referenced
this pull request
Oct 7, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs. Dependency-only: no application source changes. **Screening time:** 2026-10-07T08:38:20Z (reconciled again at 09:00Z; rebased onto `1f05aee9`, which picked up #2015) **72h cutoff:** published at or before 2026-10-04T08:38:20Z. Every resolved version below clears it. The npm lockfile was regenerated with `npm install --package-lock-only --before=2026-10-04T08:38:20Z`, so the resolver could not float past the cutoff. ## Included | PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion | |---|---|---|---|---|---| | #2000 | modernc.org/sqlite (+ modernc.org/libc) | v1.59.0 → v1.60.1 (libc v1.75.7 → v1.77.1) | sqlite 2026-09-29 08:41; libc 2026-09-21 23:07 | ~8d / ~15.4d | Low–moderate. SQLite stays 3.53.4. The libc range is substantial on Linux (see notes), so I ran the sqlite-backed stores' tests in a Linux container. | | #1998 | github.com/prometheus/common | v0.71.0 → v0.72.0 | 2026-09-28 08:33 | ~9d | Low. The only change on Radar's path is a stricter text parser (see notes). Its `go 1.26` requirement matches ours. | | #2001 | github.com/google/go-containerregistry | v0.22.0 → v0.22.1 | 2026-09-04 00:07 | ~33d | Low. SSRF-guard hardening, an authn fix that stops empty credentials overwriting `AuthConfig.Auth`, and sha512 digest support. Radar uses `authn`, `name`, `remote`, `v1/google` for image inspection. | | #2004 | react-virtuoso | 4.18.13 → 4.18.16 | 2026-09-29 16:03 | ~7.7d | Low. 4.18.14 adds custom `ul` List wrappers. 4.18.15 fixes `initialItemCount` clamping, which Radar doesn't use. 4.18.16 stops TableVirtuoso leaking `skipAnimationFrameInResizeObserver` onto the DOM; Radar doesn't pass that prop. I smoke-tested the binary in a browser anyway. | | #2003 | typescript-eslint (+ 10 `@typescript-eslint/*`) | 8.70.0 → **8.71.0** | 2026-09-28 17:12 | ~8.6d | Low. Adds a new rule that's opt-in and not enabled here, plus rule fixes. The set of 444 lint warnings is identical before and after (0 errors). **8.71.1 (2026-10-05) is too fresh and was deliberately not picked up.** | | #2002 | vitest (+ @vitest/mocker, @vitest/spy) | 5.0.2 → 5.0.3 | 2026-09-30 11:30 | ~6.9d | Low. Bug fixes in repeats/retry, cache revalidation, jsdom Blob and the pool. Both test suites pass. | | #1999 | prettier | 3.9.8 → 3.9.9 | 2026-09-23 06:31 | ~14d | Negligible. A Markdown `$`-as-math fix; Radar formats only `.ts/.tsx`. `prettier --check` reports the same 1089 files before and after. | | #2015 | source-map-js | 1.2.1 → 1.2.2 | 2026-09-30 14:08 | ~6.8d | Low. Build/test-time only (postcss, Tailwind, jsdom via css-tree). Fixes a DoS from malicious indexed source maps (CVE-2026-93749) and a crash under a no-`unsafe-eval` CSP. | ### Movement beyond the Dependabot PRs (reviewed, all soaked) - **Go:** `modernc.org/libc` v1.75.7 → v1.77.1 (2026-09-21), the version sqlite pins. - Three `go.sum` entries also changed, `golang.org/x/tools` v0.50.0 (2026-09-08), `modernc.org/cc/v4` v4.29.7 (2026-09-12) and `modernc.org/ccgo/v4` v4.36.1 (2026-09-21). `go mod why` shows each one is reached only through `go-sdk/mcp.test` or `libc.test`, never a Radar binary. - `pkg/go.mod` is untouched. - **npm:** - `ignore` 7.0.9 → 7.0.12 (2026-10-02, ~4.8d), nested under `@typescript-eslint/eslint-plugin`. These are gitignore-semantics fixes plus linear-time perf work (no release notes, so I reviewed the [compare](kaelzhang/node-ignore@7.0.9...7.0.12)). It's lint-time only, and the lint output is identical. - `why-is-node-running` 3.2.2 → 3.2.1, a **downgrade** that vitest 5.0.3 pins on purpose ([vitest#11403](vitest-dev/vitest#11403), avoids `ERR_PNPM_TRUST_DOWNGRADE`). 3.2.1 was published 2024-10-29. - Nothing else in `package-lock.json` changed. - **Too-fresh versions deliberately excluded by the `--before` cutoff:** - typescript-eslint / `@typescript-eslint/*` 8.71.1 (2026-10-05 17:08Z). - `magic-string` 1.4.3 (2026-10-05 04:52Z), which a plain refresh would have pulled under `@vitest/mocker`. It stays at 1.4.2, inside mocker's `^1.2.3`. ## Held / excluded (these PRs stay open) | PR | Update | Decision | Reason | |---|---|---|---| | #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** | I re-tested on today's main and it still fails `TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract` ("private mount handshake did not mark the scope connected"). Radar's private-mount handling needs adapting first; that's a source change. | | #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Unchanged from last week. The deep side-effect imports in `packages/k8s-ui/src/components/ui/monacoRuntime.ts` don't resolve under 0.57 (TS2882), and that file hasn't changed since. The PR's CI still fails the Frontend, k8s-ui and Settings jobs. Needs a source change. | | #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** | Unchanged from last week. Since v2.3.0 the action installs helm-unittest twice ([#648](helmfile/helmfile-action#648)), so the Helm chart job fails. Needs a `ci.yml` change to how `helm-plugins` is specified. | ## Radar usage and risk notes - **modernc sqlite 1.60 / libc 1.77.1** ([sqlite CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.60.1/CHANGELOG.md), [libc compare](https://gitlab.com/cznic/libc/-/compare/v1.75.7...v1.77.1)): - Radar imports only the `database/sql` driver: the SQLite timeline store and `ai-runs.db`. It uses no `vfs`, no `pcache`, none of the removed `lib` constants and no `_pragma`. `StrictPragmas` is opt-in. - The 1.60.0 change that turns a WAL `-shm` read fault into `SQLITE_IOERR_IN_PAGE` instead of a crash is a strict improvement. - The libc range includes musl atomics translated to Go, stdio locking fixes, and setenv/putenv mirrored into the Go environment on musl. That's why I ran the targeted Linux run below. - **Last week's blocker is resolved.** libc v1.77.0's recursive `Xnanf` stack overflow ([cznic/libc#60](https://gitlab.com/cznic/libc/-/issues/60)) caused us to hold sqlite 1.60. v1.77.0 is now retracted, and v1.77.1 adds the fix and a `TestNaN` regression test. - The issue is still open upstream, so I checked directly: in v1.77.1, Linux `Xnanf` returns `X__builtin_nanf` (`math.NaN()`), and the issue's own reproducer prints `NaN NaN NaN` on linux/arm64 with no stack overflow. - **prometheus/common 0.72** ([release](https://github.com/prometheus/common/releases/tag/v0.72.0)): - Radar uses `expfmt.NewTextParser(model.LegacyValidation)` to parse apiserver metrics in `internal/upgrade/collectors_live.go`, and `model` in the MCP Prometheus tool. - The only text-parser change ([#988](prometheus/common#988)) now rejects a nameless `{}` sample that follows metric metadata. Kubernetes apiserver exposition never emits one. - The rest is OpenMetrics 2.0 encoding, which is experimental and unused here, plus format-constant docs ([#992](prometheus/common#992), backward compatible). - **typescript-eslint 8.71.0** ([release](https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.71.0)), **vitest 5.0.3** ([release](https://github.com/vitest-dev/vitest/releases/tag/v5.0.3)), **prettier 3.9.9** ([changelog](https://github.com/prettier/prettier/blob/3.9.9/CHANGELOG.md#399)), **react-virtuoso** ([releases](https://github.com/petyosi/react-virtuoso/releases)), **source-map-js 1.2.2** ([compare](7rulnik/source-map-js@v1.2.1...v1.2.2)), **go-containerregistry 0.22.1** ([release](https://github.com/google/go-containerregistry/releases/tag/v0.22.1)). ## Verification All results are on the rebased branch (base `1f05aee9`). - **Integrity:** `npm ci` passes, and `go mod verify` passes for root and `pkg`. - **Type-check:** `make tsc` passes. - **Go tests:** `make test` (root `go test ./...`, 43 packages ok) and `cd pkg && go test ./...` both pass. The first run failed with "package unsafe is not in std" and missing `go-build` cache files because the Go build cache was cleaned during the run; both pass on a clean re-run. - **Frontend tests:** - `packages/k8s-ui` `npm test`: 218 files, 4160 passed, 1 skipped. - `web` `npm run test`: 158 files, 1865 passed. - **Lint:** `cd web && npm run lint` gives 0 errors and 444 warnings, the same warning set as main. I compared the normalized warning lists from a clean `npm ci` of `origin/main`. - **Prettier:** `prettier --check` on `web/src` and `packages/k8s-ui/src` flags 1089 files before and after, so the bump changes no formatting. - **Build:** `make build` passes. - **Linux targeted test:** `go test ./internal/timeline/ ./internal/ai/` passes in `golang:1.26` (go1.26.8, linux/arm64) against libc v1.77.1. Those are the SQLite timeline store and the `ai-runs.db` store. - **Binary smoke test:** I ran the built binary against a live cluster with the Pods table at ~100 pods. - TableVirtuoso virtualized as expected: 5182px of scroll height rendered 29 rows, then 43 after a mid-scroll. - Rows rendered correctly mid-list, and the console showed 0 errors and 0 warnings. - **visual-test:** I didn't run a full `/visual-test`. The only rendering-relevant bump is react-virtuoso, and the targeted smoke test above covers it. Supersedes #2000, #1998, #2001, #2004, #2003, #2002, #1999, #2015 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Dependency-only lockfile and manifest updates with no runtime code changes; bumps are patch/minor and were screened with tests per the PR description. > > **Overview** > This PR **batches soaked Dependabot dependency bumps** with **no application source changes**—only `go.mod`/`go.sum`, root `package-lock.json`, and version pins in `packages/k8s-ui/package.json` and `web/package.json`. > > **Go** updates include `modernc.org/sqlite` (v1.59.0 → v1.60.1) with its `modernc.org/libc` transitive bump, `github.com/prometheus/common` (v0.71.0 → v0.72.0), and `github.com/google/go-containerregistry` (v0.22.0 → v0.22.1), plus related `go.sum` entries for sqlite/libc toolchain deps. > > **npm** updates cover `react-virtuoso` (4.18.13 → 4.18.16) in k8s-ui and web, `typescript-eslint` / `@typescript-eslint/*` (8.70.0 → 8.71.0), `vitest` (5.0.2 → 5.0.3) in k8s-ui, `prettier` (3.9.8 → 3.9.9), and lockfile-only moves such as `source-map-js` 1.2.2 and vitest’s pinned `why-is-node-running` downgrade. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3716b5a. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
Contributor
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps source-map-js from 1.2.1 to 1.2.2.
Release notes
Sourced from source-map-js's releases.
Changelog
Sourced from source-map-js's changelog.
Commits
0a1d3341.2.24c6fa26Update changelogcf76580Fix denial of service from malicious indexed source maps (CVE-2026-93749) (#79)7899a86Fix crash when executing browser with CSP script-src that don't permit unsafe...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Lockfile-only patch bump with security fixes; no direct usage or logic changes in this repo.
Overview
Bumps the resolved
source-map-jsversion from 1.2.1 to 1.2.2 inpackage-lock.json(transitive dependency; no application code changes).This picks up upstream fixes for a DoS via malicious indexed source maps (CVE-2026-93749) and a browser crash under strict CSP (
script-srcwithoutunsafe-eval).Reviewed by Cursor Bugbot for commit f03c252. Bugbot is set up for automated code reviews on this repo. Configure here.