Repository navigation
deps: bump browserslist and drop the no-op dompurify override - #2018
Open
nadaverell wants to merge 1 commit into
Open
nadaverell wants to merge 1 commit into
nadaverell wants to merge 1 commit into
Conversation
browserslist 4.28.4 -> 4.29.3 (GHSA-73wf-gq98-2v4g) with its data packages, resolved with --before=2026-10-04T09:37:26Z. The root dompurify override never reached the browser: monaco-editor 0.55.1 imports a vendored DOMPurify 3.2.7 by relative path, and nothing else depends on the npm package. Dropping it lets the lockfile and Dependabot report the version actually shipped. The production frontend build is byte-identical.
PR Summary by QodoRemove the ineffective DOMPurify override
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can route each severity your way: inline, summary, both, or drop |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lockfile-only security follow-up to #2017. The production frontend build is byte-identical to main.
Changes
1. browserslist 4.28.4 → 4.29.3 fixes GHSA-73wf-gq98-2v4g (high). browserslist's data packages move with it: caniuse-lite, electron-to-chromium, baseline-browser-mapping, node-releases and update-browserslist-db.
--before=2026-10-04T09:37:26Z, a 72h soak. The newest mover was published 2026-10-02.2. The root
"overrides": {"dompurify": "3.4.0"}is removed. It never had a runtime effect:esm/vs/base/browser/domSanitize.js→./dompurify/dompurify.js). The built monaco chunk contains.version="3.2.7".dompurify, and Radar source doesn't import it.dompurify@3.2.7undernode_modules/monaco-editor/node_modules/. The DOMPurify alerts now describe what actually ships.What this does NOT fix
Radar still ships DOMPurify 3.2.7 inside monaco. The real fix is monaco-editor ≥0.56, which vendors 3.4.15 (#1930), but that's blocked upstream:
exportsmap that breaks the pre-0.56 deep pathmonaco-editor/esm/vs/editor/editor.worker.js.monaco-worker-manager2.0.1, used by monaco-yaml's worker, still imports that path, so the Vite build fails to resolve it.@monaco-editor/react4.7.0, the latest stable, imports the same old path in its types, soMonacocollapses toany.A Vite alias mapping
monaco-editor/esm/vs/*onto the real files makes 0.57 build. Radar Hub bundles radar-app source with its own Vite config, though, so it would need the same alias in lockstep. That was deliberately deferred until upstream catches up.The exposure is narrow. Monaco calls only
sanitize()(with hooks andRETURN_TRUSTED_TYPE) to render hover markdown; most of the open advisories needIN_PLACE,setConfigor custom-element handling.Verification
npm cipasses, andnpm ls --package-lock-onlyreports a valid tree.make tscpasses.packages/k8s-ui: 218 files, 4160 passed, 1 skipped.web: 158 files, 1865 passed.npm run lintgives 0 errors and 444 warnings, the same as main.make buildpasses.web/distfrom this branch and fromorigin/main, each built from a cleannpm ci, are identical across all 337 assets.dompurifyand no path from the browserslist data into production JS/CSS.Note
Low Risk
Changes are limited to lockfile and a removed no-op override; production
web/distis reported byte-identical to main.Overview
This is a lockfile-only dependency hygiene PR: it bumps the browserslist toolchain (including
caniuse-lite,electron-to-chromium,baseline-browser-mapping,node-releases, andupdate-browserslist-db) to address advisory GHSA-73wf-gq98-2v4g. That stack is used at lint/build tooling time (e.g. via ESLint/Babel), not as a direct change to app source.It also removes the root
package.jsondompurifyoverride (3.4.0). The lockfile now recordsdompurify@3.2.7nested undermonaco-editor, matching what Monaco actually vendors—so security reporting aligns with what ships, without changing production bundle output (per PR verification).Reviewed by Cursor Bugbot for commit 007a93c. Bugbot is set up for automated code reviews on this repo. Configure here.