Skip to content

chore(deps): fix Dependabot security alerts - #29

Merged
PierreRaybaut merged 4 commits into
developfrom
chore/dependabot-alerts
Oct 8, 2026
Merged

PierreRaybaut merged 4 commits into
developfrom
chore/dependabot-alerts

Conversation

@PierreRaybaut

Copy link
Copy Markdown
Contributor

Fixes the 23 open Dependabot alerts; npm audit now reports 0 vulnerabilities.

  • dompurify 3.4.16 (runtime; the app only uses string-mode sanitize, so none of the advisories was reachable).
  • In-range lockfile refresh of transitive packages (source-map-js, brace-expansion, undici, ws, @babel/core, postcss, nanoid, js-yaml, probe-image-size). The auto-installed plotly.js peer of react-plotly.js moves to 4.1.2 for maplibre-gl; it is not bundled (Vite aliases it to plotly.js-dist-min).
  • Vite 6.4 and Vitest 4 (removes tinypool, fixes the launch-editor and server.fs.deny advisories).
  • Dependabot version updates targeting develop (npm and GitHub Actions, weekly, grouped; pyodide excluded because it is pinned with PYODIDE_VERSION).

Not covered: plotly.js-dist-min 2.35.3 embeds its own MapLibre and probe-image-size copies, invisible to Dependabot; fixing them requires a Plotly 3/4 migration.

Vitest (745, also with coverage), Prettier, ESLint, build with bundle budget, and the smoke, signal-layout, image-pan, macro, notebooks and worker_mode Playwright specs pass.

@PierreRaybaut
PierreRaybaut merged commit f5f8d2b into develop Oct 8, 2026
5 checks passed
@PierreRaybaut
PierreRaybaut deleted the chore/dependabot-alerts branch October 9, 2026 06:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant