From ca7409191c63549a4284f1eb991e5eeb806718b0 Mon Sep 17 00:00:00 2001 From: TheStreamCode Date: Tue, 22 Sep 2026 19:58:11 +0200 Subject: [PATCH] fix: resolve red dependency audit (fast-uri, js-yaml, qs) + add grouped Dependabot updates Scheduled Dependency audit failed 3x (runs 34123426028, 34846427672, 35602599991) on 2 high advisories: fast-uri 3.1.5 (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp) via ajv, and js-yaml 4.3.1 (GHSA-2883-xcg3-v3hh) via textlint/rc-config-loader. Bump lockfile to patched in-range versions: fast-uri 3.1.8, js-yaml 4.3.2, qs 6.16.0 (moderate GHSA-x5fp-wj9c-mxmx / GHSA-4mjr-xmp4-gh2g). No manifest range changes; npm audit --audit-level=high now reports 0 vulnerabilities. Add .github/dependabot.yml (weekly grouped npm + Actions, minor/patch only) so future advisories arrive as PRs for the existing dependabot-auto-merge workflow; majors stay manual. --- .github/dependabot.yml | 47 ++++++++++++++++++++++++++++++++++++++++++ package-lock.json | 18 ++++++++-------- 2 files changed, 56 insertions(+), 9 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..8828d0c --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,47 @@ +# Dependabot: weekly grouped npm + Actions updates. +# +# Pairs with `dependabot-auto-merge.yml`: patch/minor bumps merge +# automatically once protection checks pass; majors stay open for +# human review. Grouping keeps the PR noise to (at most) one npm +# PR and one Actions PR per week. + +version: 2 + +updates: + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + day: monday + time: "06:00" + timezone: Europe/Rome + groups: + npm-minor-patch: + applies-to: version-updates + update-types: + - minor + - patch + patterns: + - "*" + open-pull-requests-limit: 5 + labels: + - dependencies + + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + time: "06:00" + timezone: Europe/Rome + groups: + actions-minor-patch: + applies-to: version-updates + update-types: + - minor + - patch + patterns: + - "*" + open-pull-requests-limit: 5 + labels: + - dependencies diff --git a/package-lock.json b/package-lock.json index 3fd12fb..e555b7e 100644 --- a/package-lock.json +++ b/package-lock.json @@ -2165,9 +2165,9 @@ } }, "node_modules/fast-uri": { - "version": "3.1.5", - "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.5.tgz", - "integrity": "sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==", + "version": "3.1.8", + "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.8.tgz", + "integrity": "sha512-GZMtZUTNRpOVIECoXwLNZS5xUGE+mVNbTB8h/7Rwh2TFWcBQiPzTgyZi05BF9UMZKkLJv8XBRJTlU7zg8+ZfMg==", "dev": true, "funding": [ { @@ -2745,9 +2745,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", - "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", + "version": "4.3.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz", + "integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==", "dev": true, "funding": [ { @@ -3689,9 +3689,9 @@ } }, "node_modules/qs": { - "version": "6.15.3", - "resolved": "https://registry.npmjs.org/qs/-/qs-6.15.3.tgz", - "integrity": "sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==", + "version": "6.16.0", + "resolved": "https://registry.npmjs.org/qs/-/qs-6.16.0.tgz", + "integrity": "sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==", "dev": true, "license": "BSD-3-Clause", "dependencies": {