Skip to content

chore(GAT-9016): sweep the dependency tree and triage Dependabot - #147

Closed
calmacx wants to merge 2 commits into
feat/GAT-9016-hdruk-uifrom
chore/GAT-9016-dependency-sweep
Closed

calmacx wants to merge 2 commits into
feat/GAT-9016-hdruk-uifrom
chore/GAT-9016-dependency-sweep

Conversation

@calmacx

@calmacx calmacx commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

What

Takes npm audit from 45 findings to 21, and from one critical to none. Upgrades react-router and @react-router/* 7.16.0 → 7.18.4, sweeps patch and minor across the tree, takes seven majors, and changes the internal AJV cache key so the fast-uri upgrade is not blocked.

Why

Seventeen Dependabot PRs are open, the oldest from February 2026, all raised against the Express service and a lockfile that has since been rewritten wholesale — #103 already reports CONFLICTING, and #88 names validator and express-validator, neither of which is in the tree at all any more. Rather than merge stale lockfile patches one at a time, this sweeps the tree once and closes them out.

Testing

npm run typecheck, npm run lint and npm run build all exit 0. npm run test:unit 2 passed / 1 file; npm test 58 passed / 9 files against the production build. ?subsection= verified directly on /validate (200), because that is what the fast-uri change protects.

Notes

  • The sweep broke subsection validation before it fixed it, and the cause is worth knowing. fast-uri 3.1.6 tightened URI parsing, and AJV resolves schema references through it. The AJV cache key was Name:Version, which parses as a URI with scheme GWDM and path 1.0, so ajv.getSchema("GWDM:1.0#/properties/summary") stopped resolving and both /translate?subsection= and /validate?subsection= returned 400. Bisected across releases: 3.1.5 resolves, 3.1.6 does not. Pinning below 3.1.6 would keep a high advisory in the URI parser that runs on every validate request, so schemaKey() now registers and looks schemas up as Name/Version instead. The key is internal — every string a caller sees (error messages, log lines, translation graph nodes, /list/translations output) still uses Name:Version and is deliberately unchanged. The existing subsection tests are the regression gate; they are what caught it.
  • Two majors are blocked upstream, not by anything here. eslint 10 crashes loading react/display-name because eslint-plugin-react 7.37.5 is the newest published and peer-caps at eslint ^9.7. typescript 7 sits outside @react-router/node's peer range of ^5.1.0 || ^6.0.0. Both reverted, both worth revisiting when upstream moves.
  • MUI stays on 7 deliberately — @hdruk/ui peer-requires ^7.3.2, so 9.4.0 is not an upgrade this service can take.
  • @semantic-release/npm is dropped from devDependencies: release.config.js never loads it and the package is private: true so it could not publish anyway. This does not shrink the tree — semantic-release depends on it directly, so the npm CLI and its transitive advisories stay. Measured before and after: no change to the audit count.
  • npx semantic-release --dry-run fails on this branch, with ERR_REQUIRE_CYCLE_MODULE loading release.config.js. It fails identically on the base branch, so this PR did not cause it and does not address it — flagged only so a reviewer does not attribute it to the upgrades.
  • Of the 21 findings left, 15 are in the build and release toolchain rather than anything the service loads at runtime.
  • Stacked on feat(GAT-9016): adopt @hdruk/ui and downgrade MUI to v7 #146.

npm audit went from 45 findings to 21, and from one critical to none.
Most of it is npm update plus react-router 7.16.0 to 7.18.4, which
carried a high advisory of its own and pulled express, body-parser, qs
and morgan up with it.

The sweep first broke subsection validation, and the cause is worth
recording. fast-uri 3.1.6 tightened URI parsing, and AJV resolves schema
references through it. Our AJV cache key was Name:Version, which parses
as a URI with scheme "GWDM" and path "1.0", so
ajv.getSchema("GWDM:1.0#/properties/summary") stopped resolving and
/translate?subsection= and /validate?subsection= both returned 400.
Bisected across fast-uri releases: 3.1.5 resolves, 3.1.6 does not.

Pinning below 3.1.6 would have kept a high advisory in the URI parser
that runs on every validate request, so the key moves instead.
schemaKey() registers and looks schemas up as Name/Version, which parses
as a plain relative reference and resolves on current fast-uri. The key
is internal to the AJV store and the two index caches; every string a
caller sees — error messages, log lines, translation graph nodes,
/list/translations output — still uses Name:Version and is deliberately
untouched.

The existing subsection tests are what caught this, and they are the
regression gate.

Also drops @semantic-release/npm from devDependencies. release.config.js
never loads it and the package is private:true so it could not publish
anyway. Note this does not shrink the tree: semantic-release depends on
it directly, so the npm CLI and its transitive advisories stay. Measured
before and after — no change to the audit count.
…ream

wait-on 8 to 9, dotenv 16 to 18, eslint-plugin-react-hooks 5 to 7,
@types/node 22 to 26, @semantic-release/exec 6 to 7,
conventional-changelog-conventionalcommits 8 to 9, and
@semantic-release/github to 11.0.6. None needed a code change.

Two are blocked by upstream peer ranges rather than by anything here:

eslint 10 crashes on startup loading react/display-name, because
eslint-plugin-react 7.37.5 is the newest published and peer-caps at
eslint ^9.7. Reverted to ^9.

typescript 7 is outside @react-router/node's peer range of
^5.1.0 || ^6.0.0, so it is left on 5.9.

MUI stays on 7 deliberately: @hdruk/ui peer-requires ^7.3.2, so 9.4.0 is
not an upgrade this service can take.
@gh-actions-pipelines-app

Copy link
Copy Markdown

🎉 Great job! Your PR title follows the correct format. 🚀

@calmacx
calmacx added this pull request to stack #145 September 24, 2026 09:52
@calmacx

calmacx commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator Author

Closing without merging per the 2026-09-24 workstream restructure — this dependency sweep is redone from scratch as WS7 once WS4–WS6 land and dev has absorbed their new packages. See upgrade-plans/02-tracker.md and upgrade-plans/ws7-pr01-final-dependency-review.md.

@calmacx calmacx closed this Sep 24, 2026
An error occurred while trying to automatically change base from feat/GAT-9016-hdruk-ui to dev September 25, 2026 08:24

This branch was successfully deployed

2 active deployments
release — c488f846 Deployed Sep 24, 2026 by calmacx via testing #757
dev — c488f846 Deployed Sep 24, 2026 by calmacx via testing #756
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant