Repository navigation
Conversation
npm audit went from 45 findings to 21, and from one critical to none.
Most of it is npm update plus react-router 7.16.0 to 7.18.4, which
carried a high advisory of its own and pulled express, body-parser, qs
and morgan up with it.
The sweep first broke subsection validation, and the cause is worth
recording. fast-uri 3.1.6 tightened URI parsing, and AJV resolves schema
references through it. Our AJV cache key was Name:Version, which parses
as a URI with scheme "GWDM" and path "1.0", so
ajv.getSchema("GWDM:1.0#/properties/summary") stopped resolving and
/translate?subsection= and /validate?subsection= both returned 400.
Bisected across fast-uri releases: 3.1.5 resolves, 3.1.6 does not.
Pinning below 3.1.6 would have kept a high advisory in the URI parser
that runs on every validate request, so the key moves instead.
schemaKey() registers and looks schemas up as Name/Version, which parses
as a plain relative reference and resolves on current fast-uri. The key
is internal to the AJV store and the two index caches; every string a
caller sees — error messages, log lines, translation graph nodes,
/list/translations output — still uses Name:Version and is deliberately
untouched.
The existing subsection tests are what caught this, and they are the
regression gate.
Also drops @semantic-release/npm from devDependencies. release.config.js
never loads it and the package is private:true so it could not publish
anyway. Note this does not shrink the tree: semantic-release depends on
it directly, so the npm CLI and its transitive advisories stay. Measured
before and after — no change to the audit count.
…ream wait-on 8 to 9, dotenv 16 to 18, eslint-plugin-react-hooks 5 to 7, @types/node 22 to 26, @semantic-release/exec 6 to 7, conventional-changelog-conventionalcommits 8 to 9, and @semantic-release/github to 11.0.6. None needed a code change. Two are blocked by upstream peer ranges rather than by anything here: eslint 10 crashes on startup loading react/display-name, because eslint-plugin-react 7.37.5 is the newest published and peer-caps at eslint ^9.7. Reverted to ^9. typescript 7 is outside @react-router/node's peer range of ^5.1.0 || ^6.0.0, so it is left on 5.9. MUI stays on 7 deliberately: @hdruk/ui peer-requires ^7.3.2, so 9.4.0 is not an upgrade this service can take.
|
🎉 Great job! Your PR title follows the correct format. 🚀 |
calmacx
added this pull request to stack #145
September 24, 2026 09:52
Collaborator
Author
|
Closing without merging per the 2026-09-24 workstream restructure — this dependency sweep is redone from scratch as WS7 once WS4–WS6 land and dev has absorbed their new packages. See upgrade-plans/02-tracker.md and upgrade-plans/ws7-pr01-final-dependency-review.md. |
An error occurred while trying to automatically change base from
feat/GAT-9016-hdruk-ui
to
dev
September 25, 2026 08:24
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Takes
npm auditfrom 45 findings to 21, and from one critical to none. Upgradesreact-routerand@react-router/*7.16.0 → 7.18.4, sweeps patch and minor across the tree, takes seven majors, and changes the internal AJV cache key so thefast-uriupgrade is not blocked.Why
Seventeen Dependabot PRs are open, the oldest from February 2026, all raised against the Express service and a lockfile that has since been rewritten wholesale — #103 already reports
CONFLICTING, and #88 namesvalidatorandexpress-validator, neither of which is in the tree at all any more. Rather than merge stale lockfile patches one at a time, this sweeps the tree once and closes them out.Testing
npm run typecheck,npm run lintandnpm run buildall exit 0.npm run test:unit2 passed / 1 file;npm test58 passed / 9 files against the production build.?subsection=verified directly on/validate(200), because that is what thefast-urichange protects.Notes
fast-uri3.1.6 tightened URI parsing, and AJV resolves schema references through it. The AJV cache key wasName:Version, which parses as a URI with schemeGWDMand path1.0, soajv.getSchema("GWDM:1.0#/properties/summary")stopped resolving and both/translate?subsection=and/validate?subsection=returned 400. Bisected across releases: 3.1.5 resolves, 3.1.6 does not. Pinning below 3.1.6 would keep a high advisory in the URI parser that runs on every validate request, soschemaKey()now registers and looks schemas up asName/Versioninstead. The key is internal — every string a caller sees (error messages, log lines, translation graph nodes,/list/translationsoutput) still usesName:Versionand is deliberately unchanged. The existing subsection tests are the regression gate; they are what caught it.eslint10 crashes loadingreact/display-namebecauseeslint-plugin-react7.37.5 is the newest published and peer-caps ateslint ^9.7.typescript7 sits outside@react-router/node's peer range of^5.1.0 || ^6.0.0. Both reverted, both worth revisiting when upstream moves.@hdruk/uipeer-requires^7.3.2, so 9.4.0 is not an upgrade this service can take.@semantic-release/npmis dropped from devDependencies:release.config.jsnever loads it and the package isprivate: trueso it could not publish anyway. This does not shrink the tree —semantic-releasedepends on it directly, so the npm CLI and its transitive advisories stay. Measured before and after: no change to the audit count.npx semantic-release --dry-runfails on this branch, withERR_REQUIRE_CYCLE_MODULEloadingrelease.config.js. It fails identically on the base branch, so this PR did not cause it and does not address it — flagged only so a reviewer does not attribute it to the upgrades.