Skip to content

Update postcss, @babel/core and webpack-dev-server for security fixes - #4030

Merged
blarghmatey merged 1 commit into
mainfrom
js-security-deps
Sep 30, 2026
Merged

blarghmatey merged 1 commit into
mainfrom
js-security-deps

Conversation

@blarghmatey

Copy link
Copy Markdown
Member

What are the relevant tickets?

Supersedes #3829, #3765, #3830

Description (What does it do?)

Renovate opened these three bumps, then autoclosed them on 2026-09-22 when #3991 disabled its npm manager, so main still pins the vulnerable versions in frontend/public/package.json.

All three are build or dev tooling. yarn.lock was regenerated with yarn 3.8.7 on Node 20.18 and only moves these packages and their own dependencies (launch-editor, shell-quote, nanoid, and the @babel/* helpers @babel/core 7.29.6 needs).

How can this be tested?

  • CI's javascript-tests steps pass locally in node:20.18: yarn install --immutable, lint, fmt:check, scss_lint, flow, test (477 passing), and the production build of both workspaces.
  • CI does not run webpack-dev-server. Started it in node:17.9 (the watch container's image): it compiles and serves on :8012. 5.2.5 and 5.2.6 both declare node >= 18.12.0, so the 17.9 container was already outside that range before this change.

Additional Context

Older copies remain in the lock through the staff dashboard's react-scripts 5 (webpack-dev-server 4.15.2, postcss 8.5.3, @babel/core 7.27.1) and frontend/public's css-loader 3.6 (postcss 7). Those are out of scope here and go with the move off Create React App and the learner-page removal.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LnFWc4xtY7GnBaqaPPLRrN

Renovate opened these as #3829, #3765 and #3830, then autoclosed them on
2026-09-22 when #3991 disabled its npm manager, so main still pins the
vulnerable versions. @babel/core 7.29.6 fixes GHSA-4x5r-pxfx-6jf8
(arbitrary file read through sourceMappingURL at build time).

All three are build or dev tooling. The lock was regenerated with yarn
3.8.7 on Node 20.18 (CI's version) and only moves these packages and
their own dependencies.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LnFWc4xtY7GnBaqaPPLRrN
@github-actions

Copy link
Copy Markdown

OpenAPI Changes

Show/hide changes
## Changes for v0.yaml:
No changes detected

## Changes for v1.yaml:
No changes detected

## Changes for v2.yaml:
No changes detected

Unexpected changes? Ensure your branch is up-to-date with main (consider rebasing).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The manifest and lockfile updates are consistent with the documented security releases.

Review effort: Balanced
Findings: None

What changed in this PR

Updates frontend build tooling to patched security releases.

Changes:

  • Upgrades PostCSS, Babel Core, and webpack-dev-server.
  • Regenerates the Yarn lockfile with required transitive dependencies.
File Description
frontend/​public/​package.json Pins patched dependency versions.
yarn.lock Locks upgraded packages and transitive dependencies.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@blarghmatey
blarghmatey merged commit a9fdde1 into main Sep 30, 2026
16 checks passed
@blarghmatey
blarghmatey deleted the js-security-deps branch September 30, 2026 15:05
@odlbot odlbot mentioned this pull request Sep 30, 2026
9 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants