Skip to content

Fix open Dependabot alerts in transitive dependencies - #2773

Open
Hector Hernandez (hectorhdzg) wants to merge 3 commits into
microsoft:mainfrom
hectorhdzg:hectorhdzg-sync-security-fixes
Open

Hector Hernandez (hectorhdzg) wants to merge 3 commits into
microsoft:mainfrom
hectorhdzg:hectorhdzg-sync-security-fixes

Conversation

@hectorhdzg

Copy link
Copy Markdown
Member

Summary

Resolves all nine open Dependabot alerts by updating vulnerable transitive dependencies to their first patched versions.

Dependency Previous Updated
basic-ftp 5.3.1 6.2.1
brace-expansion 5.0.9 5.0.12
fast-uri 4.1.4 4.1.5
ip-address 10.7.0 10.7.1
morgan 1.12.0 1.12.1

Updates the root overrides, Rush PNPM configuration, and generated lockfile. No application source code is changed.

Validation

  • PNPM accepted the updated lockfile using frozen, offline validation.
  • Confirmed that none of the vulnerable package versions remain in the lockfile.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:35
@hectorhdzg
Hector Hernandez (hectorhdzg) requested a review from a team as a code owner October 1, 2026 22:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The override configurations and generated lockfile are consistent, with no vulnerable versions remaining.

Review effort: Balanced
Findings: None

What changed in this PR

Updates vulnerable transitive dependencies while preserving synchronized npm/Rush dependency resolution.

Changes:

  • Raises overrides to patched dependency versions.
  • Regenerates the PNPM lockfile with updated resolutions and integrity hashes.
File Description
package.json Updates root dependency overrides.
common/​config/​rush/​pnpm-config.json Synchronizes Rush PNPM overrides.
common/​config/​rush/​pnpm-lock.yaml Locks patched transitive versions.
Files not reviewed (1)
  • common/config/rush/pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants