Skip to content

fix: patch notebook build dependency vulnerabilities - #854

Open
xianshijing-lk wants to merge 1 commit into
mainfrom
fix/notebook-security-dependencies
Open

xianshijing-lk wants to merge 1 commit into
mainfrom
fix/notebook-security-dependencies

Conversation

@xianshijing-lk

Copy link
Copy Markdown
Contributor

The notebook frontend lockfile contains vulnerable Babel, js-yaml, brace-expansion, postcss/nanoid, browserslist, baseline-browser-mapping, and @humanfs/node versions. Update those transitive dependencies within their existing dependency ranges, preserving the direct React, LiveKit client, Vite, TypeScript, and ESLint versions.

Validation: frozen-lockfile install, ESLint (0 errors; the existing Fast Refresh warning remains), TypeScript compilation and production Vite build. pnpm audit now reports only braces GHSA-vfj7-8cjw-p6xm, which has no patched upstream release and is pulled in by vite-plugin-singlefile's build tooling. This remaining finding is retained and explicitly reported by the follow-up security workflow.

Only the lockfile changes; the generated bundled HTML is not updated, and there are no notebook source or public SDK API changes. No SDK release is required for this build-tooling update. Land before the recurring dependency-security workflow so its notebook gate sees the patched versions.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant