-
Notifications
You must be signed in to change notification settings - Fork 491
fix: patch security vulnerabilities in 6 dependencies #8802
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
- axios ^1.8.2 -> ^1.13.5 (GHSA-43fc-jf86-j433, HIGH) - glob ^11.0.3 -> ^11.1.0 (GHSA-5j98-mcp5-4vw2, HIGH) - storybook ecosystem ^10.1.9 -> ^10.2.8 (GHSA-8452-54wp-rmv6, HIGH) - tailwindcss + @tailwindcss/vite ^4.1.12 -> ^4.1.18 (tar vulns, HIGH) - vue-i18n ^9.14.3 -> ^9.14.5 (GHSA-x8qp-wqqm-57ph, MODERATE) - jsondiffpatch ^0.6.0 -> ^0.7.3 (GHSA-33vc-wfww-vjfv, MODERATE) Remove deprecated showName/dynamicTitle from Storybook toolbar config (properties removed in Storybook 10.2.x). Amp-Thread-ID: https://ampcode.com/threads/T-019c4b81-3522-754d-9d26-eedc70c9925a Co-authored-by: Amp <[email protected]>
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (3)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughThree files updated: Storybook configuration simplified by removing explicit toolbar flags, and dependencies upgraded including Storybook packages, axios, jsondiffpatch, glob, and vue-i18n across package.json and pnpm-workspace.yaml catalogs. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches🧪 Generate unit tests (beta)
Comment |
🎨 Storybook Build Status✅ Build completed successfully! ⏰ Completed at: 02/11/2026, 09:19:13 AM UTC 🔗 Links🎉 Your Storybook is ready for review! |
|
Playwright: ✅ 521 passed, 0 failed · 3 flaky 📊 Browser Reports
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c4b81-3522-754d-9d26-eedc70c9925a Co-authored-by: Amp <[email protected]>
Bundle Size ReportSummary
Category Glance Per-category breakdownApp Entry Points — 22 kB (baseline 22 kB) • ⚪ 0 BMain entry bundles and manifests
Status: 1 added / 1 removed Graph Workspace — 872 kB (baseline 872 kB) • ⚪ 0 BGraph editor runtime, canvas, workflow orchestration
Status: 1 added / 1 removed Views & Navigation — 68.8 kB (baseline 68.8 kB) • ⚪ 0 BTop-level views, pages, and routed surfaces
Status: 11 added / 11 removed Panels & Settings — 454 kB (baseline 454 kB) • ⚪ 0 BConfiguration panels, inspectors, and settings screens
Status: 11 added / 11 removed User & Accounts — 16 kB (baseline 16 kB) • ⚪ 0 BAuthentication, profile, and account management bundles
Status: 6 added / 6 removed Editors & Dialogs — 751 B (baseline 751 B) • ⚪ 0 BModals, dialogs, drawers, and in-app editors
Status: 1 added / 1 removed UI Components — 36.5 kB (baseline 36.5 kB) • ⚪ 0 BReusable component library chunks
Status: 9 added / 9 removed Data & Services — 2.1 MB (baseline 2.1 MB) • ⚪ 0 BStores, services, APIs, and repositories
Status: 13 added / 13 removed Utilities & Hooks — 237 kB (baseline 237 kB) • ⚪ 0 BHelpers, composables, and utility bundles
Status: 16 added / 16 removed Vendor & Third-Party — 8.68 MB (baseline 8.67 MB) • 🔴 +5.74 kBExternal libraries and shared vendor chunks
Status: 3 added / 3 removed Other — 7.29 MB (baseline 7.29 MB) • ⚪ 0 BBundles that do not match a named category
Status: 71 added / 71 removed |
Tailwind CSS 4.1.12 -> 4.1.18 causes pixel-level rendering changes. Delete the old baseline so CI can regenerate via /update-playwright. Amp-Thread-ID: https://ampcode.com/threads/T-019c4bb3-3bb3-714a-8f26-d775e658c14f Co-authored-by: Amp <[email protected]>
|
Updating Playwright Expectations |
Summary
Patch 6 dependency vulnerabilities (4 HIGH, 2 MODERATE) with minimal-risk version bumps.
Changes
Removed deprecated \showName/\dynamicTitle\ from Storybook toolbar config (dropped in 10.2.x).
Review Focus
All bumps stay within their major version. Remaining audit findings are transitive-only (linkifyjs, lodash, brace-expansion) tracked for future PRs.
┆Issue is synchronized with this Notion page by Unito