rusackas opened a new pull request, #44740: URL: https://github.com/apache/superset/pull/44740
### SUMMARY Resolves five open Dependabot alerts across the two npm lockfiles. All of them are transitive dependencies, so there's no direct `package.json` dependency to bump; each is handled with a lockfile bump plus, where the parent's declared range doesn't admit the patched release, a per-parent `overrides` entry (following the pattern already used in both files for `js-yaml`). | Alert | Advisory | Package | Pulled in by | Resolution | |---|---|---|---|---| | #1564 (medium) | GHSA-px8p-9vwx-vf98 | `fflate` 0.7.4 → 0.7.5 | `@loaders.gl/[email protected]` (pins `0.7.4` exactly) | lockfile bump + `overrides["@loaders.gl/compression"].fflate = "^0.7.5"`. The root `[email protected]` (jspdf, numcodecs) was already outside the vulnerable range and is untouched. | | #1590 (high) | GHSA-w3rx-r6r6-pgpr | `image-size` 0.7.5 → 2.0.3 | `[email protected]` ← `@loaders.gl/textures` (declares `^0.7.4`) | lockfile bump + `overrides["texture-compressor"]["image-size"] = "^2.0.3"`. See note below on why the major jump is safe here. | | #1582 (high) | GHSA-2883-xcg3-v3hh | `js-yaml` 4.3.1 → 4.3.2 (`superset-frontend`) | `cosmiconfig` (×3), `lerna` (pins `4.3.0`), `react-diff-viewer-continued` | lockfile bump of the four nested 4.x copies + bumped the existing `cosmiconfig` / `lerna` / `react-diff-viewer-continued` overrides from `^4.3.1` to `^4.3.2`. | | #1573 (high) | GHSA-2883-xcg3-v3hh | `js-yaml` 4.3.1 → 4.3.2 (`cypress-base`) | `@cypress/[email protected]` (pins `4.1.0`) | lockfile bump + bumped the existing `@cypress/code-coverage` override from `4.3.1` to `^4.3.2`. | | #1585 (high) | GHSA-7w5x-hrqm-74c2 | `smol-toml` 1.6.1 → 1.7.1 | `[email protected]` ← `lerna` (pins `1.6.1` exactly) | lockfile bump + `overrides.nx["smol-toml"] = "^1.7.1"`. | The `[email protected]` copies (`@istanbuljs/load-nyc-config`, `js-yaml-loader`) are a different major and outside the advisory's `>=4.0.0 <4.3.2` range, so they're left alone. **Why `image-size` 0.7 → 2.0 is safe:** `image-size` only exists in this tree because `texture-compressor` (a Node CLI for encoding GPU textures) depends on it. `@loaders.gl/textures` never imports `texture-compressor` as a module; its only reference is spawning `npx texture-compressor` as a child process from its Node-side `CompressedTextureWriter`. Nothing in Superset's source, webpack config or build scripts calls that writer or the CLI, so the `image-size` API change in 2.x can't affect the browser bundle or the build. Its `engines.node` moves to `>=18`, which is already below the repo's Node baseline. **Not included:** `extract-zip` in `cypress-base` has no patched version available, and `anyio` (Python) is handled separately in #44735. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A — dependency lockfile change only. ### TESTING INSTRUCTIONS Both lockfiles were edited surgically (patched `version` / `resolved` / `integrity` from the registry), then regenerated with `npm install --package-lock-only --ignore-scripts` in each directory to confirm npm produces the same result ("up to date", no further changes). ```bash cd superset-frontend npm ls fflate image-size js-yaml smol-toml --package-lock-only # expect: [email protected] (under @loaders.gl/compression) and [email protected] (root), # [email protected], [email protected], [email protected] for every 4.x copy, # [email protected] for the two 3.x copies, and no "invalid" / "missing" markers cd cypress-base npm ls js-yaml --package-lock-only # expect: [email protected] only ``` CI (`npm ci`, frontend build, jest, Cypress/Playwright) covers the rest. ### ADDITIONAL INFORMATION <!--- Check any relevant boxes with "x" --> - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration (follow approval process in [SIP-59](https://github.com/apache/superset/issues/13351)) - [ ] Migration is atomic, supports rollback & is backwards-compatible - [ ] Confirm DB migration upgrade and downgrade tested - [ ] Runtime estimates and downtime expectations provided - [ ] Introduces new feature or API - [ ] Removes existing feature or API 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
