Skip to content

Commit 757590f

Browse files
chore(deps): bundle the five open dependabot lockfile bumps (#176)
## Motivation Five open dependabot PRs, all lockfile-only transitive bumps, all currently red because they were branched before the Forge CI fix in #175. They also all edit the same two lockfiles, so merging them one at a time forces the rest to rebase and burns a CI run each time. Bundling them means one review and one CI run instead of five. Supersedes #168, #169, #170, #171 and #172. Dependabot's commits are cherry-picked unchanged, so authorship and the advisory trail are preserved. | PR | Bump | Advisory | | --- | --- | --- | | #172 | brace-expansion 2.0.1 to 2.1.4 | GHSA-mh99-v99m-4gvg, CVE-2026-13149 (ReDoS) | | #170 | pbkdf2 3.1.2 to 3.1.6 | CVE-2025-6545, CVE-2025-6547 (predictable key material) | | #168 | immutable 4.1.0 to 4.3.9 | GHSA-v56q-mh7h-f735, GHSA-xvcm-6775-5m9r, CVE-2026-29063 | | #169 | immutable 4.1.0 to 4.3.9, vendored OZ copy | as above | | #171 | min-document 2.19.0 to 2.19.2, vendored OZ copy | transitive | ## Solution Two files change and both are lockfiles. No `package.json`, no contract source, no submodule. None of these five packages appears in this repo's `dependencies` or `devDependencies`, so every one is transitive. `yarn.lock` is not published to npm, so no consumer of the package is affected. The Solidity dependencies come from the git submodules in `.gitmodules` rather than npm, so the contracts are untouched. `src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/package-lock.json` is a vendored copy of OpenZeppelin, not a submodule, and nothing in the build reads that lockfile. Those two entries (#169 and #171) are inert, and are included here to close out the queue rather than because they change behavior. ## Verification Resolved versions after bundling: ``` yarn.lock brace-expansion 2.1.4 pbkdf2 3.1.6 immutable 4.3.9 vendored OZ lock immutable 4.3.9 min-document 2.19.2 ``` All five cherry-picks applied without conflict, and the diff against `main` touches nothing but the two lockfiles. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 454c9f8 commit 757590f

2 files changed

Lines changed: 200 additions & 28 deletions

File tree

src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/package-lock.json

Lines changed: 12 additions & 12 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)