Commit 757590f
chore(deps): bundle the five open dependabot lockfile bumps (#176)
## Motivation
Five open dependabot PRs, all lockfile-only transitive bumps, all
currently red because they were branched before the Forge CI fix in
#175. They also all edit the same two lockfiles, so merging them one at
a time forces the rest to rebase and burns a CI run each time.
Bundling them means one review and one CI run instead of five.
Supersedes #168, #169, #170, #171 and #172. Dependabot's commits are
cherry-picked unchanged, so authorship and the advisory trail are
preserved.
| PR | Bump | Advisory |
| --- | --- | --- |
| #172 | brace-expansion 2.0.1 to 2.1.4 | GHSA-mh99-v99m-4gvg,
CVE-2026-13149 (ReDoS) |
| #170 | pbkdf2 3.1.2 to 3.1.6 | CVE-2025-6545, CVE-2025-6547
(predictable key material) |
| #168 | immutable 4.1.0 to 4.3.9 | GHSA-v56q-mh7h-f735,
GHSA-xvcm-6775-5m9r, CVE-2026-29063 |
| #169 | immutable 4.1.0 to 4.3.9, vendored OZ copy | as above |
| #171 | min-document 2.19.0 to 2.19.2, vendored OZ copy | transitive |
## Solution
Two files change and both are lockfiles. No `package.json`, no contract
source, no submodule.
None of these five packages appears in this repo's `dependencies` or
`devDependencies`, so every one is transitive. `yarn.lock` is not
published to npm, so no consumer of the package is affected. The
Solidity dependencies come from the git submodules in `.gitmodules`
rather than npm, so the contracts are untouched.
`src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/package-lock.json`
is a vendored copy of OpenZeppelin, not a submodule, and nothing in the
build reads that lockfile. Those two entries (#169 and #171) are inert,
and are included here to close out the queue rather than because they
change behavior.
## Verification
Resolved versions after bundling:
```
yarn.lock brace-expansion 2.1.4 pbkdf2 3.1.6 immutable 4.3.9
vendored OZ lock immutable 4.3.9 min-document 2.19.2
```
All five cherry-picks applied without conflict, and the diff against
`main` touches nothing but the two lockfiles.
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent 454c9f8 commit 757590f
2 files changed
Lines changed: 200 additions & 28 deletions
File tree
- src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts
Lines changed: 12 additions & 12 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments