Skip to content

chore(deps): bundle the five open dependabot lockfile bumps - #176

Merged
ryanio merged 5 commits into
mainfrom
chore/dependency-bumps
Aug 24, 2026
Merged

chore(deps): bundle the five open dependabot lockfile bumps#176
ryanio merged 5 commits into
mainfrom
chore/dependency-bumps

Conversation

@ryanio

@ryanio ryanio commented Aug 24, 2026

Copy link
Copy Markdown
Collaborator

Motivation

Five open dependabot PRs, all lockfile-only transitive bumps, all currently red because they were branched before the Forge CI fix in #175. They also all edit the same two lockfiles, so merging them one at a time forces the rest to rebase and burns a CI run each time.

Bundling them means one review and one CI run instead of five.

Supersedes #168, #169, #170, #171 and #172. Dependabot's commits are cherry-picked unchanged, so authorship and the advisory trail are preserved.

PR Bump Advisory
#172 brace-expansion 2.0.1 to 2.1.4 GHSA-mh99-v99m-4gvg, CVE-2026-13149 (ReDoS)
#170 pbkdf2 3.1.2 to 3.1.6 CVE-2025-6545, CVE-2025-6547 (predictable key material)
#168 immutable 4.1.0 to 4.3.9 GHSA-v56q-mh7h-f735, GHSA-xvcm-6775-5m9r, CVE-2026-29063
#169 immutable 4.1.0 to 4.3.9, vendored OZ copy as above
#171 min-document 2.19.0 to 2.19.2, vendored OZ copy transitive

Solution

Two files change and both are lockfiles. No package.json, no contract source, no submodule.

None of these five packages appears in this repo's dependencies or devDependencies, so every one is transitive. yarn.lock is not published to npm, so no consumer of the package is affected. The Solidity dependencies come from the git submodules in .gitmodules rather than npm, so the contracts are untouched.

src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/package-lock.json is a vendored copy of OpenZeppelin, not a submodule, and nothing in the build reads that lockfile. Those two entries (#169 and #171) are inert, and are included here to close out the queue rather than because they change behavior.

Verification

Resolved versions after bundling:

yarn.lock          brace-expansion 2.1.4   pbkdf2 3.1.6   immutable 4.3.9
vendored OZ lock   immutable 4.3.9         min-document 2.19.2

All five cherry-picks applied without conflict, and the diff against main touches nothing but the two lockfiles.

dependabot Bot added 5 commits August 24, 2026 09:22
Bumps [pbkdf2](https://github.com/browserify/pbkdf2) from 3.1.2 to 3.1.6.
- [Changelog](https://github.com/browserify/pbkdf2/blob/master/CHANGELOG.md)
- [Commits](browserify/pbkdf2@v3.1.2...v3.1.6)

---
updated-dependencies:
- dependency-name: pbkdf2
  dependency-version: 3.1.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 4.1.0 to 4.3.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v4.1.0...v4.3.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 4.3.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.0.1 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.0.1...v2.1.4)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 4.1.0 to 4.3.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v4.1.0...v4.3.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 4.3.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [min-document](https://github.com/Raynos/min-document) from 2.19.0 to 2.19.2.
- [Commits](Raynos/min-document@v2.19.0...v2.19.2)

---
updated-dependencies:
- dependency-name: min-document
  dependency-version: 2.19.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@ryanio
ryanio merged commit 757590f into main Aug 24, 2026
10 checks passed
@github-actions

Copy link
Copy Markdown

Coverage Report for CI Build 32750560607

Warning

Build has drifted: This PR's base is out of sync with its target branch, so coverage data may include unrelated changes.
Quick fix: rebase this PR. Learn more →

Coverage remained the same at 64.702%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 905
Covered Lines: 693
Line Coverage: 76.57%
Relevant Branches: 605
Covered Branches: 284
Branch Coverage: 46.94%
Branches in Coverage %: Yes
Coverage Strength: 722.06 hits per line

💛 - Coveralls

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant