chore(ui): bump moment and vulnerable dependency overrides

pnpm audit on master reports 27 advisories in the UI tree. This clears the 21 that have a fix inside the major versions already in use; 6 remain.

Changes

Package Before After Cleared
moment 2.30.1 2.31.0 CVE-2026-17495 (GitHub issue 391)
dompurify 3.4.14 3.4.16 two low-severity advisories without a CVE id
fast-uri 3.1.5 3.1.8 CVE-2026-75899, -75931, -75975, -76172, -84292, -86472
brace-expansion 1.1.18, 5.0.9 1.1.21, 5.0.12 CVE-2026-102276, -102277, -102278
browserslist 4.28.2 4.29.3 CVE-2026-73088, -73089
baseline-browser-mapping 2.10.13 2.11.27 CVE-2026-45819
js-yaml 4.3.1 4.3.2 CVE-2026-84375
source-map-js 1.2.1 1.2.2 CVE-2026-93749
@humanfs/node 0.16.7 0.16.8 one moderate advisory without a CVE id

moment is a direct dependency of ui/packages/ce and ui/packages/shared; its range moves from ^2.24.0 to ^2.31.0. Everything else is transitive and goes through pnpm.overrides in ui/package.json: the existing dompurify, fast-uri, brace-expansion and js-yaml entries are raised, and entries for browserslist, baseline-browser-mapping, source-map-js and @humanfs/node are new. ui/pnpm-lock.yaml is regenerated with pnpm install --lockfile-only.

Only moment and dompurify (via monaco-editor) end up in the shipped bundle. The rest is build, lint and test tooling.

Not addressed

  • tinypool (CVE-2026-104848, -104849) and vitest / @vitest/mocker (CVE-2026-84373): the fixes are in tinypool 2.x and vitest 4.1.11, and the tree is on vitest 3.2.7. Test tooling only.
  • postcss-selector-parser (CVE-2026-104844): fixed in 7.1.6, while stylelint 14 depends on 6.x.
  • braces (CVE-2026-93687): no fixed release. Reached through cspell.
  • deepmerge 2.2.1 (CVE-2026-93753, GitHub issue 392): the CVE covers every release through 4.3.1, the latest, so there is no version to override to. It comes in through formik, which calls it only in runAllValidations to merge validation-error objects keyed by the field names of the yup schemas, so no untrusted keys reach it.

Merge request reports

Loading
Loading