Loading
chore(ui): bump moment and vulnerable dependency overrides
pnpm audit on master reports 27 advisories in the UI tree. This clears the 21 that have a fix inside the major versions already in use; 6 remain.
Changes
| Package | Before | After | Cleared |
|---|---|---|---|
moment |
2.30.1 | 2.31.0 | CVE-2026-17495 (GitHub issue 391) |
dompurify |
3.4.14 | 3.4.16 | two low-severity advisories without a CVE id |
fast-uri |
3.1.5 | 3.1.8 | CVE-2026-75899, -75931, -75975, -76172, -84292, -86472 |
brace-expansion |
1.1.18, 5.0.9 | 1.1.21, 5.0.12 | CVE-2026-102276, -102277, -102278 |
browserslist |
4.28.2 | 4.29.3 | CVE-2026-73088, -73089 |
baseline-browser-mapping |
2.10.13 | 2.11.27 | CVE-2026-45819 |
js-yaml |
4.3.1 | 4.3.2 | CVE-2026-84375 |
source-map-js |
1.2.1 | 1.2.2 | CVE-2026-93749 |
@humanfs/node |
0.16.7 | 0.16.8 | one moderate advisory without a CVE id |
moment is a direct dependency of ui/packages/ce and ui/packages/shared; its range moves from ^2.24.0 to ^2.31.0. Everything else is transitive and goes through pnpm.overrides in ui/package.json: the existing dompurify, fast-uri, brace-expansion and js-yaml entries are raised, and entries for browserslist, baseline-browser-mapping, source-map-js and @humanfs/node are new. ui/pnpm-lock.yaml is regenerated with pnpm install --lockfile-only.
Only moment and dompurify (via monaco-editor) end up in the shipped bundle. The rest is build, lint and test tooling.
Not addressed
tinypool(CVE-2026-104848, -104849) andvitest/@vitest/mocker(CVE-2026-84373): the fixes are intinypool2.x andvitest4.1.11, and the tree is onvitest3.2.7. Test tooling only.postcss-selector-parser(CVE-2026-104844): fixed in 7.1.6, whilestylelint14 depends on 6.x.braces(CVE-2026-93687): no fixed release. Reached throughcspell.deepmerge2.2.1 (CVE-2026-93753, GitHub issue 392): the CVE covers every release through 4.3.1, the latest, so there is no version to override to. It comes in throughformik, which calls it only inrunAllValidationsto merge validation-error objects keyed by the field names of the yup schemas, so no untrusted keys reach it.