Skip to content

fix(deps): address security vulnerabilities in dompurify, vite, and next - #2194

Merged
czarandy merged 1 commit into
mainfrom
security/update-vulnerable-deps
May 19, 2026
Merged

czarandy merged 1 commit into
mainfrom
security/update-vulnerable-deps

Conversation

@czarandy

@czarandy czarandy commented May 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • dompurify (medium): added ^3.3.2 resolution to root package.json — resolves to 3.4.5 (was 3.2.7, transitive via monaco-editor)
  • vite (medium): bumped internal/vibe-tests/app from ^5.0.0 to ^6.4.2 and added ^6.4.2 resolution to root — resolves to 6.4.2 (was 5.4.21)
  • next (high): bumped from ^15.5.15 to ^15.5.16 across 6 apps (docsite, sandbox, example-nextjs, example-nextjs-source, example-nextjs-stylex, example-nextjs-tailwind) — resolves to 15.5.18

Test plan

  • Verify yarn install succeeds with no new errors
  • Verify Storybook dev server starts (yarn dev)
  • Verify docsite builds (yarn workspace @xds/docs build)
  • Spot-check that vibe-tests app still builds

@vercel

vercel Bot commented May 18, 2026

Copy link
Copy Markdown

@czarandy must be a member of the Meta Open Source team on Vercel to deploy.
- Click here to add @czarandy to the team.
- If you initiated this build, request access.

Learn more about collaboration on Vercel and other options here.

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Meta Open Source bot. label May 18, 2026
- dompurify: resolve to ^3.3.2 (was 3.2.7, affected <= 3.3.1, medium severity)
- vite: bump to ^6.4.2 and add resolution (was 5.4.21, affected <= 6.4.1, medium severity)
- next: bump to ^15.5.16 across all apps (was 15.5.15, affected < 15.5.16, high severity)
@vercel

vercel Bot commented May 19, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
xds-sandbox Error Error May 19, 2026 0:12am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

PR Analysis Report

📚 Storybook Preview

View Storybook for this PR
GitHub Pages may take up to a minute to hydrate after deploy.

🧪 Sandbox Preview

View Sandbox for this PR
GitHub Pages may take up to a minute to hydrate after deploy.

No new or modified components detected.

Bundle Size Summary

Package Size (ESM) Size (CJS) Gzipped
@xds/core 18.3KB 28.3KB 4.2KB

Accessibility Audit

Status: No accessibility violations detected.


Generated by PR Enrichment workflow | Storybook | Sandbox | View full report

@cixzhang cixzhang left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Safe patches across the board. Vite major bump is contained to internal test app. Ship it.

@czarandy
czarandy merged commit d387d08 into main May 19, 2026
20 of 21 checks passed
@czarandy
czarandy deleted the security/update-vulnerable-deps branch May 19, 2026 02:17
cixzhang pushed a commit that referenced this pull request Jun 21, 2026
…ext (#2194)

- dompurify: resolve to ^3.3.2 (was 3.2.7, affected <= 3.3.1, medium severity)
- vite: bump to ^6.4.2 and add resolution (was 5.4.21, affected <= 6.4.1, medium severity)
- next: bump to ^15.5.16 across all apps (was 15.5.15, affected < 15.5.16, high severity)
cixzhang pushed a commit that referenced this pull request Jun 21, 2026
…ext (#2194)

- dompurify: resolve to ^3.3.2 (was 3.2.7, affected <= 3.3.1, medium severity)
- vite: bump to ^6.4.2 and add resolution (was 5.4.21, affected <= 6.4.1, medium severity)
- next: bump to ^15.5.16 across all apps (was 15.5.15, affected < 15.5.16, high severity)

This branch had an error being deployed

1 failed deployment
Preview — 9809c07f Deployed May 19, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Meta Open Source bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants