Repository navigation
fix(web): pin esbuild to 0.28.1 to clear high audit advisories - #34
Conversation
vite 7.3.3 depends on esbuild ^0.27.0, but GHSA-gv7w-rqvm-qjhr and GHSA-g7r4-m6w7-qqqr have no patched release inside that range (fixed in 0.28.1 only). This failed the audit npm-vuln gate on main and every open dependabot PR. Add an overrides entry to force esbuild 0.28.1; build is verified working and npm audit reports 0 vulnerabilities.
|
Warning Review limit reached
More reviews will be available in 45 minutes and 46 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more credits in the billing tab to continue. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request updates the esbuild dependency from version 0.27.7 to 0.28.1 by adding an override in web/package.json and updating the corresponding entries in web/package-lock.json. There are no review comments, and I have no feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
What
The audit
npm-vulngate (npm audit --omit=dev --audit-level=high) is failing onmainand on every open dependabot PR (#28–#33) with two high-severity esbuild advisories:GHSA-gv7w-rqvm-qjhr— missing binary integrity verification in esbuild's Deno moduleGHSA-g7r4-m6w7-qqqr— arbitrary file read in esbuild's dev server (Windows)The vulnerable
esbuild@0.27.7comes in transitively viaastro → vite.vite@7.3.3declaresesbuild ^0.27.0, but the advisories are only fixed in0.28.1— i.e. there is no safe esbuild release inside vite's declared range, so no dependabot bump can resolve it.Fix
Add an
overridesentry forcingesbuild@0.28.1.Verification
npm audit --omit=dev --audit-level=high→ found 0 vulnerabilitiesnpm run build→ 58 pages built, no errors (vite 7.3.3 runs fine on esbuild 0.28.1)Once merged, rebasing the dependabot PRs onto
mainclears theirnpm-vulnfailures too.