Skip to content
This repository was archived by the owner on Jul 27, 2026. It is now read-only.

fix(web): pin esbuild to 0.28.1 to clear high audit advisories - #34

Merged
kanywst merged 1 commit into
mainfrom
fix/esbuild-audit-override
Jun 15, 2026
Merged

kanywst merged 1 commit into
mainfrom
fix/esbuild-audit-override

Conversation

@kanywst

@kanywst kanywst commented Jun 15, 2026

Copy link
Copy Markdown
Member

What

The audit npm-vuln gate (npm audit --omit=dev --audit-level=high) is failing on main and on every open dependabot PR (#28–#33) with two high-severity esbuild advisories:

  • GHSA-gv7w-rqvm-qjhr — missing binary integrity verification in esbuild's Deno module
  • GHSA-g7r4-m6w7-qqqr — arbitrary file read in esbuild's dev server (Windows)

The vulnerable esbuild@0.27.7 comes in transitively via astro → vite. vite@7.3.3 declares esbuild ^0.27.0, but the advisories are only fixed in 0.28.1 — i.e. there is no safe esbuild release inside vite's declared range, so no dependabot bump can resolve it.

Fix

Add an overrides entry forcing esbuild@0.28.1.

Verification

  • npm audit --omit=dev --audit-level=high → found 0 vulnerabilities
  • npm run build → 58 pages built, no errors (vite 7.3.3 runs fine on esbuild 0.28.1)

Once merged, rebasing the dependabot PRs onto main clears their npm-vuln failures too.

vite 7.3.3 depends on esbuild ^0.27.0, but GHSA-gv7w-rqvm-qjhr and
GHSA-g7r4-m6w7-qqqr have no patched release inside that range (fixed in
0.28.1 only). This failed the audit npm-vuln gate on main and every open
dependabot PR. Add an overrides entry to force esbuild 0.28.1; build is
verified working and npm audit reports 0 vulnerabilities.
@coderabbitai

coderabbitai Bot commented Jun 15, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@kanywst, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 45 minutes and 46 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more credits in the billing tab to continue.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: c0021f83-ac87-4cce-8467-dd36c2d22486

📥 Commits

Reviewing files that changed from the base of the PR and between 312f6ce and a612679.

⛔ Files ignored due to path filters (1)
  • web/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • web/package.json
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/esbuild-audit-override

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the esbuild dependency from version 0.27.7 to 0.28.1 by adding an override in web/package.json and updating the corresponding entries in web/package-lock.json. There are no review comments, and I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@kanywst
kanywst merged commit a9bc41a into main Jun 15, 2026
14 checks passed
@kanywst
kanywst deleted the fix/esbuild-audit-override branch June 15, 2026 10:16
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant