All 52 reviewed open alerts have been addressed in the local dev working tree. Every package entry in pnpm-lock.yaml was compared to the GitHub alert ranges; zero affected versions remain. pnpm audit reports no known vulnerabilities.
The changes are not committed or pushed yet. GitHub still has 52 open alerts because its default branch, master, has the old dependency graph. These should close as fixed after the changes reach master; do not dismiss still-vulnerable master dependencies as inaccurate or unused.
- Upgrade @dicebear/collection to ^9.4.3.
- Add targeted security overrides in pnpm-workspace.yaml and regenerate/prune pnpm-lock.yaml, including all vulnerable transitive copies.
- Upgrade d3-color to 3.1.0 and deepmerge-ts to 8.0.2. The former changes module packaging; map SSR and browser bundling passed. Prisma uses the deepmerge API retained in v8; config validation and client generation passed. v8 changes Map merge behavior, which is not used in this repository’s Prisma configuration.
- Convert PostCSS plugin configuration to the object form accepted by Next.js and Vite, retaining all plugin options. This fixes CSS loading in the updated test tooling.
| Package | Versions in local dev lockfile | Alerts covered |
|---|---|---|
| next | 16.3.4 | #335, #334, #333, #332 |
| sharp | 0.35.4 | #331 |
| vitest | 4.1.11 | #330 |
| @vitest/mocker | 4.1.11 | #329 |
| svgo | 3.3.5 | #328, #327, #260, #131 |
| js-yaml | 4.3.2 | #326, #308, #254, #253 |
| colord | 2.10.0 | #325 |
| browserslist | 4.28.7 | #324, #323 |
| fflate | 0.4.9 | #322 |
| fast-uri | 3.1.6 | #321, #320, #317, #316, #302 |
| @dicebear/initials | 9.4.3 | #319 |
| mysql2 | 3.23.1 | #318, #315 |
| deepmerge-ts | 8.0.2 | #314 |
| nanoid | 3.3.18 | #313 |
| brace-expansion | 1.1.18, 2.1.4, 5.0.9 | #311, #310, #309, #304, #294, #288, #171, #162 |
| d3-color | 3.1.0 | #292 |
| shell-quote | 1.9.0 | #263, #228 |
| @babel/core | 7.29.6 | #252 |
| vite | 8.0.16 | #235, #234 |
| esbuild | 0.28.2 | #230 |
| picomatch | 4.0.4, 4.0.5 | #153 |
| minimatch | 3.1.4, 5.1.8, 5.1.9, 9.0.7 | #127, #125, #124, #121, #120, #118, #116 |
- Frozen lockfile installation: passed.
- All 52 Dependabot vulnerable-range comparisons: passed.
- pnpm audit: zero known vulnerabilities.
- Prisma schema validation and client generation: passed.
- API client and MCP builds, including declarations: passed.
- Workspace package tests: 50 passed.
- Map server rendering and browser bundle with d3-color 3.1.0: passed.
- Tracker and recorder Rollup bundles: passed.
- Biome checks for changed JavaScript/JSON and git diff --check: passed.
- Root test suite: 857 tests passed across 115 files (vitest run --maxWorkers=4).
- Next.js production build: passed. The existing Next.js configuration skips TypeScript validation during builds.
Existing React/React DOM peer warnings (react-simple-maps/react-spring) and TypeScript peer warnings (openapi-typescript) remain; these are not vulnerability findings. No new tests were written.