Consolidate Dependabot dependency updates - #156
Merged
Merged
Conversation
Bumps @docusaurus/core and @docusaurus/preset-classic to 3.10.2 and adds npm overrides for uuid and serialize-javascript to resolve all outstanding Dependabot security alerts in one pass (65 alerts across 9 open PRs plus additional transitive vulnerabilities not yet covered by a PR). Verified with npm audit (0 vulnerabilities) and a full docusaurus build. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
🔵 Needs a closer look
Broad dependency and transitive-resolution changes warrant final human review.
Pull request overview
Consolidates Dependabot security updates for the Docusaurus documentation build.
Changes:
- Upgrades Docusaurus packages to 3.10.2.
- Adds overrides for patched
uuidandserialize-javascriptversions. - Aligns React dependencies and refreshes dependency resolutions.
File summaries
| File | Description |
|---|---|
package.json |
Updates Docusaurus dependencies and adds security overrides. |
Review details
- Files reviewed: 1/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Jancis
approved these changes
Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@docusaurus/coreand@docusaurus/preset-classicfrom 3.9.1 to 3.10.2, which pulls in patched transitive dependencies across the whole build toolchain.overridesforuuid(^11.1.1) andserialize-javascript(^7.1.1) to force-patch two deeply nested transitive packages that npm's own resolver couldn't bump without a spurious "downgrade" suggestion.This consolidates the fixes from all 9 currently open Dependabot PRs (#154, #153, #152, #151, #150, #148, #147, #145, #143) plus additional transitive vulnerabilities that had open Dependabot security alerts but no PR yet.
npm auditgoes from 65 open Dependabot alerts / 50 local vulnerabilities down to 0.Doing this as a single consolidated branch avoids running CI/build 9+ separate times for what is ultimately one lockfile. Once this merges, Dependabot should auto-close the individual PRs since the same version bumps are already satisfied on
master.Test plan
npm install— clean install, no peer dependency errorsnpm audit— 0 vulnerabilities (was 50 local / 65 total including alerts without PRs yet)npm run build— production build succeedsnpm run serve— verified homepage and a docs page render correctly in a browser, no console errors🤖 Generated with Claude Code