Skip to content

DUX-3335: fix Dependabot security alerts for webpack-dev-server (CVE-2025-30359, CVE-2025-30360)#233

Merged
BadassBison merged 1 commit intomasterfrom
DUX-3335-ae-page-objects-vulns
Apr 13, 2026
Merged

DUX-3335: fix Dependabot security alerts for webpack-dev-server (CVE-2025-30359, CVE-2025-30360)#233
BadassBison merged 1 commit intomasterfrom
DUX-3335-ae-page-objects-vulns

Conversation

@BadassBison
Copy link
Copy Markdown
Contributor

@BadassBison BadassBison commented Apr 12, 2026

Summary

Bumps webpack-dev-server constraint from ^3.10.3 to >=5.2.1 in the three test app package.json files to resolve 6 open Dependabot alerts.

Vulnerabilities fixed

Alert Package Ecosystem Severity CVE Fix
#68 webpack-dev-server npm MEDIUM CVE-2025-30359 >=5.2.1 in test/test_apps/7.2
#69 webpack-dev-server npm MEDIUM CVE-2025-30360 >=5.2.1 in test/test_apps/7.2
#70 webpack-dev-server npm MEDIUM CVE-2025-30359 >=5.2.1 in test/test_apps/8.0
#71 webpack-dev-server npm MEDIUM CVE-2025-30360 >=5.2.1 in test/test_apps/8.0
#72 webpack-dev-server npm MEDIUM CVE-2025-30359 >=5.2.1 in test/test_apps/8.1
#73 webpack-dev-server npm MEDIUM CVE-2025-30360 >=5.2.1 in test/test_apps/8.1

No gem release needed

These changes only affect devDependencies in test app package.json files. The gem itself is unchanged — no version bump or new release is required.

Note on full cleanup (future work)

The webpack-dev-server entry in these package.json files appears to be vestigial — there are no lock files in any test app directory and CI never runs yarn install. A follow-up cleanup could remove webpack-dev-server from devDependencies entirely rather than carrying forward this stale constraint. This PR takes the minimal approach (constraint bump) to close the alerts with the smallest possible diff.

Test plan

🤖 Generated with Claude Code using /dependabot-fix

@kermitapp
Copy link
Copy Markdown

kermitapp Bot commented Apr 12, 2026

…VE-2025-30360

Fixes Dependabot alerts #68#73 across test app directories.

Severities: MEDIUM
CVEs: CVE-2025-30359, CVE-2025-30360
Package: webpack-dev-server (devDependency in test/test_apps/*/package.json)
@BadassBison BadassBison force-pushed the DUX-3335-ae-page-objects-vulns branch from 1e0ca7e to 75587b5 Compare April 12, 2026 20:57
@BadassBison BadassBison marked this pull request as ready for review April 12, 2026 21:04
@BadassBison BadassBison requested a review from a team as a code owner April 12, 2026 21:04
@BadassBison BadassBison merged commit 184ee95 into master Apr 13, 2026
13 checks passed
@BadassBison BadassBison deleted the DUX-3335-ae-page-objects-vulns branch April 13, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants