docs(deps): record advisory remediation
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
# DEP-001 frontend advisory remediation
|
||||
|
||||
Updated: 2026-08-10
|
||||
|
||||
Status: `VERIFIED LOCALLY`. The repository fix is pushed; CI and live deployment verification remain.
|
||||
|
||||
## Trigger
|
||||
|
||||
The live deployment pipeline failed its frontend dependency audit on five advisories: React Router/@remix-run/router, js-yaml and nanoid.
|
||||
|
||||
## Resolution
|
||||
|
||||
- Upgraded `react-router-dom` from the vulnerable 6.x line to `7.18.2`, covering the subsequently reported React Router advisories.
|
||||
- Refreshed transitive `js-yaml` from `3.15.0` to `3.15.1` and `nanoid` from `3.3.16` to `3.3.18` through normal lockfile resolution.
|
||||
- Removed the obsolete v6 `RouterProvider` future flag. Existing route definitions and URLs were not redesigned.
|
||||
- Supplied Node's `TextEncoder`/`TextDecoder` to Jest's jsdom environment for React Router v7 module initialization.
|
||||
- Did not run `npm audit fix --force`; the explicit upgrade and resolved lockfile were reviewed.
|
||||
|
||||
## Verification
|
||||
|
||||
- `npm.cmd audit`: PASS, zero vulnerabilities.
|
||||
- Focused data-router regression: 6 suites, 24 tests passed.
|
||||
- Full frontend regression: 49 suites, 190 tests passed.
|
||||
- `npm.cmd run build`: PASS, production compilation, TypeScript and static generation.
|
||||
- Resolved versions: `react-router-dom`/`react-router` `7.18.2`, `js-yaml` `3.15.1`, `nanoid` `3.3.18`.
|
||||
- Commit: `b55a592` (pushed to `release-readiness`).
|
||||
|
||||
## Remaining gate
|
||||
|
||||
Confirm the repository CI dependency-audit job and subsequent live deployment complete from the pushed commit. No production access or deployment was performed in this session.
|
||||
|
||||
## Rollback
|
||||
|
||||
Reverting `b55a592` restores the previous router/test setup but also restores known vulnerable packages and the deployment-blocking audit result. Prefer fixing any v7 compatibility regression forward; do not suppress the audit without a reviewed exception.
|
||||
Reference in New Issue
Block a user