Files
jobtrackingapp/docs/verification/dep-001-frontend-advisories.md
T
cesnimda d7b556e494
CI and Deploy / test (pull_request) Failing after 4m12s
CI and Deploy / deploy (pull_request) Has been skipped
docs(deps): record advisory remediation
2026-08-10 00:42:41 +02:00

1.8 KiB

DEP-001 frontend advisory remediation

Updated: 2026-08-10

Status: VERIFIED LOCALLY. The repository fix is pushed; CI and live deployment verification remain.

Trigger

The live deployment pipeline failed its frontend dependency audit on five advisories: React Router/@remix-run/router, js-yaml and nanoid.

Resolution

  • Upgraded react-router-dom from the vulnerable 6.x line to 7.18.2, covering the subsequently reported React Router advisories.
  • Refreshed transitive js-yaml from 3.15.0 to 3.15.1 and nanoid from 3.3.16 to 3.3.18 through normal lockfile resolution.
  • Removed the obsolete v6 RouterProvider future flag. Existing route definitions and URLs were not redesigned.
  • Supplied Node's TextEncoder/TextDecoder to Jest's jsdom environment for React Router v7 module initialization.
  • Did not run npm audit fix --force; the explicit upgrade and resolved lockfile were reviewed.

Verification

  • npm.cmd audit: PASS, zero vulnerabilities.
  • Focused data-router regression: 6 suites, 24 tests passed.
  • Full frontend regression: 49 suites, 190 tests passed.
  • npm.cmd run build: PASS, production compilation, TypeScript and static generation.
  • Resolved versions: react-router-dom/react-router 7.18.2, js-yaml 3.15.1, nanoid 3.3.18.
  • Commit: b55a592 (pushed to release-readiness).

Remaining gate

Confirm the repository CI dependency-audit job and subsequent live deployment complete from the pushed commit. No production access or deployment was performed in this session.

Rollback

Reverting b55a592 restores the previous router/test setup but also restores known vulnerable packages and the deployment-blocking audit result. Prefer fixing any v7 compatibility regression forward; do not suppress the audit without a reviewed exception.