Triage of the fork's open Dependabot alerts, done once so nobody has to face "121 alerts" again. Measured 2026-09-08.
The raw picture
|
|
| open alerts |
121 — 4 critical, 54 high, 53 medium, 10 low |
| npm scope |
91 dependencies, 30 devDependencies |
| open fix PRs |
17, all now targeting this trunk |
The axis that matters
dependencies vs devDependencies is not the same question as "does it reach the browser". This fork is consumed by nextview-viewer through webpack, so a CVE in build tooling is a build-host concern, while one in a bundled library is a product concern.
Of the 17 packages with fix PRs, only 4 are direct dependencies of this repo — dompurify, lodash-es, linkify-it, @babel/core — and the last is build tooling despite its declaration. The other 13 are transitive.
Caveat on method, stated so nobody repeats it: I tried to settle "does it ship" by grepping the deployed bundle for package names. That does not work — minification strips them, and protobufjs reads as 0 occurrences while plainly being present via Cesium. The reliable method is the bundle's module manifest (source maps / bundle analyzer), which is the one piece of this triage still owed.
The decision list
Act — runtime-scope, fix PR available
Merge order roughly by exposure. dompurify matters most on principle: it is the XSS sanitiser, so a defect there is directly a product risk.
protobufjs (critical) · lodash-es · linkify-it · lodash · nanoid · postcss · fast-uri · browserslist
Escalate — runtime-scope, NO fix PR exists
Dependabot cannot find a non-breaking upgrade path, so these need a human decision: bump the parent, patch, or accept and record why. This is the group that will still be open in six months if nobody owns it.
fast-xml-parser — CRITICAL, no fix PR. The single most important line in this issue.
tinymce (high) · underscore (high) · serialize-javascript (high) · picomatch (high) · @babel/plugin-transform-modules-systemjs (high)
Deprioritise — development scope
Build/test/docs tooling. Real, but they do not reach the product.
form-data (critical, dev) · brace-expansion · flatted · minimatch · tmp · js-yaml · immutable · svgo
Special mention: mkdocs-material has an open PR and is a Python documentation dependency. It cannot reach a browser bundle under any circumstances.
Why this is not just a list
The durable fix is not merging these 17. It is that this fork is 35 commits ahead of and 3,346 behind upstream, so it accrues advisories that upstream has already fixed and we cannot take. Every commit upstreamed and every step of re-baselining removes CVEs wholesale rather than one PR at a time.
Related
Triage of the fork's open Dependabot alerts, done once so nobody has to face "121 alerts" again. Measured 2026-09-08.
The raw picture
dependencies, 30devDependenciesThe axis that matters
dependenciesvsdevDependenciesis not the same question as "does it reach the browser". This fork is consumed bynextview-viewerthrough webpack, so a CVE in build tooling is a build-host concern, while one in a bundled library is a product concern.Of the 17 packages with fix PRs, only 4 are direct dependencies of this repo —
dompurify,lodash-es,linkify-it,@babel/core— and the last is build tooling despite its declaration. The other 13 are transitive.Caveat on method, stated so nobody repeats it: I tried to settle "does it ship" by grepping the deployed bundle for package names. That does not work — minification strips them, and
protobufjsreads as 0 occurrences while plainly being present via Cesium. The reliable method is the bundle's module manifest (source maps / bundle analyzer), which is the one piece of this triage still owed.The decision list
Act — runtime-scope, fix PR available
Merge order roughly by exposure.
dompurifymatters most on principle: it is the XSS sanitiser, so a defect there is directly a product risk.protobufjs(critical) ·lodash-es·linkify-it·lodash·nanoid·postcss·fast-uri·browserslistEscalate — runtime-scope, NO fix PR exists
Dependabot cannot find a non-breaking upgrade path, so these need a human decision: bump the parent, patch, or accept and record why. This is the group that will still be open in six months if nobody owns it.
fast-xml-parser— CRITICAL, no fix PR. The single most important line in this issue.tinymce(high) ·underscore(high) ·serialize-javascript(high) ·picomatch(high) ·@babel/plugin-transform-modules-systemjs(high)Deprioritise — development scope
Build/test/docs tooling. Real, but they do not reach the product.
form-data(critical, dev) ·brace-expansion·flatted·minimatch·tmp·js-yaml·immutable·svgoSpecial mention:
mkdocs-materialhas an open PR and is a Python documentation dependency. It cannot reach a browser bundle under any circumstances.Why this is not just a list
The durable fix is not merging these 17. It is that this fork is 35 commits ahead of and 3,346 behind upstream, so it accrues advisories that upstream has already fixed and we cannot take. Every commit upstreamed and every step of re-baselining removes CVEs wholesale rather than one PR at a time.
Related
mainmirror too #80 — the fork's gate, and owning the workflow surface in code