Skip to content

MLE-24928 Fixing CVEs - #304

Merged
rjrudin merged 1 commit into
developfrom
feature/bumps
Oct 28, 2025
Merged

rjrudin merged 1 commit into
developfrom
feature/bumps

Conversation

@rjrudin

@rjrudin rjrudin commented Oct 28, 2025

Copy link
Copy Markdown
Contributor

Main one - bumping webpack to 5.102.1 .

Also bumping mocha to 10.8.2 to knock out a couple other CVEs.

Want to see what Black Duck thinks about this. Have not done any testing of this, will address that later when we plan to do a new release. At which point, we will likely update to Node Client 4.0 and require Node 22, and thus update types/node (which the webpackFix comment states is likely necessary).

Main one - bumping webpack to 5.102.1 .

Also bumping mocha to 10.8.2 to knock out a couple other CVEs.

Want to see what Black Duck thinks about this. Have not done any testing of this, will address that later when we plan to do a new release. At which point, we will likely update to Node Client 4.0 and require Node 22, and thus update types/node (which the webpackFix comment states is likely necessary).
Copilot AI review requested due to automatic review settings October 28, 2025 18:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR addresses security vulnerabilities by updating multiple dependencies to newer versions. The primary change is upgrading webpack from 5.76.1 to 5.102.1, with mocha being updated to 10.8.2 across both package.json files. Additional supporting dependencies have been updated to maintain compatibility with these core changes.

Key Changes:

  • Upgraded webpack to 5.102.1 and webpack-cli to 6.0.1 to address CVEs
  • Updated mocha to 10.8.2 in both root and server package.json files
  • Updated various supporting packages including @vscode/debugadapter, fast-xml-parser, marklogic, ts-loader, and vscode-languageclient

Reviewed Changes

Copilot reviewed 2 out of 4 changed files in this pull request and generated 1 comment.

File Description
package.json Updates webpack, mocha, and several dependencies to newer versions; bumps @types/mocha and @vscode/test-cli
server/package.json Updates mocha version and reorders dependency list entries
Files not reviewed (1)
  • server/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread package.json
"ts-loader": "9.5.1",
"vscode-languageclient": "7.0.0",
"ts-loader": "9.5.4",
"vscode-languageclient": "7.1.0-next.5",

Copilot AI Oct 28, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using a pre-release version (7.1.0-next.5) of vscode-languageclient in production dependencies could introduce instability. Consider using a stable release version unless there's a specific requirement for this pre-release.

Suggested change
"vscode-languageclient": "7.1.0-next.5",
"vscode-languageclient": "7.1.0",

Copilot uses AI. Check for mistakes.
@rjrudin
rjrudin merged commit 8424a11 into develop Oct 28, 2025
1 check passed
@rjrudin
rjrudin deleted the feature/bumps branch October 28, 2025 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants