Skip to content

Update frontend dependencies (DOMPurify XSS fixes, Vite 7, Node 22) - #714

Open
chrisclark wants to merge 2 commits into
masterfrom
frontend-deps
Open

chrisclark wants to merge 2 commits into
masterfrom
frontend-deps

Conversation

@chrisclark

Copy link
Copy Markdown
Collaborator

Replaces the stale Dependabot PRs #680 and #682. npm audit goes from 14 findings (11 high) to 1.

Runtime (shipped in the browser bundle)

  • DOMPurify 3.1.3 → 3.4.16. This fixes XSS advisories GHSA-v2wj-7wpq-c8vv and others. DOMPurify sanitizes the AI Assistant's markdown before it's inserted with innerHTML, so these advisories reached end users.
  • Transitive fixes: nanoid, immutable, postcss, rollup, @babel/runtime and others, all via npm audit fix with no range changes.

Build tooling

  • Vite 5 → 7. I stopped short of 8 because it swaps Rollup/esbuild for Rolldown/Oxc, a bigger change for an es2015 target.
  • vite-plugin-static-copy 1 → 4. v4 preserves source directory structure, so the image target needs rename: { stripBase: true }. Without it, the logo lands at images/explorer/src/images/logo.png and breaks on every page.
  • sass ~1.69 → ^1.105. Bootstrap 5's own Sass triggers Dart Sass deprecation warnings that can't be fixed until Bootstrap 6, so they're silenced in vite.config.mjs.
  • Removed vite-plugin-copy, which was unused.
  • Node 20.15.1 → 22 in .nvmrc (CI and PyPI publish), the Dockerfile and entrypoint.sh. Vite 7 and static-copy 4 require it, and Node 20 is end-of-life.

Remaining finding: braces via chokidar. It affects every version and has no fix. It's only reached by static-copy's dev-mode file watcher with our fixed glob patterns.

Testing

  • Build: same 15 output files with similar sizes, and no warnings except the existing chunk-size notice.
  • Browser check: headless Chrome against the built assets (VITE_DEV_MODE=False). Query list, query view, query with results, playground, new query, logs and connections all load with no console errors and no failed requests. CodeMirror and the schema iframe render, and the images load.
  • Assistant sanitizing: I mocked an /assistant/ response containing markdown plus <script>, onerror and a javascript: link. The markdown renders (heading, bold, code block), all three payloads are stripped, and nothing executes.
  • Not tested: the Docker image build, because Docker wasn't running locally.

🤖 Generated with Claude Code

chrisclark and others added 2 commits October 5, 2026 12:54
- npm audit fix: DOMPurify 3.1.3 -> 3.4.16 (XSS advisories; it sanitizes AI
  Assistant output in the browser bundle), plus nanoid, immutable, postcss,
  rollup and others.
- Vite 5 -> 7, vite-plugin-static-copy 1 -> 4, sass ~1.69 -> ^1.105; removed
  unused vite-plugin-copy.
- vite-plugin-static-copy 4 preserves directory structure, so copied images
  need rename.stripBase to stay at images/<file>.
- Silence Bootstrap 5's Sass deprecation warnings (can't migrate until
  Bootstrap 6).
- Node 20.15.1 -> 22 (.nvmrc, Dockerfile, entrypoint.sh): Vite 7 and
  static-copy 4 need it, and Node 20 is end-of-life.

Remaining audit finding: braces (all versions, no fix) via chokidar, used by
vite-plugin-static-copy's dev-mode watcher with fixed globs.

Co-Authored-By: Claude <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant