Skip to content

Security#139

Merged
EthanThePhoenix38 merged 17 commits intomainfrom
security
Feb 24, 2026
Merged

Security#139
EthanThePhoenix38 merged 17 commits intomainfrom
security

Conversation

@EthanThePhoenix38
Copy link
Member

@EthanThePhoenix38 EthanThePhoenix38 commented Feb 24, 2026


Continue Tasks: ▶️ 1 queued — View all

dependabot bot and others added 17 commits February 23, 2026 06:27
Bumps [@csstools/color-helpers](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/color-helpers) from 6.0.1 to 6.0.2.
- [Changelog](https://github.com/csstools/postcss-plugins/blob/main/packages/color-helpers/CHANGELOG.md)
- [Commits](https://github.com/csstools/postcss-plugins/commits/HEAD/packages/color-helpers)

---
updated-dependencies:
- dependency-name: "@csstools/color-helpers"
  dependency-version: 6.0.2
  dependency-type: indirect
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@octokit/request](https://github.com/octokit/request.js) from 10.0.7 to 10.0.8.
- [Release notes](https://github.com/octokit/request.js/releases)
- [Commits](octokit/request.js@v10.0.7...v10.0.8)

---
updated-dependencies:
- dependency-name: "@octokit/request"
  dependency-version: 10.0.8
  dependency-type: indirect
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@csstools/css-color-parser](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-color-parser) from 4.0.1 to 4.0.2.
- [Changelog](https://github.com/csstools/postcss-plugins/blob/main/packages/css-color-parser/CHANGELOG.md)
- [Commits](https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-color-parser)

---
updated-dependencies:
- dependency-name: "@csstools/css-color-parser"
  dependency-version: 4.0.2
  dependency-type: indirect
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [isomorphic-dompurify](https://github.com/kkomelin/isomorphic-dompurify) from 2.35.0 to 3.0.0.
- [Release notes](https://github.com/kkomelin/isomorphic-dompurify/releases)
- [Commits](kkomelin/isomorphic-dompurify@2.35.0...3.0.0)

---
updated-dependencies:
- dependency-name: isomorphic-dompurify
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…/csstools/css-color-parser-4.0.2' into security
Bumps [@csstools/css-syntax-patches-for-csstree](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-syntax-patches-for-csstree) from 1.0.27 to 1.0.28.
- [Changelog](https://github.com/csstools/postcss-plugins/blob/main/packages/css-syntax-patches-for-csstree/CHANGELOG.md)
- [Commits](https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-syntax-patches-for-csstree)

---
updated-dependencies:
- dependency-name: "@csstools/css-syntax-patches-for-csstree"
  dependency-version: 1.0.28
  dependency-type: indirect
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [whatwg-url](https://github.com/jsdom/whatwg-url) from 16.0.0 to 16.0.1.
- [Release notes](https://github.com/jsdom/whatwg-url/releases)
- [Commits](jsdom/whatwg-url@v16.0.0...v16.0.1)

---
updated-dependencies:
- dependency-name: whatwg-url
  dependency-version: 16.0.1
  dependency-type: indirect
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [openai](https://github.com/openai/openai-node) from 6.19.0 to 6.24.0.
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/master/CHANGELOG.md)
- [Commits](openai/openai-node@v6.19.0...v6.24.0)

---
updated-dependencies:
- dependency-name: openai
  dependency-version: 6.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
….27 to 1.0.28 (#135)

Bumps
[@csstools/css-syntax-patches-for-csstree](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-syntax-patches-for-csstree)
from 1.0.27 to 1.0.28.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/csstools/postcss-plugins/blob/main/packages/css-syntax-patches-for-csstree/CHANGELOG.md"><code>@​csstools/css-syntax-patches-for-csstree</code>'s
changelog</a>.</em></p>
<blockquote>
<h3>1.0.28</h3>
<p><em>February 21, 2026</em></p>
<ul>
<li>Update <code>@webref/css</code> to <a
href="https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.2.5"><code>v8.2.5</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-syntax-patches-for-csstree">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@csstools/css-syntax-patches-for-csstree&package-manager=npm_and_yarn&previous-version=1.0.27&new-version=1.0.28)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

---

<!-- continue-task-summary-start -->
**Continue Tasks:** ▶️ 1 queued — [View
all](https://hub.continue.dev/inbox/pr/ThePhoenixAgency/AI-Pulse/135?utm_source=github_pr&utm_medium=pr_body&utm_campaign=continue_tasks)
<!-- continue-task-summary-end -->
@EthanThePhoenix38 EthanThePhoenix38 marked this pull request as ready for review February 24, 2026 18:22
Copilot AI review requested due to automatic review settings February 24, 2026 18:22
@github-actions github-actions bot added documentation Improvements or additions to documentation configuration dependencies labels Feb 24, 2026
@EthanThePhoenix38 EthanThePhoenix38 merged commit 2fd967b into main Feb 24, 2026
10 checks passed
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates security-related dependencies through the automated DependabotSecureFlow process. It upgrades isomorphic-dompurify from v2.35.0 to v3.0.0 and openai from v6.19.0 to v6.24.0, along with their transitive dependencies.

Changes:

  • Updated isomorphic-dompurify to v3.0.0, simplifying the dependency tree by reusing the project's existing jsdom v28.0.0 instead of bundling v27.4.0
  • Updated openai to v6.24.0 with new transitive dependency json-with-bigint v3.5.3
  • Added automated security batch update entries to CHANGELOG.md (though incorrectly added to released version sections)

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 4 comments.

File Description
package.json Updated isomorphic-dompurify to ^3.0.0 and openai to ^6.24.0
package-lock.json Updated dependency versions with simplified tree for isomorphic-dompurify, added json-with-bigint, removed ws duplication
CHANGELOG.md Added automated security batch update entries (incorrectly added to all version sections due to workflow bug)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +58 to +62
- **2026-02-24 06:18 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-24 06:16 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:30 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:29 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:28 UTC**: Automated Security Batch Update (DependabotSecureFlow)
Copy link

Copilot AI Feb 24, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Released version sections in CHANGELOG.md must remain immutable according to Keep a Changelog format. These automated security batch update entries (dated 2026-02-23 and 2026-02-24) should only be added to the [Unreleased] section (lines 10-14), not to the released [1.1.0] version section dated 2026-01-31. This is caused by the sed command in the DependabotSecureFlow workflow matching all "### Added" occurrences instead of only the first one under [Unreleased].

Copilot uses AI. Check for mistakes.
Comment on lines +100 to +104
- **2026-02-24 06:18 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-24 06:16 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:30 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:29 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:28 UTC**: Automated Security Batch Update (DependabotSecureFlow)
Copy link

Copilot AI Feb 24, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Released version sections in CHANGELOG.md must remain immutable according to Keep a Changelog format. These automated security batch update entries (dated 2026-02-23 and 2026-02-24) should only be added to the [Unreleased] section (lines 10-14), not to the released [1.2.0] version section dated 2026-02-01. This is caused by the sed command in the DependabotSecureFlow workflow matching all "### Added" occurrences instead of only the first one under [Unreleased].

Copilot uses AI. Check for mistakes.
Comment on lines +155 to +159
- **2026-02-24 06:18 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-24 06:16 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:30 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:29 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:28 UTC**: Automated Security Batch Update (DependabotSecureFlow)
Copy link

Copilot AI Feb 24, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Released version sections in CHANGELOG.md must remain immutable according to Keep a Changelog format. These automated security batch update entries (dated 2026-02-23 and 2026-02-24) should only be added to the [Unreleased] section (lines 10-14), not to the released [1.0.0] version section dated 2025-12-10. This is caused by the sed command in the DependabotSecureFlow workflow matching all "### Added" occurrences instead of only the first one under [Unreleased].

Copilot uses AI. Check for mistakes.
Comment on lines +203 to +207
- **2026-02-24 06:18 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-24 06:16 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:30 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:29 UTC**: Automated Security Batch Update (DependabotSecureFlow)
- **2026-02-23 06:28 UTC**: Automated Security Batch Update (DependabotSecureFlow)
Copy link

Copilot AI Feb 24, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This section appears to be a duplicate [Unreleased] section dated 2026-02-16 (line 201), which is inconsistent with the changelog structure. The automated security batch update entries (dated 2026-02-23 and 2026-02-24) are being added here as well due to the sed command matching all "### Added" occurrences. This section should likely be removed or renamed to avoid confusion.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

configuration dependencies documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants