Skip to content

Conversation

@scottschreckengaust
Copy link
Member

Fixes CVE-2025-23166

Summary

Playwright updated node version.

From syft and grype analysis:

NAME    INSTALLED  FIXED IN                           TYPE    VULNERABILITY        SEVERITY  EPSS           RISK   
node    22.14.0    20.19.2, 22.15.1, 23.11.1, 24.0.2  binary  CVE-2025-23166       High      < 0.1% (12th)  < 0.1  
node    22.14.0    20.19.2, 22.15.1                   binary  CVE-2025-23165       Low       < 0.1% (22nd)  < 0.1  

Changes

% uv lock --upgrade-package configargparse
Resolved 154 packages in 142ms
Updated configargparse v1.7 -> v1.7.1
% uv lock --upgrade-package playwright
Resolved 154 packages in 82ms
Updated playwright v1.52.0 -> v1.57.0

Node updated to >=22.15.1

Please provide a summary of what's being changed

User experience

Please share what the user experience looks like before and after this change

Checklist

If your change doesn't seem to apply, please leave them unchecked.

  • I have reviewed the contributing guidelines
  • I have performed a self-review of this change
  • Changes have been tested
  • Changes are documented

Is this a breaking change? (Y/N)

RFC issue number:

Checklist:

  • Migration process documented
  • Implement warnings (if it can live side by side)

Acknowledgment

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of the project license.

Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
@scottschreckengaust scottschreckengaust requested review from a team as code owners January 13, 2026 21:22
@scottschreckengaust scottschreckengaust added dependencies Pull requests that update a dependency file or issues from dependenices 👮admin👮 Looking for admin help to unblock ready-for-merge Folks believe this is ready to merge labels Jan 13, 2026
@codecov
Copy link

codecov bot commented Jan 13, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.60%. Comparing base (4a07e72) to head (4202c7b).
⚠️ Report is 54 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2162      +/-   ##
==========================================
+ Coverage   90.58%   90.60%   +0.01%     
==========================================
  Files         921      918       -3     
  Lines       64789    64319     -470     
  Branches    10419    10341      -78     
==========================================
- Hits        58692    58277     -415     
+ Misses       3769     3760       -9     
+ Partials     2328     2282      -46     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: Scott Schreckengaust <scottschreckengaust@users.noreply.github.com>
@github-actions
Copy link
Contributor

This pull request is now marked as stale because it hasn't seen activity for a while. Add a comment or it will be closed soon. If you wish to exclude this issue from being marked as stale, add the "backlog" label.

@github-actions github-actions bot added stale These are items that have been around for a long time without progress and removed stale These are items that have been around for a long time without progress labels Jan 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

👮admin👮 Looking for admin help to unblock dependencies Pull requests that update a dependency file or issues from dependenices ready-for-merge Folks believe this is ready to merge

Projects

Status: To triage

Development

Successfully merging this pull request may close these issues.

1 participant