Dependabot’s npm_and_yarn security job was failing with security_update_not_possible because the dependency graph was locked to dompurify@3.4.8 through @monaco-editor/react -> monaco-editor@0.56.0. Since the security advisory requires dompurify >= 3.4.13, the updater could not produce a valid remediation PR.
Root cause
@monaco-editor/react introduced a transitive path to monaco-editor@0.56.0, which pins vulnerable dompurify@3.4.8.
That pin blocked Dependabot from resolving to a non-vulnerable dompurify version.
Change made
Removed @monaco-editor/react from package.json (unused in src/).
Regenerated package-lock.json to remove the monaco-editor subtree and its pinned dompurify@3.4.8.
Dependabot’s `npm_and_yarn` security job was failing with `security_update_not_possible` because the dependency graph was locked to `dompurify@3.4.8` through `@monaco-editor/react -> monaco-editor@0.56.0`. Since the security advisory requires `dompurify >= 3.4.13`, the updater could not produce a valid remediation PR.
- **Root cause**
- `@monaco-editor/react` introduced a transitive path to `monaco-editor@0.56.0`, which pins vulnerable `dompurify@3.4.8`.
- That pin blocked Dependabot from resolving to a non-vulnerable `dompurify` version.
- **Change made**
- Removed `@monaco-editor/react` from `package.json` (unused in `src/`).
- Regenerated `package-lock.json` to remove the `monaco-editor` subtree and its pinned `dompurify@3.4.8`.
- **Resulting dependency-shape change**
```json
// package.json (dependencies)
{
"dependencies": {
// removed:
// "@monaco-editor/react": "^4.6.0"
}
}
```
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Dependabot’s
npm_and_yarnsecurity job was failing withsecurity_update_not_possiblebecause the dependency graph was locked todompurify@3.4.8through@monaco-editor/react -> monaco-editor@0.56.0. Since the security advisory requiresdompurify >= 3.4.13, the updater could not produce a valid remediation PR.Root cause
@monaco-editor/reactintroduced a transitive path tomonaco-editor@0.56.0, which pins vulnerabledompurify@3.4.8.dompurifyversion.Change made
@monaco-editor/reactfrompackage.json(unused insrc/).package-lock.jsonto remove themonaco-editorsubtree and its pinneddompurify@3.4.8.Resulting dependency-shape change