Skip to content

refactor: Bump puppeteer from 24.37.2 to 24.43.1 - #3476

Merged
mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:refactor/puppeteer-24.43.1
Sep 26, 2026
Merged

mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:refactor/puppeteer-24.43.1

Conversation

@mtrezza

@mtrezza mtrezza commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Pull Request

Issue

Resolves the ws security advisory GHSA-96hv-2xvq-fx4p / CVE-2026-48779 (high, memory exhaustion DoS from tiny fragments and data chunks; vulnerable >=8.0.0 <8.21.0, fixed in 8.21.0) for the development dependency tree (Dependabot alert 362).

Approach

puppeteer-core 24.37.2 pins ws exactly to 8.19.0, so the nested node_modules/puppeteer-core/node_modules/ws@8.19.0 copy can only be updated by upgrading puppeteer. puppeteer-core 24.43.1 depends on ws ^8.20.0, so it now dedupes to the existing top-level ws 8.21.0 and the nested vulnerable copy is removed.

  • puppeteer (devDependency, exact pin): 24.37.2 → 24.43.1
  • puppeteer-core: 24.37.2 → 24.43.1, @puppeteer/browsers 2.12.0 → 2.13.2, chromium-bidi 13.1.1 → 14.0.0, devtools-protocol 0.0.1566079 → 0.0.1608973, plus transitive updates in the @puppeteer/browsers subtree (tar-fs, tar-stream, streamx, bare-*, netmask)

All changed packages are development-only. puppeteer 24.43.1 requires Node >=18, which covers the CI matrix and engines.node.

Changes

  • 24.37.3 – 24.37.5: Chrome 145 / Firefox 147 rolls; user data dir is no longer resolved if absolute; missing .catch on CDP target initialization
  • 24.38.0: Roll to Chrome 146 and Firefox 148; BiDi navigation disposal fix
  • 24.39.0 – 24.39.1: Exposes Page.hasDevTools; Chrome 146 / Firefox 148 patch rolls
  • 24.40.0: Supports the PUPPETEER_DANGEROUS_NO_SANDBOX environment variable
  • 24.41.0: Roll to Chrome 147 and Firefox 149; Issues, extension realms and WebMCP APIs; Target.asPage returns the same Page instance
  • 24.42.0: URL blocklist, extension metadata, CDP address autofill
  • 24.43.0: Roll to Chrome 148 and Firefox 150; allowlist support; locator.fill supports checkboxes and radios
  • 24.43.1: Removes the networkidle options from page.setContent (fix: remove networkidle options from setContent puppeteer/puppeteer#14940); BiDi URL restriction fix; puppeteer-core depends on ws ^8.20.0

Breaking Changes

None. The upgrade is a minor version bump. The setContent change in 24.43.1 does not affect this repository, which only uses networkidle2 with page.goto and page.reload.

Code Changes Required

None. The upgrade is a drop-in replacement.

Tasks

No tasks apply; this PR only updates a development dependency.

Summary by CodeRabbit

  • Chores
    • Updated Puppeteer and its supporting packages used by the project’s browser automation tooling. This maintenance update affects development tooling only; it does not add or remove app features or change behavior visible to end users. No user-facing changes are included in this update.

@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 4f9f7e84-1dbb-4860-970d-e2c46d6712d9

📥 Commits

Reviewing files that changed from the base of the PR and between f14a5d8 and 3f7b632.

📒 Files selected for processing (2)
  • package-lock.json
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 5 remain after this review.


📝 Walkthrough

Walkthrough

The Puppeteer development dependency changes from 24.37.2 to 24.43.1. The lockfile updates Puppeteer’s browser, protocol, query-selector, and transitive dependencies.

Changes

Puppeteer dependency update

Layer / File(s) Summary
Puppeteer version and dependency graph
package.json, package-lock.json
The development dependency and locked Puppeteer packages update to 24.43.1. The lockfile also updates related browser, protocol, query-selector, and transitive package entries.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Merge Risk: ⚪ Minimal · up to 3f7b6

The dependency update is mergeable after normal checks; the supplied evidence shows the intended patched ws versions in the lockfile.

🚥 Pre-merge checks | ✅ 7
✅ Passed checks (7 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Security Check ✅ Passed No security vulnerability is introduced by the reviewed changes. The PR only updates development dependencies and lockfile records. The vulnerable nested ws@8.19.0 is removed, and puppeteer-core n…
Engage In Review Feedback ✅ Passed No review feedback comments or actionable findings are present. Therefore, the pull request did not ignore or resolve feedback without discussion.
Title check ✅ Passed The title begins with the allowed refactor: prefix and clearly describes the Puppeteer version upgrade. The first word after the prefix is capitalized.
Description check ✅ Passed The description includes the required Pull Request, Issue, Approach, and Tasks sections. It clearly explains the security issue, dependency changes, compatibility, and testing or documentation task st…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@mtrezza
mtrezza merged commit c23655a into parse-community:alpha Sep 26, 2026
11 checks passed
@mtrezza
mtrezza deleted the refactor/puppeteer-24.43.1 branch September 26, 2026 01:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant