refactor: Bump puppeteer from 24.37.2 to 24.43.1 - #3476
Conversation
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 5 remain after this review. 📝 WalkthroughWalkthroughThe Puppeteer development dependency changes from 24.37.2 to 24.43.1. The lockfile updates Puppeteer’s browser, protocol, query-selector, and transitive dependencies. ChangesPuppeteer dependency update
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Merge Risk: ⚪ Minimal · up to The dependency update is mergeable after normal checks; the supplied evidence shows the intended patched ws versions in the lockfile. 🚥 Pre-merge checks | ✅ 7✅ Passed checks (7 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Pull Request
Issue
Resolves the
wssecurity advisory GHSA-96hv-2xvq-fx4p / CVE-2026-48779 (high, memory exhaustion DoS from tiny fragments and data chunks; vulnerable>=8.0.0 <8.21.0, fixed in 8.21.0) for the development dependency tree (Dependabot alert 362).Approach
puppeteer-core24.37.2 pinswsexactly to 8.19.0, so the nestednode_modules/puppeteer-core/node_modules/ws@8.19.0copy can only be updated by upgradingpuppeteer.puppeteer-core24.43.1 depends onws ^8.20.0, so it now dedupes to the existing top-levelws8.21.0 and the nested vulnerable copy is removed.puppeteer(devDependency, exact pin): 24.37.2 → 24.43.1puppeteer-core: 24.37.2 → 24.43.1,@puppeteer/browsers2.12.0 → 2.13.2,chromium-bidi13.1.1 → 14.0.0,devtools-protocol0.0.1566079 → 0.0.1608973, plus transitive updates in the@puppeteer/browserssubtree (tar-fs,tar-stream,streamx,bare-*,netmask)All changed packages are development-only.
puppeteer24.43.1 requires Node>=18, which covers the CI matrix andengines.node.Changes
.catchon CDP target initializationPage.hasDevTools; Chrome 146 / Firefox 148 patch rollsPUPPETEER_DANGEROUS_NO_SANDBOXenvironment variableTarget.asPagereturns the samePageinstancelocator.fillsupports checkboxes and radiosnetworkidleoptions frompage.setContent(fix: remove networkidle options from setContent puppeteer/puppeteer#14940); BiDi URL restriction fix;puppeteer-coredepends onws ^8.20.0Breaking Changes
None. The upgrade is a minor version bump. The
setContentchange in 24.43.1 does not affect this repository, which only usesnetworkidle2withpage.gotoandpage.reload.Code Changes Required
None. The upgrade is a drop-in replacement.
Tasks
No tasks apply; this PR only updates a development dependency.
Summary by CodeRabbit