Skip to content

fix: resolve dependency audit findings - #193

Open
clbotdev wants to merge 6 commits into
mainfrom
audit-fix
Open

clbotdev wants to merge 6 commits into
mainfrom
audit-fix

Conversation

@clbotdev

@clbotdev clbotdev commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Non-breaking dependency audit remediation for the pnpm monorepo. Direct dependencies were bumped within existing semver ranges (or same major for exact pins), and pnpm.overrides were added only for same-major transitive patches. Breaking major bumps were intentionally not applied.

Reopened under the Codelit bot account (clbotdev). Supersedes #192.

Audit severity counts

Severity Before After
critical 10 0
high 111 6
moderate 107 18
low 24 5
total 252 29

(Unique advisories: 206 → 28.)

Packages changed (direct)

  • next: ^15.5.7 → ^15.5.24 (apps/web); 16.2.0 → 16.3.6 (apps/docs); 15.5.7 → 15.5.24 (examples/next-app-router)
  • mongoose: ^8.19.3 → ^8.24.1 (apps/api, apps/web, packages/models, packages/scripts)
  • joi: ^17.6.0 → ^17.13.7 (apps/api)
  • form-data: ^4.0.0 → ^4.0.6 (packages/medialit)
  • nanoid: ^3.3.2 → ^3.3.18 (packages/utils, .migrations)

Root package.json also adds pnpm.overrides pinning same-major patched versions for transitive deps. Lockfile regenerated with pnpm install (verified with pnpm install --frozen-lockfile).

Follow-up commits on this branch also apply a further non-breaking hono bump.

Remaining findings (require breaking bumps — not applied)

Package Severity Notes
nodemailer high/moderate/low Direct dep ^6.10.0; patches start at 7.x+
uuid moderate Locked on 3.x/8.x; patch requires 11.x
braces / micromatch high/moderate Older 2.x/3.x lines need major bump
tmp / srvx / esbuild / decode-uri-component / @eslint/plugin-kit various 0.x minor bumps treated as breaking
node-notifier / tough-cookie moderate Major bumps
request / aws-sdk moderate/low Unmaintained / no patch

Verification

  • pnpm install --frozen-lockfile ✅
  • pnpm lint ✅
  • pnpm prettier ✅
  • pnpm -r build ✅
  • pnpm test ✅ (Node 22, matching CI)

rajat1saxena and others added 5 commits October 1, 2026 01:24
Non-breaking audit follow-up for hono/jsx unescaped string advisory.
Remaining findings still require major bumps (nodemailer 7+, uuid 11+, etc.).
Verified: pnpm install --frozen-lockfile, lint, prettier, build, test
…kit)

- Override tmp → 0.2.7 (path traversal advisories)
- Bump @tus/server/@tus/file-store within ^2.x (pulls srvx ≥0.11.13)
- Bump eslint ^9.24 → ^9.39.5 and override @eslint/plugin-kit 0.2.x → 0.3.5

Leftovers still need majors / have no patch: nodemailer 7+/10+, uuid 11+,
aws-sdk v2→v3, jest24 chain (braces/micromatch/request/tough-cookie/
node-notifier/decode-uri-component), esbuild 0.27→0.28, braces ≤3.0.3 unpatched.

Verified: pnpm install --frozen-lockfile, lint, prettier, build, test
…css-selector-parser, joi, @modelcontextprotocol/sdk)
@clbotdev

clbotdev commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Heads-up: main moved from pnpm to bun, so this branch now merges main (taking main's side on every conflict, so the old pnpm lockfile and overrides are gone) and re-applies the audit fixes on bun: proxy-addr 2.0.8, source-map-js 1.2.2, postcss-selector-parser 7.1.6, joi 17.13.8 (overrides) and @modelcontextprotocol/sdk pinned 1.30.0 → 1.32.1. The diff against main is now just package.json, apps/api/package.json and bun.lock. bun install --frozen-lockfile, bun run lint, bun run prettier and bun run test all pass locally.

Addresses Next.js advisories requiring >=16.3.8 (SSRF in image
optimization, cache poisoning, draft-mode leak, metadata disclosure).
Pins direct deps and the root bun override within the same major.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants