Skip to content

fix: resolve dependency audit findings - #21

Open
clbotdev wants to merge 2 commits into
mainfrom
audit-fix-2026-10-07
Open

clbotdev wants to merge 2 commits into
mainfrom
audit-fix-2026-10-07

Conversation

@clbotdev

@clbotdev clbotdev commented Oct 7, 2026

Copy link
Copy Markdown

Automated dependency audit (pnpm audit), non-breaking fixes only.

Fixed

  • proxy-addr 2.0.7 → 2.0.8 (critical: IP spoofing via IPv4-mapped IPv6), via scoped override
  • source-map-js 1.2.1 → 1.2.2 (high: event-loop DoS), via scoped override
  • postcss-selector-parser 7.1.4 → 7.1.6 (moderate: quadratic parsing), 7.x only
  • @modelcontextprotocol/sdk 1.29.0 → 1.31+ (high: OAuth credential leak), via scoped override
  • @modelcontextprotocol/client ^2.0.0 → ^2.2.0 in apps/api (same advisory)

Audit went from 1 critical / 6 high / 7 moderate / 2 low to 0 critical / 3 high / 7 moderate / 2 low.

Not fixed (would need a major/0.x-minor bump or has no patched release)
nodemailer 9→10, esbuild 0.27→0.28 and older 0.1x copies, postcss-selector-parser 6.x (via tailwind 3), ts-deepmerge 6→8, tsup 6→8, braces 3.0.3 and sprintf-js 1.0.3 (no patched release published).

Checks (run locally the same way CI does, Node 24, pnpm 11.11.0)

  • pnpm install --frozen-lockfile: OK
  • pnpm lint, pnpm prettier: OK, no changes
  • package builds + pnpm test: all passing (api 410, web 50, email-editor 12, email-blocks 8)

…ector-parser, @modelcontextprotocol/sdk and client)
- Bump next ^16.3.7 → ^16.4.0 (clears Image Optimization SSRF and related advisories)
- Override esbuild@>=0.27.3 <0.28.1 → >=0.28.1 <0.29 (fumadocs-mdx Windows file-read)
- Bump @modelcontextprotocol/client ^2.2.0 → ^2.3.1
- Refresh minimumReleaseAgeExclude for audit-allowed patch versions

Left unresolved (need majors or unpublished patches): nodemailer 9→10, braces 3.0.4 (not on npm), sprintf-js 1.1.4 (not on npm), ts-deepmerge 6→8, tsup 6→8, postcss-selector-parser 6.x under tailwind 3, older esbuild via drizzle-kit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant