Skip to content

fix(deps): resolve three new transitive security advisories - #106

Merged
finalerock44 merged 1 commit into
devfrom
chore/audit-fix-transitive-advisories
Aug 5, 2026
Merged

fix(deps): resolve three new transitive security advisories#106
finalerock44 merged 1 commit into
devfrom
chore/audit-fix-transitive-advisories

Conversation

@finalerock44

@finalerock44 finalerock44 commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

pnpm audit --audit-level moderate started failing CI on every branch, including a clean dev - these advisories were published after dev's last green run, so nothing in the tree had to change to break it.

  • brace-expansion: the existing override pinned 5.0.8, which GHSA-rgw5-rvv9-x895 now covers (vulnerable <5.0.9). Range and target bumped to 5.0.9.
  • fast-uri (via @modelcontextprotocol/sdk > ajv): GHSA-7p8r-x3mc-p8w7, pinned 3.1.5.
  • hono (via @modelcontextprotocol/sdk): GHSA-8j4g-w8fx-2239, pinned 4.12.34.

All three pinned to the lowest patched version within their current major, following the existing exact-pin overrides. A first pass using open '>=' ranges pulled fast-uri 4.1.2 - a major jump inside ajv - for no benefit; these land on 3.1.5 and 4.12.34 instead.

audit clean; lint, typecheck, build and all 194 tests pass. fast-uri and hono are both MCP SDK dependencies, so also smoke-tested dist/mcp/index.js over stdio: initialize and tools/list both return, all five tools registered.

What & why

Type of change

  • fix — bug fix
  • feat — new feature
  • perf — performance improvement
  • refactor — code change that's neither a fix nor a feature
  • docs — documentation only
  • chore / ci / build / test — tooling, no user-facing change
  • Breaking change (title has ! or PR notes a BREAKING CHANGE:)

Checklist

  • PR title follows the Conventional Commits format (see comment above)
  • pnpm lint passes
  • pnpm typecheck passes
  • pnpm build passes
  • I have not bumped the version or edited CHANGELOG.md (release-please handles this)
  • I have signed the CLA (the bot will prompt on first contribution)
  • Docs / README.md / STYLE_GUIDE.md updated if behaviour or output changed

How to test


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

pnpm audit --audit-level moderate started failing CI on every branch, including
a clean dev - these advisories were published after dev's last green run, so
nothing in the tree had to change to break it.

- brace-expansion: the existing override pinned 5.0.8, which GHSA-rgw5-rvv9-x895
  now covers (vulnerable <5.0.9). Range and target bumped to 5.0.9.
- fast-uri (via @modelcontextprotocol/sdk > ajv): GHSA-7p8r-x3mc-p8w7, pinned 3.1.5.
- hono (via @modelcontextprotocol/sdk): GHSA-8j4g-w8fx-2239, pinned 4.12.34.

All three pinned to the lowest patched version within their current major,
following the existing exact-pin overrides. A first pass using open '>=' ranges
pulled fast-uri 4.1.2 - a major jump inside ajv - for no benefit; these land on
3.1.5 and 4.12.34 instead.

audit clean; lint, typecheck, build and all 194 tests pass. fast-uri and hono
are both MCP SDK dependencies, so also smoke-tested dist/mcp/index.js over
stdio: initialize and tools/list both return, all five tools registered.
@finalerock44 finalerock44 self-assigned this Aug 5, 2026
@claude

claude Bot commented Aug 5, 2026

Copy link
Copy Markdown

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

@finalerock44
finalerock44 merged commit f7934b0 into dev Aug 5, 2026
12 checks passed
@finalerock44
finalerock44 deleted the chore/audit-fix-transitive-advisories branch August 5, 2026 09:32
@finalerock44 finalerock44 mentioned this pull request Aug 6, 2026
14 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant