Skip to content

[Snyk] Fix for 2 vulnerabilities - #4

Merged
ElectronSz merged 1 commit into
mainfrom
snyk-fix-2a769eae4bb9ae7c24d80a4860922302
Sep 22, 2026
Merged

ElectronSz merged 1 commit into
mainfrom
snyk-fix-2a769eae4bb9ae7c24d80a4860922302

Conversation

@ElectronSz

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Uncontrolled Recursion
SNYK-JS-IOREDIS-19963957
  721  
medium severity Use of Less Trusted Source
SNYK-JS-BUN-15123966
  559  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled Recursion

@ElectronSz

Copy link
Copy Markdown
Owner Author

Merge Risk: High

The upgrade of ioredis from 5.8.1 to 6.0.0 is a major version change with significant breaking changes, while the bun upgrade is a minor patch.

ioredis 5.8.1 → 6.0.0 (High Risk)

This major upgrade introduces several breaking changes that require developer action and environment verification.

Key Breaking Changes:

  • Node.js Requirement: Support for Node.js versions older than 20.x has been dropped.
  • Default Redis Protocol: The client now uses the RESP3 protocol by default. This is a fundamental change in communication with the Redis server. If your Redis server or any proxy in between does not support RESP3, you must explicitly set protocol: 2 in the client configuration to maintain the v5 behavior.
  • Constructor Change: The Redis client must now be instantiated as a class (new Redis()). The previous function-style invocation (Redis()) is no longer supported.
  • Promise Implementation: Support for third-party promise libraries has been removed. The client now exclusively uses native Promises.

Recommendation:
Before merging, verify that your production environment runs on Node.js 20 or newer. Review your Redis infrastructure's compatibility with the RESP3 protocol and update your ioredis instantiation to use the new Redis() constructor. Add protocol: 2 to your configuration if you need to maintain the older RESP2 protocol.

Source: ioredis v6.0.0 Release Notes

bun 1.3.0 → 1.3.5 (Low Risk)

This is a patch upgrade that includes new features, performance improvements, and bug fixes. No breaking changes are documented for this range.

Source: Bun Release Notes

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@ElectronSz
ElectronSz merged commit 6c04cd1 into main Sep 22, 2026
2 of 3 checks passed
@ElectronSz
ElectronSz deleted the snyk-fix-2a769eae4bb9ae7c24d80a4860922302 branch September 22, 2026 16:27

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6d92b418a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
"license": "MIT",
"dependencies": {
"ioredis": "^5.8.1",
"ioredis": "^6.0.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate bun.lock for the ioredis upgrade

This updates only the npm lockfile while the repository's Bun lockfile still declares and resolves ioredis as ^5.8.1/5.8.1 (bun.lock:7,443). The build and test scripts use Bun, so any environment using bun install --frozen-lockfile—which disallows lockfile changes—cannot install this manifest without first rewriting bun.lock for ^6.0.0. Commit the corresponding Bun lockfile update so Bun-based CI and development installs remain reproducible.

Useful? React with 👍 / 👎.

Comment thread package.json
"license": "MIT",
"dependencies": {
"ioredis": "^5.8.1",
"ioredis": "^6.0.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the declared Node 18 support

The package still advertises Node >=18.0.0 (package.json:137-140), but the newly locked ioredis@6.0.0 declares node >=20.0.0 (package-lock.json:2724-2739). Consequently, supported Node 18 consumers using engine-strict cannot install this package, and non-strict installs receive an unsupported Redis client. Keep a patched 5.x ioredis release if it satisfies the security fix, or raise the package's Node engine requirement alongside this major upgrade.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants