[Snyk] Fix for 2 vulnerabilities - #4
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-IOREDIS-19963957 - https://snyk.io/vuln/SNYK-JS-BUN-15123966
|
The upgrade of ioredis from 5.8.1 to 6.0.0 is a major version change with significant breaking changes, while the bun upgrade is a minor patch. ioredis 5.8.1 → 6.0.0 (High Risk)This major upgrade introduces several breaking changes that require developer action and environment verification. Key Breaking Changes:
Recommendation: Source: ioredis v6.0.0 Release Notes bun 1.3.0 → 1.3.5 (Low Risk)This is a patch upgrade that includes new features, performance improvements, and bug fixes. No breaking changes are documented for this range. Source: Bun Release Notes
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e6d92b418a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "license": "MIT", | ||
| "dependencies": { | ||
| "ioredis": "^5.8.1", | ||
| "ioredis": "^6.0.0", |
There was a problem hiding this comment.
Regenerate bun.lock for the ioredis upgrade
This updates only the npm lockfile while the repository's Bun lockfile still declares and resolves ioredis as ^5.8.1/5.8.1 (bun.lock:7,443). The build and test scripts use Bun, so any environment using bun install --frozen-lockfile—which disallows lockfile changes—cannot install this manifest without first rewriting bun.lock for ^6.0.0. Commit the corresponding Bun lockfile update so Bun-based CI and development installs remain reproducible.
Useful? React with 👍 / 👎.
| "license": "MIT", | ||
| "dependencies": { | ||
| "ioredis": "^5.8.1", | ||
| "ioredis": "^6.0.0", |
There was a problem hiding this comment.
Preserve the declared Node 18 support
The package still advertises Node >=18.0.0 (package.json:137-140), but the newly locked ioredis@6.0.0 declares node >=20.0.0 (package-lock.json:2724-2739). Consequently, supported Node 18 consumers using engine-strict cannot install this package, and non-strict installs receive an unsupported Redis client. Keep a patched 5.x ioredis release if it satisfies the security fix, or raise the package's Node engine requirement alongside this major upgrade.
Useful? React with 👍 / 👎.
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-IOREDIS-19963957
SNYK-JS-BUN-15123966
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Uncontrolled Recursion