Skip to content

fix: resolve dependency audit findings - #192

Closed
rajat1saxena wants to merge 2 commits into
mainfrom
audit-fix
Closed

rajat1saxena wants to merge 2 commits into
mainfrom
audit-fix

Conversation

@rajat1saxena

Copy link
Copy Markdown
Member

Summary

Non-breaking dependency audit remediation for the pnpm monorepo. Direct dependencies were bumped within existing semver ranges (or same major for exact pins), and pnpm.overrides were added only for same-major transitive patches. Breaking major bumps were intentionally not applied.

Audit severity counts

Severity Before After
critical 10 0
high 111 6
moderate 107 18
low 24 5
total 252 29

(Unique advisories: 206 → 28.)

Packages changed (direct)

  • next: ^15.5.7 → ^15.5.24 (apps/web); 16.2.0 → 16.3.6 (apps/docs); 15.5.7 → 15.5.24 (examples/next-app-router)
  • mongoose: ^8.19.3 → ^8.24.1 (apps/api, apps/web, packages/models, packages/scripts)
  • joi: ^17.6.0 → ^17.13.7 (apps/api)
  • form-data: ^4.0.0 → ^4.0.6 (packages/medialit)
  • nanoid: ^3.3.2 → ^3.3.18 (packages/utils, .migrations)

Root package.json also adds pnpm.overrides pinning same-major patched versions for transitive deps (e.g. brace-expansion, js-yaml, postcss, hono, lodash, minimatch, qs, flatted, rollup, fast-xml-parser, and others). Lockfile regenerated with pnpm install (verified with pnpm install --frozen-lockfile).

Remaining findings (require breaking bumps — not applied)

Package Severity Notes
nodemailer high/moderate/low Direct dep ^6.10.0; patches start at 7.x+
uuid moderate Locked on 3.x/8.x; patch requires 11.x
braces / micromatch high/moderate Older 2.x/3.x lines need major bump
tmp / srvx / esbuild / decode-uri-component / @eslint/plugin-kit various 0.x minor bumps treated as breaking
node-notifier / tough-cookie moderate Major bumps
request / aws-sdk moderate/low Unmaintained / no patch

Verification

  • pnpm install --frozen-lockfile ✅
  • pnpm lint ✅
  • pnpm prettier ✅
  • pnpm -r build ✅
  • pnpm test ✅ (Node 22, matching CI)

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7b25027ee9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
"picomatch@>=4.0.0 <5.0.0": "4.0.4",
"yaml@>=2.0.0 <3.0.0": "2.8.3",
"path-to-regexp@>=8.0.0 <9.0.0": "8.4.0",
"lodash@>=4.0.0 <5.0.0": "4.18.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Avoid forcing the withdrawn Lodash release

The lockfile emitted by this change labels lodash@4.18.0 as a “Bad release” and explicitly directs consumers to use 4.17.21 instead. Because this selector matches every Lodash v4 dependency, every clean install will receive that known-bad package; it already replaces the Lodash used by joi-to-swagger, which the API runs for Swagger generation during both builds and development. Keep 4.17.21 or use a non-withdrawn fixed release rather than pinning this version globally.

Useful? React with 👍 / 👎.

Non-breaking audit follow-up for hono/jsx unescaped string advisory.
Remaining findings still require major bumps (nodemailer 7+, uuid 11+, etc.).
Verified: pnpm install --frozen-lockfile, lint, prettier, build, test
@rajat1saxena

Copy link
Copy Markdown
Member Author

Audit follow-up (2026-10-01 IST)

Additional non-breaking fix pushed to this branch:

Package Change Notes
hono (pnpm.overrides) 4.13.5 → 4.13.7 same major; clears hono/jsx unescaped-string advisory

Audit counts on this branch: 30 → 29 (5 low / 18 moderate / 6 high)

Remaining still need majors (nodemailer 7+, uuid 11+, braces/micromatch majors, tmp 0.x, etc.).

Verified: pnpm install --frozen-lockfile, lint, prettier, pnpm -r build, pnpm test (all green).

@rajat1saxena

Copy link
Copy Markdown
Member Author

Closing to reopen under the Codelit bot account (clbotdev).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant