fix: resolve dependency audit findings - #192
rajat1saxena wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7b25027ee9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "picomatch@>=4.0.0 <5.0.0": "4.0.4", | ||
| "yaml@>=2.0.0 <3.0.0": "2.8.3", | ||
| "path-to-regexp@>=8.0.0 <9.0.0": "8.4.0", | ||
| "lodash@>=4.0.0 <5.0.0": "4.18.0", |
There was a problem hiding this comment.
Avoid forcing the withdrawn Lodash release
The lockfile emitted by this change labels lodash@4.18.0 as a “Bad release” and explicitly directs consumers to use 4.17.21 instead. Because this selector matches every Lodash v4 dependency, every clean install will receive that known-bad package; it already replaces the Lodash used by joi-to-swagger, which the API runs for Swagger generation during both builds and development. Keep 4.17.21 or use a non-withdrawn fixed release rather than pinning this version globally.
Useful? React with 👍 / 👎.
Non-breaking audit follow-up for hono/jsx unescaped string advisory. Remaining findings still require major bumps (nodemailer 7+, uuid 11+, etc.). Verified: pnpm install --frozen-lockfile, lint, prettier, build, test
Audit follow-up (2026-10-01 IST)Additional non-breaking fix pushed to this branch:
Audit counts on this branch: 30 → 29 (5 low / 18 moderate / 6 high) Remaining still need majors (nodemailer 7+, uuid 11+, braces/micromatch majors, tmp 0.x, etc.). Verified: |
|
Closing to reopen under the Codelit bot account (clbotdev). |
Summary
Non-breaking dependency audit remediation for the pnpm monorepo. Direct dependencies were bumped within existing semver ranges (or same major for exact pins), and
pnpm.overrideswere added only for same-major transitive patches. Breaking major bumps were intentionally not applied.Audit severity counts
(Unique advisories: 206 → 28.)
Packages changed (direct)
next:^15.5.7→^15.5.24(apps/web);16.2.0→16.3.6(apps/docs);15.5.7→15.5.24(examples/next-app-router)mongoose:^8.19.3→^8.24.1(apps/api,apps/web,packages/models,packages/scripts)joi:^17.6.0→^17.13.7(apps/api)form-data:^4.0.0→^4.0.6(packages/medialit)nanoid:^3.3.2→^3.3.18(packages/utils,.migrations)Root
package.jsonalso addspnpm.overridespinning same-major patched versions for transitive deps (e.g.brace-expansion,js-yaml,postcss,hono,lodash,minimatch,qs,flatted,rollup,fast-xml-parser, and others). Lockfile regenerated withpnpm install(verified withpnpm install --frozen-lockfile).Remaining findings (require breaking bumps — not applied)
^6.10.0; patches start at 7.x+Verification
pnpm install --frozen-lockfile✅pnpm lint✅pnpm prettier✅pnpm -r build✅pnpm test✅ (Node 22, matching CI)