Skip to content

fix: resolve dependency audit findings - #193

Open
clbotdev wants to merge 3 commits into
mainfrom
audit-fix
Open

clbotdev wants to merge 3 commits into
mainfrom
audit-fix

Conversation

@clbotdev

@clbotdev clbotdev commented Oct 1, 2026

Copy link
Copy Markdown

Summary

Non-breaking dependency audit remediation for the pnpm monorepo. Direct dependencies were bumped within existing semver ranges (or same major for exact pins), and pnpm.overrides were added only for same-major transitive patches. Breaking major bumps were intentionally not applied.

Reopened under the Codelit bot account (clbotdev). Supersedes #192.

Audit severity counts

Severity Before After
critical 10 0
high 111 6
moderate 107 18
low 24 5
total 252 29

(Unique advisories: 206 → 28.)

Packages changed (direct)

  • next: ^15.5.7 → ^15.5.24 (apps/web); 16.2.0 → 16.3.6 (apps/docs); 15.5.7 → 15.5.24 (examples/next-app-router)
  • mongoose: ^8.19.3 → ^8.24.1 (apps/api, apps/web, packages/models, packages/scripts)
  • joi: ^17.6.0 → ^17.13.7 (apps/api)
  • form-data: ^4.0.0 → ^4.0.6 (packages/medialit)
  • nanoid: ^3.3.2 → ^3.3.18 (packages/utils, .migrations)

Root package.json also adds pnpm.overrides pinning same-major patched versions for transitive deps. Lockfile regenerated with pnpm install (verified with pnpm install --frozen-lockfile).

Follow-up commits on this branch also apply a further non-breaking hono bump.

Remaining findings (require breaking bumps — not applied)

Package Severity Notes
nodemailer high/moderate/low Direct dep ^6.10.0; patches start at 7.x+
uuid moderate Locked on 3.x/8.x; patch requires 11.x
braces / micromatch high/moderate Older 2.x/3.x lines need major bump
tmp / srvx / esbuild / decode-uri-component / @eslint/plugin-kit various 0.x minor bumps treated as breaking
node-notifier / tough-cookie moderate Major bumps
request / aws-sdk moderate/low Unmaintained / no patch

Verification

  • pnpm install --frozen-lockfile ✅
  • pnpm lint ✅
  • pnpm prettier ✅
  • pnpm -r build ✅
  • pnpm test ✅ (Node 22, matching CI)

rajat1saxena and others added 3 commits October 1, 2026 01:24
Non-breaking audit follow-up for hono/jsx unescaped string advisory.
Remaining findings still require major bumps (nodemailer 7+, uuid 11+, etc.).
Verified: pnpm install --frozen-lockfile, lint, prettier, build, test
…kit)

- Override tmp → 0.2.7 (path traversal advisories)
- Bump @tus/server/@tus/file-store within ^2.x (pulls srvx ≥0.11.13)
- Bump eslint ^9.24 → ^9.39.5 and override @eslint/plugin-kit 0.2.x → 0.3.5

Leftovers still need majors / have no patch: nodemailer 7+/10+, uuid 11+,
aws-sdk v2→v3, jest24 chain (braces/micromatch/request/tough-cookie/
node-notifier/decode-uri-component), esbuild 0.27→0.28, braces ≤3.0.3 unpatched.

Verified: pnpm install --frozen-lockfile, lint, prettier, build, test

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants