Skip to content

fix(deps): patch Next.js og RCE, clear audit findings, update dependencies - #212

Merged
Gautam25Raj merged 4 commits into
masterfrom
chore/deps-security-audit
Oct 4, 2026
Merged

Gautam25Raj merged 4 commits into
masterfrom
chore/deps-security-audit

Conversation

@Gautam25Raj

@Gautam25Raj Gautam25Raj commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

npm audit reported 21 vulnerabilities, including a critical RCE in next/og ImageResponse, which the site, blog, docs and portfolio OG image routes all use. This PR fixes everything with an upstream fix, updates dependencies within their current majors, and cleans up the root overrides.

Before After
Critical 1 0
High 14 5
Moderate 6 0

The 5 remaining findings are one chain, braces ← micromatch ← fast-glob@3.3.1 ← @next/eslint-plugin-next. It is only used by lint, never shipped, and has no patched version yet.

Commits

1. fix(deps): security

  • Next.js and eslint-config-next 16.3.5 → 16.3.8 (og RCE, image-optimizer SSRF, cache poisoning)
  • nodemailer 9 → 10.0.14: there is no patched 9.x. Our createTransport/sendMail usage is unchanged. @types/nodemailer is removed because v10 ships its own types.
  • express 4.22.3 (qs 6.16), multer 2.4.0, vitest 4.1.11, postcss 8.5.28 (nanoid 3.3.19)
  • Overrides that pinned vulnerable versions are fixed: fast-uri 3.1.8 (the old 3.1.7 pin had never applied to the locked tree) and body-parser 1.20.8
  • New overrides mysql2 3.24.5 and deepmerge-ts 8.0.2, both pinned vulnerable inside prisma 7.x

2. chore(deps): updates within current majors

  • Prisma 7.10.0, AWS SDK, react-pdf 4.9, docx 9.8.1, lucide-react, prettier 3.9.9, and others
  • better-auth is held at ~1.6.25: 1.7 requires a mandatory Account.issuer column and a backfill, so it needs its own migration PR
  • site now declares tsx. Its prebuild scripts use it, but it previously only worked through server's hoisted copy.

3. chore(deps): fumadocs pinning and override cleanup

  • blog and docs now pin identical exact fumadocs versions
  • Removed overrides for packages no longer in the tree (hono, @hono/node-server, better-sqlite3), a no-op (valibot) and nested duplicates of top-level rules. The installed tree is unchanged.

4. chore(release): 3.25.1

  • Version 3.25.1 across all workspaces and the Studio and portfolio build labels
  • Release notes (release-notes-v3.25.1.md) and the changelog seed entry
  • Local setup guide and README: npm 11 or higher is required

Not changed (separate PRs)

Breaking majors (zod 4, eslint 10, TypeScript 7, express 5, vitest 5, redis 6, openai 7, helmet 8, framer-motion 14), better-auth 1.7, and fumadocs 16.15+. The newer fumadocs-mdx and fumadocs-openapi require it, so it has to move as one coordinated upgrade.

Verification

Run on the original tree first as a baseline, then after each commit:

  • npm ci --legacy-peer-deps (same as CI), Prisma generate/validate, lint, format
  • npm run build for all 8 workspaces
  • Tests: server, site and studio contracts, studio PDF parity, portfolio
  • Runtime: /api/og on the site and portfolio production builds returns valid PNGs on 16.3.8, and nodemailer 10 composes a message with our exact transport options and fields

Notes for local setup

  • Installs that change dependencies need npm 11 (the repo's packageManager: npm@11.16.0). npm 10.9 crashes resolving eslint-config-next@16.3.8 peers. npm ci from the lockfile works on both.
  • Studio browser tests (test:browser) need npx playwright install chromium after the Playwright 1.63 bump.

- Upgrade Next.js and eslint-config-next to 16.3.8 (critical RCE in
  next/og ImageResponse, used by the site, blog, docs and portfolio OG
  routes; also image-optimizer SSRF and cache-poisoning fixes)
- Upgrade nodemailer to 10.0.14 (no patched 9.x); drop @types/nodemailer,
  v10 ships its own types
- Upgrade express to 4.22.3 (qs 6.16), multer to 2.4.0, vitest to 4.1.11
- Raise postcss to 8.5.28 (nanoid 3.3.19)
- Fix overrides that pinned vulnerable versions: fast-uri 3.1.8,
  body-parser 1.20.8; the old fast-uri pin never applied to the locked tree
- Override mysql2 3.24.5 and deepmerge-ts 8.0.2, both pinned vulnerable by
  prisma 7.x
- Refresh brace-expansion, qs, @xmldom/xmldom and nanoid within range

npm audit: 21 (1 critical, 14 high, 6 moderate) -> 5 high, all one
lint-only chain (braces via @next/eslint-plugin-next) with no upstream fix.
- Prisma 7.10.0 (prisma, @prisma/client, @prisma/config, @prisma/adapter-pg)
- Hold better-auth and @better-auth/prisma-adapter at ~1.6.25: 1.7 needs
  a mandatory Account.issuer column and backfill
- server: @aws-sdk 3.1146, dodopayments 2.52, mammoth 1.13, pg 8.23,
  resend 6.32, compression 1.8.2, uuid 14.0.2, tsx 4.23.15
- studio: @react-pdf/renderer 4.9, docx 9.8.1, playwright 1.63
- lucide-react 1.51, libphonenumber-js 1.13.14, sonner 2.0.8,
  zustand 5.0.15, tailwind-merge 3.7, prettier 3.9.9
- site: declare tsx, used by its prebuild scripts but previously only
  reachable through server's hoisted copy

Not changed: fumadocs-* (pinned by overrides; newer mdx/openapi need
fumadocs-core ^16.15) and all breaking majors (zod 4, eslint 10, TS 7,
express 5, vitest 5, redis 6, openai 7, helmet 8, framer-motion 14).
…rrides

- Pin fumadocs-core/ui 16.13.0 and fumadocs-mdx 15.2.0 exactly in both
  blog-platform and docs-platform (and fumadocs-openapi 11.2.2 in docs),
  matching the installed versions
- Keep the root fumadocs-core/ui overrides: they force a single copy for
  fumadocs-mdx, fumadocs-openapi and @fumadocs/api-docs, which declare
  their own ranges
- Remove nested fumadocs and @hono/node-server entries that repeated
  top-level overrides
- Remove overrides for hono, @hono/node-server and better-sqlite3 (no
  longer in the dependency tree) and for valibot (@prisma/dev already
  pins 1.4.2)
- veriworkly.md: Next.js 16.3.8, and correct the Playwright claim (it is a
  Studio dev dependency for browser tests, not used by any export path)

Installed dependency tree is unchanged.
- Bump version to 3.25.1 across root, site, studio, portfolio,
  blog-platform, docs-platform and server, plus the Studio and portfolio
  build labels
- Add release notes and the v3.25.1 changelog seed entry
- Local setup guide and README: npm 11 or higher is required
@Gautam25Raj
Gautam25Raj merged commit 7ddcf7a into master Oct 4, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant