Skip to content

fix: resolve dependency audit findings - #829

Closed
rajat1saxena wants to merge 1 commit into
mainfrom
audit-fix
Closed

rajat1saxena wants to merge 1 commit into
mainfrom
audit-fix

Conversation

@rajat1saxena

Copy link
Copy Markdown
Member

Summary

Non-breaking dependency audit remediation for the pnpm monorepo using pnpm audit + filtered pnpm.overrides (same-major / within-range only). No audit fix --force and no intentional major version bumps.

Vulnerability counts (pnpm audit)

Severity Before After
critical 8 1
high 162 23
moderate 152 38
low 41 10
total 363 72

Packages updated (notable)

Package Before After
next 16.1.6, 16.2.9 16.3.8
mongoose 8.23.1 8.24.4
axios 1.16.0 1.20.0
form-data 4.0.5 4.0.6
qs 6.13.0, 6.14.0 6.16.0
dompurify 3.3.3 3.4.16
body-parser 1.20.3 1.20.8
nodemailer 6.10.1, 9.0.3 6.10.1, 9.1.1
@tiptap/core / @tiptap/pm 3.10.8 3.31.4
@grpc/grpc-js 1.14.3 1.14.5
protobufjs 7.5.7 7.6.6
@babel/core 7.26.10 7.29.7
better-auth 1.6.11 1.7.6
preact 10.26.5 10.29.8
rollup 2.79.2 / 3.29.5 / 4.40.0 2.80.0 / 3.30.0 / 4.63.5
brace-expansion 1.1.11–5.0.5 1.1.21 / 2.1.7 / 5.0.12
minimatch various patched within majors
picomatch 2.3.1, 4.0.4 2.3.2, 4.0.7
samlify 2.10.2 2.13.1
liquidjs 10.26.0 10.29.0
ws 8.18.1 8.22.0
image-size 2.0.2 2.0.4
@xmldom/xmldom 0.8.13 0.8.15
fast-uri 3.1.2 3.1.8

Also refreshed related transitive pins via root pnpm.overrides (capped to the same major).

Left unfixed (would require breaking / major bumps)

Remaining findings need major upgrades, e.g.:

  • astro 1.x → 7.x (remaining critical + several high/moderate)
  • vite 3.x → 5+/6+
  • nodemailer 6.x → 7+/10+ (9.x line was patched to 9.1.1 where possible)
  • devalue, deepmerge-ts, sharp 0.33/0.34 → 0.35, adm-zip 0.5 → 0.6, ip-address 9 → 10, OpenTelemetry SDK 0.204 → 0.217

Test plan

  • pnpm audit before/after compared
  • Spot-check: apps/web/app/api/auth/__tests__/route.test.ts (4 tests passed)
  • CI full suite

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f1faae8e03

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
"linkify-it@<=5.0.0": ">=5.0.1 <6.0.0",
"devalue@>=4.0.0 <5.6.4": ">=5.6.4 <6.0.0",
"js-yaml@>=4.0.0 <=4.1.1": ">=4.2.0 <5.0.0",
"better-auth@<1.6.13": ">=1.6.13 <2.0.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep Better Auth SSO on its matched dependency set

When SSO is enabled, this override upgrades the app's pinned better-auth 1.6.11 to 1.7.6 while leaving @better-auth/sso pinned at 1.6.11. The resulting lock entry injects @better-auth/utils 0.5.0, @better-fetch/fetch 1.3.2, and better-call 1.4.0 into that SSO plugin, even though its declared peers are the exact 0.4.0, 1.1.21, and 1.3.5 versions respectively (pnpm-lock.yaml lines 13794-13800). Align the SSO package with the upgraded Better Auth release, or limit the override to a version compatible with the pinned SSO plugin, so SSO login does not run against incompatible internal peers.

Useful? React with 👍 / 👎.

@rajat1saxena

Copy link
Copy Markdown
Member Author

Audit re-run (2026-10-01 IST)

Re-audited on this branch: still 72 findings (1 critical / 23 high / 38 moderate / 10 low).

No additional non-breaking fixes available today — remaining items need major bumps (astro 1→5+/7+, nodemailer 6→7+/10+, vite 5→6+, adm-zip 0.5→0.6, sharp 0.33→0.35, uuid→11, etc.). No new commit pushed.

@rajat1saxena

Copy link
Copy Markdown
Member Author

Closing to reopen under the Codelit bot account (clbotdev).

@clbotdev clbotdev mentioned this pull request Oct 1, 2026
2 of 3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant