fix: resolve dependency audit findings - #829
rajat1saxena wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f1faae8e03
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "linkify-it@<=5.0.0": ">=5.0.1 <6.0.0", | ||
| "devalue@>=4.0.0 <5.6.4": ">=5.6.4 <6.0.0", | ||
| "js-yaml@>=4.0.0 <=4.1.1": ">=4.2.0 <5.0.0", | ||
| "better-auth@<1.6.13": ">=1.6.13 <2.0.0", |
There was a problem hiding this comment.
Keep Better Auth SSO on its matched dependency set
When SSO is enabled, this override upgrades the app's pinned better-auth 1.6.11 to 1.7.6 while leaving @better-auth/sso pinned at 1.6.11. The resulting lock entry injects @better-auth/utils 0.5.0, @better-fetch/fetch 1.3.2, and better-call 1.4.0 into that SSO plugin, even though its declared peers are the exact 0.4.0, 1.1.21, and 1.3.5 versions respectively (pnpm-lock.yaml lines 13794-13800). Align the SSO package with the upgraded Better Auth release, or limit the override to a version compatible with the pinned SSO plugin, so SSO login does not run against incompatible internal peers.
Useful? React with 👍 / 👎.
Audit re-run (2026-10-01 IST)Re-audited on this branch: still 72 findings (1 critical / 23 high / 38 moderate / 10 low). No additional non-breaking fixes available today — remaining items need major bumps (astro 1→5+/7+, nodemailer 6→7+/10+, vite 5→6+, adm-zip 0.5→0.6, sharp 0.33→0.35, uuid→11, etc.). No new commit pushed. |
|
Closing to reopen under the Codelit bot account (clbotdev). |
Summary
Non-breaking dependency audit remediation for the pnpm monorepo using
pnpm audit+ filteredpnpm.overrides(same-major / within-range only). Noaudit fix --forceand no intentional major version bumps.Vulnerability counts (
pnpm audit)Packages updated (notable)
Also refreshed related transitive pins via root
pnpm.overrides(capped to the same major).Left unfixed (would require breaking / major bumps)
Remaining findings need major upgrades, e.g.:
Test plan
pnpm auditbefore/after comparedapps/web/app/api/auth/__tests__/route.test.ts(4 tests passed)