Skip to content

fix: resolve dependency audit findings - #830

Open
clbotdev wants to merge 1 commit into
mainfrom
audit-fix
Open

clbotdev wants to merge 1 commit into
mainfrom
audit-fix

Conversation

@clbotdev

@clbotdev clbotdev commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Non-breaking dependency audit remediation for the pnpm monorepo using pnpm audit + filtered pnpm.overrides (same-major / within-range only). No audit fix --force and no intentional major version bumps.

Reopened under the Codelit bot account (clbotdev). Supersedes #829.

Vulnerability counts (pnpm audit)

Severity Before After
critical 8 1
high 162 23
moderate 152 38
low 41 10
total 363 72

Packages updated (notable)

Package Before After
next 16.1.6, 16.2.9 16.3.8
mongoose 8.23.1 8.24.4
axios 1.16.0 1.20.0
form-data 4.0.5 4.0.6
qs 6.13.0, 6.14.0 6.16.0
dompurify 3.3.3 3.4.16
body-parser 1.20.3 1.20.8
nodemailer 6.10.1, 9.0.3 6.10.1, 9.1.1
@tiptap/core / @tiptap/pm 3.10.8 3.31.4
@grpc/grpc-js 1.14.3 1.14.5
protobufjs 7.5.7 7.6.6
@babel/core 7.26.10 7.29.7
better-auth 1.6.11 1.7.6
preact 10.26.5 10.29.8
rollup 2.79.2 / 3.29.5 / 4.40.0 2.80.0 / 3.30.0 / 4.63.5

Also refreshed related transitive pins via root pnpm.overrides (capped to the same major).

Left unfixed (would require breaking / major bumps)

Remaining findings need major upgrades, e.g.:

  • astro 1.x → 7.x (remaining critical + several high/moderate)
  • vite 3.x → 5+/6+
  • nodemailer 6.x → 7+/10+ (9.x line was patched to 9.1.1 where possible)
  • devalue, deepmerge-ts, sharp 0.33/0.34 → 0.35, adm-zip 0.5 → 0.6, ip-address 9 → 10, OpenTelemetry SDK 0.204 → 0.217

Test plan

  • pnpm audit before/after compared
  • Spot-check: apps/web/app/api/auth/__tests__/route.test.ts (4 tests passed)
  • CI full suite

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants