Repository navigation
fix(auth): upgrade Better Auth to patched 1.7.6 - #1719
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
supermemory-app | 5efda20 | Commit Preview URL Branch Preview URL |
Oct 02 2026, 11:56 PM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
supermemory-mcp | 5efda20 | Oct 02 2026, 11:56 PM |
0dbb811 to
750b59b
Compare
…o patch critical Next advisories
There was a problem hiding this comment.
Reviewed the latest head f614459, including the broader root dependency changes and the updated Next/OpenNext pairing. Holding approval because two new global overrides downgrade already-patched dependencies on main to vulnerable versions; see inline findings. Please raise or scope those overrides and regenerate bun.lock so existing patched versions are preserved.
Fresh frozen install, targeted auth/config lint, lib/hooks/web typechecks, Next build, OpenNext Cloudflare build and Wrangler dry-run pass. Repository-defined offline suites pass (101 tools, 4 AI SDK, 197 graph tests), as do AI SDK typecheck/build and graph build. The generic tools test command also includes API-key-dependent tests and an existing broken relative import, so the passing result here refers to test:unit, not that full command. Actual deployed login/session compatibility was not exercised, and this review does not establish production exploitability of the dependency findings. No code changed or merge performed.
There was a problem hiding this comment.
Re-reviewed head 5efda20. Both requested changes are fixed: PostCSS resolves to 8.5.23 and Mintlify scraping resolves to fast-xml-parser 5.7.3 with fast-xml-builder 1.3.1. The harmless PostCSS reproduction no longer discloses an out-of-tree map; neither reviewed advisory appears in the fresh Bun audit. Both inline threads are resolved. I reviewed the additional override/lockfile changes and found no new blocking issue.
Fresh frozen install, scoped lib/hooks/web/AI SDK/graph typechecks, targeted auth/config lint, tools build, 101 tools unit tests, 4 AI SDK unit tests, 197 graph tests, OpenNext Cloudflare build and Wrangler dry-run pass. MCP widget build, 20 unit tests, 11 active e2e tests (26 skipped) and server typecheck also pass. All six PR checks are green on this head. Tools full typecheck still has 146 diagnostics; a fresh comparison confirms they exactly match current main, so they are not introduced by this PR.
Approval covers the reviewed code/dependency changes, not complete repository security clearance or live deployed login/session compatibility. No code changes or merge performed.
This PR contains the existing Better Auth upgrade and the root dependency security changes from #1724, which was merged into this branch. It targets main; it is not an auth-only diff.
Auth scope
Upgrade root Better Auth and packages/lib Better Auth/API-key plugin to 1.7.6. main now already contains packages/lib's 1.6.22/API-key fix from #1741. The remaining auth source diff removes genericOAuthClient() because 1.7.6 no longer exports it. Its published 1.3.3 implementation was inference-only; scratch mocked request routing was checked, but actual login/session compatibility against the deployed backend is not established by this PR's builds/typechecks. Keep that distinction when reviewing.
The separate mono console's AgentID genericOAuthClient/signIn.oauth2 flow, backend genericOAuth agentid provider, and MCP issuer/resource-server configuration are not changed here. No database migrations or server auth configuration changes are included.
Root dependency scope
Retain #1724's Next 16.3.3, Drizzle 0.45.2, Vite 7.3.5, Vitest 3.2.6 and root transitive security overrides. Sharp moves to 0.35.4, jsondiffpatch to 0.7.6 and adm-zip to 0.6.1; these are part of the existing PR, not newly added by conflict resolution. Docs Mintlify/archive fixes already merged on main are preserved.
Conflict resolution and validation
Merged main at b85a1bf without force-pushing. Resolved packages/lib/package.json's 1.6.22 versus existing 1.7.6 entries and bun.lock from combined manifests. The resolved lockfile and auth sources exactly match the pre-merge PR, with no new removal or dependency version selection. PR-relative diff contains eight expected files and no docs/test changes.
Fresh frozen Bun install, targeted auth Biome, lib/hooks/web/AI SDK/memory-graph typechecks, web/tools/AI SDK/memory-graph builds, and git diff against main --check pass. Existing suites pass: 4 AI SDK tests (3 skipped), 101 tools tests, 197 graph tests, 20 MCP unit tests and 11 active MCP e2e tests (26 skipped); MCP build/server typecheck pass. Tools' 146 full-typecheck diagnostics exactly match the previously established baseline. Removed a stale local untracked Better Auth 1.3.3 install before rerunning affected auth checks; no source workaround was used.
Fresh Bun audit finds no Better Auth advisory entries, but other root transitive High findings remain (including newly published advisories). This conflict-only update does not claim complete current repository security clearance or end-to-end auth compatibility. Exact Dependabot alert mapping remains blocked by alerts API HTTP 403.
Critical Better Auth advisories originally addressed include GHSA-xg6x-h9c9-2m83 and GHSA-pw9m-5jxm-xr6h (CVE-2026-53512); main's lib version is now already beyond their patched thresholds.