Skip to content

fix(deps): patch root workspace security vulnerabilities - #1724

Merged
Dhravya merged 1 commit into
capy/upgrade-better-auth-tofrom
capy/root-security-followup
Sep 29, 2026
Merged

Dhravya merged 1 commit into
capy/upgrade-better-auth-tofrom
capy/root-security-followup

Conversation

@Dhravya

@Dhravya Dhravya commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Patch the root Bun dependency graph on top of auth #1719, without refreshing unrelated SDK/runtime packages. The six-file diff contains dependency declarations and the lockfile only; no application logic or test edits.

Pin the first patched versions of Next 16.3.3, Drizzle 0.45.2, Vite 7.3.5 and Vitest 3.2.6, and raise Nanoid's 5.x bound. Exact root overrides cover vulnerable XML, ZIP, HTTP, protobuf, image and utility transitives. Multi-major dependencies (Nanoid, brace-expansion, js-yaml, picomatch and path-to-regexp) retain compatible majors through their individual lock resolutions rather than a blanket cross-major override. MCP's separate pnpm lock is #1722; this PR fixes its root Bun copies without changing its manifest.

The initial unrestricted resolver refresh was discarded. The shipped graph preserves unrelated AI SDK, OpenAI, Anthropic, Supermemory, Zod and Bun-type versions; new native/image/compiler dependencies are required by the patched packages.

Security and review order

Merge/review #1719, then this layer, then #1725. This layer patches detected High/Critical exposures in the workspace graph except the Mintlify tar/extract-zip chains, addressed by #1725. Key advisories include Next GHSA-p293-qw3h-jr36 / GHSA-2xp9-vwfh-vxw4, Vitest GHSA-5xrq-8626-4rwp, Drizzle GHSA-gpj5-g38j-94v9, and Axios GHSA-gcfj-64vw-6mp9. The combined stack has zero actual High/Critical locked-version matches in a fresh npm advisory audit.

Exact Dependabot alert numbers are pending: the connected integration's alerts API returns HTTP 403. Advisory ranges are matched against concrete lock versions, not raw Bun audit package-name output. Reconcile repository alert numbers before Vanta sign-off.

flowchart LR
  Auth["Auth #1719"] --> Root["Root dependencies #1724"] --> Docs["Docs archive chains #1725"]
Loading

Validation

Passed frozen Bun install, web/AI SDK/tools/memory-graph builds, lib/hooks/AI SDK/memory-graph typechecks, MCP build and server typecheck, and git diff --check. Existing suites pass: 4 AI SDK unit tests (3 skipped), 101 tools unit tests, 197 graph tests, 20 MCP unit tests, and 11 active MCP e2e tests (26 skipped). Patched Sharp PNG processing also passes.

Tools' full TypeScript check fails on existing examples/test fixtures; after building both baseline and candidate, the diagnostics match exactly. JSON manifests parse; Biome excludes JSON manifests in this repo, so there is no manifest lint pass to claim. No tests were changed.

Compatibility

Sharp moves from 0.33/0.34 to required 0.35.4; jsondiffpatch moves 0.6 to required 0.7.6; adm-zip moves 0.5 to required 0.6.1. No consumer source migration was required by the verified builds/tests. Framework and test-runner upgrades stay on their existing major lines.

@capy-ai
capy-ai Bot added this pull request to stack #1726 September 29, 2026 21:50
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
supermemory-app a96f0a5 Commit Preview URL

Branch Preview URL
Sep 29 2026, 09:51 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
supermemory-mcp a96f0a5 Sep 29 2026, 09:52 PM

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​next@​16.1.6 ⏵ 16.3.361 -32590 +19970
Updatednpm/​vite@​6.4.1 ⏵ 7.3.598 +7100 +248297100
Updatednpm/​drizzle-orm@​0.44.7 ⏵ 0.45.298 +1100 +1688 +197 -1100

View full report

@Dhravya
Dhravya merged commit 0dbb811 into capy/upgrade-better-auth-to Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant