Repository navigation
fix(deps): patch root workspace security vulnerabilities - #1724
Merged
Merged
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
supermemory-app | a96f0a5 | Commit Preview URL Branch Preview URL |
Sep 29 2026, 09:51 PM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
supermemory-mcp | a96f0a5 | Sep 29 2026, 09:52 PM |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Patch the root Bun dependency graph on top of auth #1719, without refreshing unrelated SDK/runtime packages. The six-file diff contains dependency declarations and the lockfile only; no application logic or test edits.
Pin the first patched versions of Next 16.3.3, Drizzle 0.45.2, Vite 7.3.5 and Vitest 3.2.6, and raise Nanoid's 5.x bound. Exact root overrides cover vulnerable XML, ZIP, HTTP, protobuf, image and utility transitives. Multi-major dependencies (Nanoid, brace-expansion, js-yaml, picomatch and path-to-regexp) retain compatible majors through their individual lock resolutions rather than a blanket cross-major override. MCP's separate pnpm lock is #1722; this PR fixes its root Bun copies without changing its manifest.
The initial unrestricted resolver refresh was discarded. The shipped graph preserves unrelated AI SDK, OpenAI, Anthropic, Supermemory, Zod and Bun-type versions; new native/image/compiler dependencies are required by the patched packages.
Security and review order
Merge/review #1719, then this layer, then #1725. This layer patches detected High/Critical exposures in the workspace graph except the Mintlify tar/extract-zip chains, addressed by #1725. Key advisories include Next GHSA-p293-qw3h-jr36 / GHSA-2xp9-vwfh-vxw4, Vitest GHSA-5xrq-8626-4rwp, Drizzle GHSA-gpj5-g38j-94v9, and Axios GHSA-gcfj-64vw-6mp9. The combined stack has zero actual High/Critical locked-version matches in a fresh npm advisory audit.
Exact Dependabot alert numbers are pending: the connected integration's alerts API returns HTTP 403. Advisory ranges are matched against concrete lock versions, not raw Bun audit package-name output. Reconcile repository alert numbers before Vanta sign-off.
Validation
Passed frozen Bun install, web/AI SDK/tools/memory-graph builds, lib/hooks/AI SDK/memory-graph typechecks, MCP build and server typecheck, and git diff --check. Existing suites pass: 4 AI SDK unit tests (3 skipped), 101 tools unit tests, 197 graph tests, 20 MCP unit tests, and 11 active MCP e2e tests (26 skipped). Patched Sharp PNG processing also passes.
Tools' full TypeScript check fails on existing examples/test fixtures; after building both baseline and candidate, the diagnostics match exactly. JSON manifests parse; Biome excludes JSON manifests in this repo, so there is no manifest lint pass to claim. No tests were changed.
Compatibility
Sharp moves from 0.33/0.34 to required 0.35.4; jsondiffpatch moves 0.6 to required 0.7.6; adm-zip moves 0.5 to required 0.6.1. No consumer source migration was required by the verified builds/tests. Framework and test-runner upgrades stay on their existing major lines.