Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
supermemory-app | d1488f4 | Commit Preview URL Branch Preview URL |
Sep 29 2026, 09:51 PM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
supermemory-mcp | d1488f4 | Sep 29 2026, 09:52 PM |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Base automatically changed from
capy/root-security-followup
to
capy/upgrade-better-auth-to
September 29, 2026 22:29
|
Recreated as #1727 on the updated auth branch, which already contains squash-merged #1724. The replacement has only the docs manifest/lockfile diff and no obsolete root commit. Its Git tree exactly matches the validated docs tree; fresh frozen install, web build, tar smoke test and zero High/Critical lock matches passed. Closing this superseded PR to avoid reviewing the conflicting stack history. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pin the docs development dependency Mintlify to 4.2.933 and regenerate only its required dependency graph, on top of #1724. No docs content, deployment configuration, application code or tests change. Existing docs dev script behavior (bunx mintlify@latest) is left untouched.
Why this parent upgrade
extract-zip 2.0.1 has no published patched release for High GHSA-jmr9-qjv8-65gv / GHSA-7pqw-9j4j-h8q3, so overriding it cannot solve the alerts. Published Mintlify/CLI/link-rot/scraping/previewing metadata establishes 4.2.933 as the earliest stable Mintlify parent that removes Puppeteer and therefore extract-zip, while using patched tar 7.5.21. Its previewing code owns the tar 6→7 API migration; we do not force a major tar override on the old parent.
Tar coverage includes Critical GHSA-23hp-3jrh-7fpw and High archive traversal/recursion advisories through GHSA-r292-9mhp-454m. Retain the root's patched js-yaml 4.3.2 rather than accepting Mintlify's vulnerable pinned 4.3.1. Preserve unrelated Bun types. The final combined root graph has zero High/Critical locked-version matches in a fresh npm advisory audit; extract-zip and Puppeteer are absent.
Exact Dependabot alert numbers await access: the integration returns HTTP 403 for the repository alerts API. Map the GHSA IDs to actual repository alert numbers before SOC 2 sign-off.
Stack
Review/merge auth #1719 → root #1724 → this docs layer. Separate lockfile PRs (#1720, #1721, #1722 and #1723) are independent.
Validation and limitations
Frozen Bun install, git diff --check, tar gzip archive roundtrip, and Sharp PNG resize pass. All shared consumers were revalidated after this graph change: web/AI SDK/tools/memory-graph builds; lib/hooks/AI SDK/memory-graph and MCP server typechecks; 4 AI SDK, 101 tools, 197 graph, 20 MCP unit and 11 active MCP e2e tests pass. Tools' remaining full-typecheck diagnostics match the post-build baseline exactly. No docs build/typecheck/test scripts are defined.
The local Mintlify CLI encounters duplicate-React hook errors both before and after the upgrade. A scratch-only React resolution loader gets the patched validator past that inherited issue, but strict docs validation then rejects the externally hosted OpenAPI document (api.supermemory.ai/v4/openapi): /v3/settings/security PATCH response 200 lacks a required description. Thus a successful docs validation/build is not claimed. Neither that external API schema nor unrelated React resolution was changed in this security PR.
Mintlify's internal MDX packages change major versions as part of the required parent graph; docs content is unchanged, and full docs validation remains limited as above.