Skip to content

fix(deps): resolve three new transitive security advisories - #106

Merged
finalerock44 merged 1 commit into
devfrom
chore/audit-fix-transitive-advisories
Aug 5, 2026
Merged

fix(deps): resolve three new transitive security advisories#106
finalerock44 merged 1 commit into
devfrom
chore/audit-fix-transitive-advisories

Conversation

@finalerock44

@finalerock44 finalerock44 commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

pnpm audit --audit-level moderate started failing CI on every branch, including a clean dev - these advisories were published after dev's last green run, so nothing in the tree had to change to break it.

  • brace-expansion: the existing override pinned 5.0.8, which GHSA-rgw5-rvv9-x895 now covers (vulnerable <5.0.9). Range and target bumped to 5.0.9.
  • fast-uri (via @modelcontextprotocol/sdk > ajv): GHSA-7p8r-x3mc-p8w7, pinned 3.1.5.
  • hono (via @modelcontextprotocol/sdk): GHSA-8j4g-w8fx-2239, pinned 4.12.34.

All three pinned to the lowest patched version within their current major, following the existing exact-pin overrides. A first pass using open '>=' ranges pulled fast-uri 4.1.2 - a major jump inside ajv - for no benefit; these land on 3.1.5 and 4.12.34 instead.

audit clean; lint, typecheck, build and all 194 tests pass. fast-uri and hono are both MCP SDK dependencies, so also smoke-tested dist/mcp/index.js over stdio: initialize and tools/list both return, all five tools registered.

What & why

Type of change

  • fix — bug fix
  • feat — new feature
  • perf — performance improvement
  • refactor — code change that's neither a fix nor a feature
  • docs — documentation only
  • chore / ci / build / test — tooling, no user-facing change
  • Breaking change (title has ! or PR notes a BREAKING CHANGE:)

Checklist

  • PR title follows the Conventional Commits format (see comment above)
  • pnpm lint passes
  • pnpm typecheck passes
  • pnpm build passes
  • I have not bumped the version or edited CHANGELOG.md (release-please handles this)
  • I have signed the CLA (the bot will prompt on first contribution)
  • Docs / README.md / STYLE_GUIDE.md updated if behaviour or output changed

How to test


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

pnpm audit --audit-level moderate started failing CI on every branch, including
a clean dev - these advisories were published after dev's last green run, so
nothing in the tree had to change to break it.

- brace-expansion: the existing override pinned 5.0.8, which GHSA-rgw5-rvv9-x895
  now covers (vulnerable <5.0.9). Range and target bumped to 5.0.9.
- fast-uri (via @modelcontextprotocol/sdk > ajv): GHSA-7p8r-x3mc-p8w7, pinned 3.1.5.
- hono (via @modelcontextprotocol/sdk): GHSA-8j4g-w8fx-2239, pinned 4.12.34.

All three pinned to the lowest patched version within their current major,
following the existing exact-pin overrides. A first pass using open '>=' ranges
pulled fast-uri 4.1.2 - a major jump inside ajv - for no benefit; these land on
3.1.5 and 4.12.34 instead.

audit clean; lint, typecheck, build and all 194 tests pass. fast-uri and hono
are both MCP SDK dependencies, so also smoke-tested dist/mcp/index.js over
stdio: initialize and tools/list both return, all five tools registered.
@finalerock44 finalerock44 self-assigned this Aug 5, 2026
@claude

claude Bot commented Aug 5, 2026

Copy link
Copy Markdown

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

@finalerock44
finalerock44 merged commit f7934b0 into dev Aug 5, 2026
12 checks passed
@finalerock44
finalerock44 deleted the chore/audit-fix-transitive-advisories branch August 5, 2026 09:32
@finalerock44 finalerock44 mentioned this pull request Aug 6, 2026
14 tasks
finalerock44 added a commit that referenced this pull request Aug 7, 2026
Promote from dev to stable:

* feat: client-side envelope encryption of app binaries, flow zips and env vars
  (#94, #101) — opt-in via `--encrypt` / `DCD_ENCRYPT_BINARIES=1` and off by
  default, so uploads stay byte-identical unless asked for. Per-upload DEK,
  chunked AES-256-GCM container, X25519 sealed-box DEK wrap; encrypted binaries
  dedup on the plaintext hash so re-uploads still hit the cache.
* feat(artifacts): prefer server-assembled bundle delivery for downloads (#93) —
  falls back to the inline endpoint on 501, so it degrades cleanly against an
  API that has not shipped bundles.
* feat(device): add Android API level 37 (Android 17) (#107) — the flag enum
  accepts 37, but the device/API-level pair is validated against the
  compatibility matrix the *target* API serves, and production still tops out at
  36, so 37 is refused client-side until the platform gate flips.
* refactor(cloud): remove the enterprise-only --mitmHost / --mitmPath flags
  (#102). The submitted config payload for runs that never passed them is
  byte-identical.
* fix(deps) / deps: clear every outstanding pnpm audit advisory (#89, #92, #95,
  #100, #106), bump chalk 5 -> 6, and regenerate the schema types from the
  current API swagger (#105).

No platform prerequisite this time: the envelope decrypt half (dcd api +
simulators) is already on production with both env KEK public keys pinned,
bundle delivery has a 501 fallback, and API 37 is gated server-side.

Carries only the source delta — package.json version, CHANGELOG.md and the
release-please manifests stay as release-please left them on production.

Release-As: 5.3.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant