chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides - #17

Merged
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps
May 7, 2026
Merged

chore(deps): resolve transitive vite + esbuild security alerts via npm overrides#17
LSDimi merged 2 commits into
mainfrom
chore/audit-fix-deps

Conversation

@LSDimi

Copy link
Copy Markdown
Owner

Summary

Resolves the two remaining transitive Dependabot security alerts that the per-package Dependabot bumps couldn't reach:

  • vite path traversal in optimized deps .map handling — patched in 6.4.2
  • esbuild dev server arbitrary request injection — patched in 0.25.0

Both are dev-only, reaching us through vitest -> vite -> esbuild. Adds an overrides block in the root package.json and regenerates the lockfile so all transitives resolve to patched versions across all workspaces.

npm audit reports 0 vulnerabilities after this PR.

What's in this PR

  1. package.json (+4 lines) — adds:
    "overrides": {
    "vite": "^6.4.2",
    "esbuild": "^0.25.0"
    }
  2. package-lock.json (net -301 lines) — regenerated from scratch to apply the overrides. Net reduction comes from deduplication; no major version bumps to direct dependencies.
  3. packages/mcp-server/src/server.ts (-9 lines) — drops three @ts-expect-error directives that the regenerated dep tree no longer needs. The MCP TypeScript SDK upgrade pulled in by the lockfile regen fixesmodelcontextprotocol/typescript-sdk#494 (the deep Zod type inference issue), which is exactly the removal condition the original directive comments documented (Remove when SDK fixes deep type inference for complex Zod schemas). Without removing them, tsc flags them as unused (TS2578).

Why overrides instead of bumping vitest

Bumping vitest to a major version that uses vite >= 6.4.2 natively would touch four package.json files and risk test-runtime regressions across all workspaces. overrides is the surgical fix: pin the vulnerable transitives to patched versions without changing direct dependency declarations. Same outcome, smaller blast radius.

Test plan

  • npm auditfound 0 vulnerabilities
  • npm run check → lint (9 pre-existing warnings, 0 errors), format:check clean, build:shared clean, typecheck clean (after @ts-expect-error cleanup), build all workspaces clean, all 103 tests pass across mcp-server (60), claude-plugin (18), shared (25)
  • vite@6.4.2 and esbuild@0.25.12 confirmed installed in node_modules
  • Reviewer: confirm CI green and that no test regressions surface in the matrix
  • Reviewer: verify the @ts-expect-error removal is appropriate (cross-check that server.tool() calls now type-check cleanly without the suppressions)

LSDimi added 2 commits May 7, 2026 13:59
Resolves two transitive Dependabot security alerts:
- vite path traversal in optimized deps .map handling (CVE patched in 6.4.2)
- esbuild dev server arbitrary request injection (patched in 0.25.0)
Both vulnerabilities reach PluginOS only through dev-dep chains
(vitest -> vite -> esbuild). Adds an 'overrides' block to the root
package.json forcing patched versions across all workspaces. Lockfile
regenerated from scratch to apply the overrides; net diff is a small
reduction (-301 lines) due to deduplication.
npm audit reports 0 vulnerabilities after this change.
The MCP TypeScript SDK upgrade pulled in by the lockfile regeneration
fixes the deep Zod type inference issue tracked in
modelcontextprotocol/typescript-sdk#494 (the original directives'
removal condition). All three suppressions in mcp-server/src/server.ts
are now flagged as unused by tsc; removing them per the comment's
intent.
@LSDimi
LSDimi requested a review from apappascs as a code ownerMay 7, 2026 11:59

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds dependency overrides for vite and esbuild in package.json and removes several @ts-expect-error suppressions in server.ts that were previously used to handle Zod type depth issues. A high-severity issue was identified where the specified vite version (^6.4.2) does not exist on the npm registry, which will lead to installation failures.

Comment threadpackage.json
"typescript-eslint": "^8.58.2"
},
"overrides": {
"vite": "^6.4.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The version ^6.4.2 for vite does not appear to exist on the npm registry. The latest stable version is currently 6.1.0. This might be a typo for 5.4.12 (the security patch for the 5.x branch) or 6.0.2 (for the 6.x branch). Since using a non-existent version will cause npm install to fail, please verify and correct the version number.

Copy link
Copy Markdown
OwnerAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is incorrect — vite@6.4.2 exists and is on the registry. The latest stable is currently 8.0.11, not 6.1.0 as suggested. Verification:

$ npm view vite@6.4.2 version
6.4.2
$ npm view vite versions --json | tail -6
"8.0.6", "8.0.7", "8.0.8", "8.0.9", "8.0.10", "8.0.11"

The lockfile in this PR resolves to https://registry.npmjs.org/vite/-/vite-6.4.2.tgz and CI ran a full npm install + build + 103 tests successfully across Node 20/22/24. npm audit reports 0 vulnerabilities on this branch (vs 6 on main).

Looks like a stale-training-data hallucination. Closing this thread and proceeding with merge.

@LSDimi
LSDimi merged commit 2cd16d5 into mainMay 7, 2026
5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"Type instantiation is excessively deep and possibly infinite" typescript error when importing ToolCallback type

1 participant

@LSDimi