Uh oh!
There was an error while loading. Please reload this page.
chore: fix security vulnerabilities found by yarn audit - #1121
Conversation
Resolves all security vulnerabilities reported by yarn audit: Direct dependency upgrades: - nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection) - posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution) - @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution) Resolutions for transitive dependencies: - next via @react-email/preview-server (DoS with Server Components) - hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass) - langsmith via @langchain/core (prototype pollution) - markdown-it via codemirror-json-schema (ReDoS) - yaml via codemirror-json-schema + openapi3-ts (stack overflow) - ajv via @eslint/eslintrc (ReDoS) - smol-toml via @react-grab/cli (DoS) - teeny-request via retry-request (incorrect control flow in @tootallnate/once) Also adds `audit` script to root package.json with --no-deprecations flag. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
WalkthroughAdds a root Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
License Audit
Weak Copyleft Packages (informational)
Resolved Packages (20)
|
Summary
nodemailer,posthog-js,@posthog/ai) to resolve known security vulnerabilitiesnext,hono,@hono/node-server,langsmith,markdown-it,yaml,ajv,smol-toml,teeny-request)auditscript to rootpackage.jsonwith--no-deprecationsflag for clean security-only auditing🤖 Generated with Claude Code
Summary by CodeRabbit
Chores
Documentation