chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: fix security vulnerabilities found by yarn audit - #1121

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities
Apr 15, 2026
Merged

chore: fix security vulnerabilities found by yarn audit#1121
brendan-kellam merged 2 commits into
mainfrom
brendan/fix-audit-vulnerabilities

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades direct dependencies (nodemailer, posthog-js, @posthog/ai) to resolve known security vulnerabilities
  • Adds scoped resolutions for transitive dependency vulnerabilities (next, hono, @hono/node-server, langsmith, markdown-it, yaml, ajv, smol-toml, teeny-request)
  • Adds audit script to root package.json with --no-deprecations flag for clean security-only auditing

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated dependencies (mail, protocol, analytics, and others) to newer stable versions.
    • Added an automated dependency audit command for improved security monitoring.
    • Pinned multiple transitive dependencies to ensure compatibility across the project.
  • Documentation

    • Expanded unreleased notes to cover JavaScript dependency remediation and running yarn audit to address security findings.

Resolves all security vulnerabilities reported by yarn audit:
Direct dependency upgrades:
- nodemailer: ^7.0.11 → ^8.0.5 (SMTP command injection)
- posthog-js: ^1.345.5 → ^1.369.0 (dompurify XSS/prototype pollution)
- @posthog/ai: ^7.8.10 → ^7.15.0 (langsmith prototype pollution)
Resolutions for transitive dependencies:
- next via @react-email/preview-server (DoS with Server Components)
- hono + @hono/node-server via @modelcontextprotocol/sdk (cookie, path traversal, middleware bypass)
- langsmith via @langchain/core (prototype pollution)
- markdown-it via codemirror-json-schema (ReDoS)
- yaml via codemirror-json-schema + openapi3-ts (stack overflow)
- ajv via @eslint/eslintrc (ReDoS)
- smol-toml via @react-grab/cli (DoS)
- teeny-request via retry-request (incorrect control flow in @tootallnate/once)
Also adds `audit` script to root package.json with --no-deprecations flag.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77785511-f2bd-4c5c-a444-845849784ccb

📥 Commits

Reviewing files that changed from the base of the PR and between 55b607a and 4dd5610.

📒 Files selected for processing (1)
  • CHANGELOG.md

Walkthrough

Adds a root audit script and multiple yarn resolutions entries to pin transitive dependencies; bumps four direct dependencies in packages/web/package.json; updates CHANGELOG to include JS dependency remediation and PR reference.

Changes

Cohort / File(s)Summary
Root package config
package.json
Added "scripts.audit": "yarn npm audit --all --recursive --no-deprecations" and appended multiple resolutions entries to pin transitive packages (e.g., @react-email/preview-server/next, @modelcontextprotocol/sdk/*, langsmith, markdown-it, yaml, ajv@^6, smol-toml, teeny-request).
Web package dependencies
packages/web/package.json
Bumped direct dependencies: @modelcontextprotocol/sdk ^1.27.1 → ^1.29.0, @posthog/ai ^7.8.10 → ^7.15.0, nodemailer ^7.0.11 → ^8.0.5, posthog-js ^1.345.5 → ^1.369.0.
Changelog
CHANGELOG.md
Expanded Unreleased → Fixed entry to include JS dependency remediation and added PR reference #1121.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and accurately describes the main objective of the PR: fixing security vulnerabilities found by yarn audit, which is confirmed by the file changes (dependency upgrades and audit script addition) and PR description.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/fix-audit-vulnerabilities

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 35db5c2 into mainApr 15, 2026
7 of 8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 15, 2026
@brendan-kellam
brendan-kellam deleted the brendan/fix-audit-vulnerabilities branch April 15, 2026 04:31
@github-actions

github-actionsBot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2057
Resolved (non-standard)20
Unresolved0
Strong copyleft0
Weak copyleft31

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (20)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/cli0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; individual package.json omits license field but inherits repo-level MIT
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo aidenybai/react-grab — root LICENSE file confirms MIT; packages/mcp/package.json confirmed to be part of same monorepo
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — FSL-1.1-MIT is a valid SPDX identifier (Functional Source License v1.1 with MIT future grant); confirmed via getsentry/sentry-cli GitHub repo. Note: this is a source-available license, not OSI-approved open source.
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry — valid SPDX identifier; same license as @sentry/cli (getsentry/sentry-cli repo). Source-available, not OSI-approved open source.
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo livebook-dev/codemirror-lang-elixir — LICENSE file contains Apache License Version 2.0
element-source0.0.3UNKNOWNMITGitHub repo aidenybai/element-source — LICENSE file contains MIT License (maintainer email aiden.bai05@gmail.com matches Aiden Bai / aidenybai GitHub account)
json-schema0.4.0(AFL-2.1 OR BSD-3-Clause)AFL-2.1 OR BSD-3-Clausenpm registry — parenthesised compound SPDX expression; both AFL-2.1 (Academic Free License 2.1) and BSD-3-Clause are valid SPDX identifiers. This is a standard dual-license offering.
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo livebook-dev/lezer-elixir — LICENSE file contains Apache License Version 2.0
map-stream0.1.0UNKNOWNMITGitHub repo dominictarr/map-stream — LICENCE file contains MIT License
memorystream0.3.1{"type":"MIT","url":"http://github.com/JSBizon/node-memorystream/raw/master/LICENSE"}MITExtracted from object license field — type field is MIT; confirmed by npm registry manifest returning license object with type=MIT
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo PostHog/posthog-js — LICENSE file is Apache License Version 2.0 (primary governing license; some third-party components are MIT)
valid-url1.0.9UNKNOWNMITGitHub repo ogt/valid-url — LICENSE file contains MIT License

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam