chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs - #1502

Merged
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies
Jul 24, 2026
Merged

chore: upgrade JavaScript dependencies to address 22 CVEs and 6 GHSAs#1502
jsourcebot merged 3 commits into
mainfrom
cursor/cve/security-dependencies

Conversation

@jsourcebot

@jsourcebotjsourcebot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1556
Fixes SOU-1564
Fixes SOU-1565
Fixes SOU-1566
Fixes SOU-1568
Fixes SOU-1570
Fixes SOU-1571
Fixes SOU-1572
Fixes SOU-1573
Fixes SOU-1574
Fixes SOU-1575
Fixes SOU-1576
Fixes SOU-1577
Fixes SOU-1578
Fixes SOU-1579
Fixes SOU-1580
Fixes SOU-1581
Fixes SOU-1582
Fixes SOU-1583
Fixes SOU-1584
Fixes SOU-1590
Fixes SOU-1591
Fixes SOU-1592
Fixes SOU-1593
Fixes SOU-1594

Summary

  • Upgrades Auth.js to next-auth@5.0.0-beta.32 and @auth/core@0.41.3, Next.js to 16.2.11, PostCSS to 8.5.22, and Sharp to 0.35.3.
  • Refreshes or upgrades linkify-it, fast-uri, protobufjs, Express/body-parser, Hono, @hono/node-server, and DOMPurify to patched releases.
  • Uses qualified Yarn resolutions only where an exact or incompatible transitive range would otherwise retain a vulnerable version.
  • Updates the Sharp metadata type import for Sharp 0.35 compatibility.
  • Removes every finding reported by yarn npm audit --all --recursive --no-deprecations.

Advisories

This resolves:

SOU-1561 is excluded because it belongs to sourcebot-dev/lighthouse. SOU-1567 is excluded because the vulnerable gRPC-Go dependency belongs to the sourcebot-dev/zoekt submodule repository. Neither advisory is claimed by this PR or its changelog entry.

Verification

  • yarn npm audit --all --recursive --no-deprecations --json — no findings
  • make
  • yarn build
  • yarn lint — zero errors
  • yarn test — 120 test files and 1,789 tests passed
  • git diff --check

Supersedes

This consolidated PR supersedes the overlapping per-package CVE PRs #1467, #1477, #1478, #1479, #1480, #1486, #1487, #1488, #1489, #1490, #1491, #1492, #1493, #1494, #1495, #1496, #1497, #1498, #1499, and #1500.


Note

Medium Risk
Touches authentication (next-auth), the Next.js app shell, Express, and Sharp-based upload validation; risk is mostly regression from version bumps rather than new logic, but those surfaces are security-sensitive.

Overview
This PR bumps vulnerable JavaScript dependencies across the monorepo so yarn npm audit reports no findings, and documents the fix in CHANGELOG.

Web upgrades include next16.2.11, next-auth5.0.0-beta.32 (with @auth/core / @auth/prisma-adapter), sharp0.35.3, and postcss8.5.12. Backend moves express to 4.22.2. The root package.json adds Yarn resolutions (e.g. @hono/node-server, pinned next, postcss, sharp) so transitive trees pick patched versions.

Transitive refreshes in the lockfile cover hono, dompurify, fast-uri, linkify-it, protobufjs, body-parser, and related Express stack packages. The only application code change is in chat attachment validation: import Metadata from sharp instead of sharp.Metadata for Sharp 0.35 typing.

Reviewed by Cursor Bugbot for commit f4999ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Updated dependencies to address multiple security vulnerabilities and resolve all reported Yarn audit findings.
    • Improved security and stability across authentication, web framework, image processing, request handling, and content sanitization components.
  • Maintenance

    • Updated backend and web application dependencies, including authentication, framework, styling, and image-processing packages.
    • Documented the security updates in the changelog.

@coderabbitai

coderabbitaiBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0304706f-2753-4a2f-b705-fb67e368a79d

📥 Commits

Reviewing files that changed from the base of the PR and between a536249 and f4999ef.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • packages/backend/package.json
  • packages/web/package.json
  • packages/web/src/features/chat/attachments/validation.ts

Walkthrough

Dependency resolutions and workspace package versions were updated for security fixes, with a changelog entry added. Image attachment validation now uses an explicit sharp metadata type import without runtime behavior changes.

Changes

Dependency security updates

Layer / File(s)Summary
Dependency version and resolution updates
package.json, packages/backend/package.json, packages/web/package.json, CHANGELOG.md
Root resolutions and backend/web dependencies were upgraded across framework, authentication, image, CSS, server, and related packages, with the fixes recorded in the changelog.
Sharp metadata type import
packages/web/src/features/chat/attachments/validation.ts
The attachment validator now imports Metadata as a named type and uses it for decoded image metadata; runtime validation remains unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers:brendan-kellam, whoisthey

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: upgrading JavaScript dependencies to fix security advisories.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/security-dependencies

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jsourcebot
jsourcebot marked this pull request as ready for review July 24, 2026 01:22
@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2200
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
khroma2.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page (registry metadata: license field = Apache-2.0)
map-stream0.1.0UNKNOWNMITnpm page (registry metadata: license field = MIT)
memorystream0.3.1UNKNOWNMITnpm page (registry metadata: licenses array = [{"type":"MIT"}])
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)extracted from object (license array in oss-licenses.json lists MIT and Apache2)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file: Apache-2.0 primary license; MIT applies only to some vendored third-party files)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file: MIT)

@jsourcebot
jsourcebot merged commit 8c74f1f into mainJul 24, 2026
14 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Jul 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jsourcebot