Skip to content

fix: resolve dependency audit findings - #18

Closed
rajat1saxena wants to merge 3 commits into
mainfrom
audit-fix
Closed

rajat1saxena wants to merge 3 commits into
mainfrom
audit-fix

Conversation

@rajat1saxena

Copy link
Copy Markdown
Member

Summary

Applies non-breaking dependency updates via pnpm audit --fix update (within existing semver ranges; no major bumps, no --force).

Vulnerability counts

Severity Before After
critical 3 0
high 51 10
moderate 46 10
low 8 2
total 108 22

Notable fixed packages

  • next ^16.2.9 → ^16.3.7 (clears critical RCE advisories)
  • postcss, nanoid, liquidjs, vitest, @grpc/grpc-js, undici, hono, and related transitive updates via lockfile
  • Direct workspace package.json ranges refreshed within ^ for api/web/docs/email-* packages and root tooling

Also updates pnpm-workspace.yaml minimumReleaseAgeExclude entries so pnpm can install the patched versions.

Remaining issues (not fixed — would require major bumps)

Left unfixed intentionally (breaking majors / out-of-range):

  • nodemailer — remaining advisories need ≥10.x (currently ^9.1.1)
  • Several transitive leftovers (esbuild/tsup paths, some nested postcss/nanoid/qs/browserslist/@opentelemetry/core, pnpm CLI itself <11.11.0, ts-deepmerge major, etc.) that pnpm audit --fix update could not resolve within current ranges

Verification

  • pnpm audit re-run after fix (counts above)
  • Built shared packages, then pnpm test — all passed (api/web/email-editor/email-blocks)

Test plan

  • pnpm audit before/after
  • pnpm test after building workspace packages
  • CI green on this PR

rajat1saxena and others added 3 commits September 30, 2026 19:45
Update pnpm-workspace override from ^22.14.1 to ^22.20.0 to match
the audit-fix package.json bumps, and regenerate pnpm-lock.yaml so
pnpm install --frozen-lockfile succeeds in CI.
- Bump packageManager/devEngines pnpm 11.10.0 → 11.11.0 (high advisories)
- Override @opentelemetry/core to >=2.8.0 <3 (2.7.1 → 2.9.0)
- Override qs to >=6.16.0 <7 (drop 6.15.3)
- Remaining findings require major bumps (nodemailer 10+, esbuild 0.x, etc.)
- Verified: pnpm install --frozen-lockfile, lint, prettier --check, build, test
@rajat1saxena

Copy link
Copy Markdown
Member Author

Audit follow-up (2026-10-01 IST)

Additional non-breaking fixes pushed to this branch:

Package Change Severity cleared
pnpm (packageManager / devEngines) 11.10.0 → 11.11.0 3 high (pnpm advisories)
@opentelemetry/core 2.7.1 → 2.9.0 (override >=2.8.0 <3) moderate
qs 6.15.3 removed → 6.16.0 (override >=6.16.0 <7) moderate

Audit counts on this branch: 15 → 9 (2 low / 5 moderate / 2 high)

Remaining still need majors (nodemailer ≥10, esbuild 0.x jumps, ts-deepmerge 8, tsup 8).

Verified: pnpm install --frozen-lockfile, lint, prettier --check, CI package builds, pnpm test (all green).

@rajat1saxena

Copy link
Copy Markdown
Member Author

Closing to reopen under the Codelit bot account (clbotdev).

@clbotdev clbotdev mentioned this pull request Oct 1, 2026
2 of 3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant