Skip to content

fix(deps): proxy-addr 2.0.8, smol-toml 1.9.0 and katex 0.18.2 by caret override - #1745

Merged
Fmarzochi merged 2 commits into
mainfrom
fix/security-advisories-2026-10-05
Oct 6, 2026
Merged

Fmarzochi merged 2 commits into
mainfrom
fix/security-advisories-2026-10-05

Conversation

@Fmarzochi

@Fmarzochi Fmarzochi commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

What Changed

Three caret overrides in the root manifest (proxy-addr ^2.0.8, smol-toml ^1.9.0, katex ^0.18.2) and one in each MCP server manifest (proxy-addr ^2.0.8), in the same shape as the existing overrides. The three lockfiles now resolve to proxy-addr 2.0.8, smol-toml 1.9.0 and katex 0.18.10.

Why This Change

Three advisories were published on 5 October and reached the lockfiles through transitive dependencies: GHSA-jqcg-44mw-7w3h (proxy-addr below 2.0.8, critical, through express in the root package and both MCP servers), GHSA-r4xh-jqrq-34v2 (smol-toml below 1.9.0, moderate) and GHSA-238p-pmpm-9mq7 (katex below 0.18.2, low), the last two through markdownlint-cli in the root package. The Scorecard alert on main (code scanning #215) lists the three. The project keeps zero open vulnerabilities.

Testing Done

  • npm audit --audit-level=high: 0 vulnerabilities in the root package and in both MCP servers
  • npm ci in both MCP servers from the updated lockfiles: proxy-addr 2.0.8 installed, builds present
  • Full suite against the updated trees: 7076/7076

Type of Change

  • fix: (dependency security update, no code change)

Summary by cubic

Fixes three npm security advisories by adding caret overrides in the root manifest (proxy-addr ^2.0.8, smol-toml ^1.9.0, katex ^0.18.2) and in both MCP server manifests (proxy-addr ^2.0.8); the lockfiles now resolve to the patched versions. The same overrides are mirrored into the pnpm.overrides block so a pnpm install resolves the identical fixed versions.

  • proxy-addr 2.0.8 fixes GHSA-jqcg-44mw-7w3h (critical), which reaches the MCP servers through express.
  • smol-toml 1.9.0 and katex 0.18.10 fix GHSA-r4xh-jqrq-34v2 (moderate) and GHSA-238p-pmpm-9mq7 (low), both reaching the root package through markdownlint-cli.
  • No code changes; npm audit reports zero vulnerabilities in the root package and both MCP servers, and the full suite passes (7076/7076).

Written for commit f2dc7a0. Summary will update on new commits.

Review in cubic

…t override

Three advisories published on 5 October reached the lockfiles through transitive dependencies: proxy-addr below 2.0.8 (through express, in the root package and both MCP servers), smol-toml below 1.9.0 and katex below 0.18.2 (through markdownlint-cli, root only). Each manifest now carries a caret override at the fixed version, the same shape as the existing overrides, and the three lockfiles resolve to proxy-addr 2.0.8, smol-toml 1.9.0 and katex 0.18.10. npm audit reports zero vulnerabilities in the three packages.

Signed-off-by: Felipe Marzochi <fmarzochi@gmail.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 6 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread package.json
The repository keeps the npm overrides and the pnpm.overrides block identical, so a pnpm install resolves the same fixed versions. The three new entries are mirrored.

Signed-off-by: Felipe Marzochi <fmarzochi@gmail.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@Fmarzochi
Fmarzochi merged commit 9e1b303 into main Oct 6, 2026
42 checks passed
@Fmarzochi
Fmarzochi deleted the fix/security-advisories-2026-10-05 branch October 6, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant