Repository navigation
fix(deps): proxy-addr 2.0.8, smol-toml 1.9.0 and katex 0.18.2 by caret override - #1745
Merged
Merged
Conversation
…t override Three advisories published on 5 October reached the lockfiles through transitive dependencies: proxy-addr below 2.0.8 (through express, in the root package and both MCP servers), smol-toml below 1.9.0 and katex below 0.18.2 (through markdownlint-cli, root only). Each manifest now carries a caret override at the fixed version, the same shape as the existing overrides, and the three lockfiles resolve to proxy-addr 2.0.8, smol-toml 1.9.0 and katex 0.18.10. npm audit reports zero vulnerabilities in the three packages. Signed-off-by: Felipe Marzochi <fmarzochi@gmail.com>
Contributor
There was a problem hiding this comment.
All reported issues were addressed across 6 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
The repository keeps the npm overrides and the pnpm.overrides block identical, so a pnpm install resolves the same fixed versions. The three new entries are mirrored. Signed-off-by: Felipe Marzochi <fmarzochi@gmail.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What Changed
Three caret overrides in the root manifest (
proxy-addr^2.0.8,smol-toml^1.9.0,katex^0.18.2) and one in each MCP server manifest (proxy-addr^2.0.8), in the same shape as the existing overrides. The three lockfiles now resolve to proxy-addr 2.0.8, smol-toml 1.9.0 and katex 0.18.10.Why This Change
Three advisories were published on 5 October and reached the lockfiles through transitive dependencies: GHSA-jqcg-44mw-7w3h (proxy-addr below 2.0.8, critical, through express in the root package and both MCP servers), GHSA-r4xh-jqrq-34v2 (smol-toml below 1.9.0, moderate) and GHSA-238p-pmpm-9mq7 (katex below 0.18.2, low), the last two through markdownlint-cli in the root package. The Scorecard alert on main (code scanning #215) lists the three. The project keeps zero open vulnerabilities.
Testing Done
npm audit --audit-level=high: 0 vulnerabilities in the root package and in both MCP serversnpm ciin both MCP servers from the updated lockfiles: proxy-addr 2.0.8 installed, builds presentType of Change
fix:(dependency security update, no code change)Summary by cubic
Fixes three npm security advisories by adding caret overrides in the root manifest (
proxy-addr^2.0.8,smol-toml^1.9.0,katex^0.18.2) and in both MCP server manifests (proxy-addr^2.0.8); the lockfiles now resolve to the patched versions. The same overrides are mirrored into thepnpm.overridesblock so a pnpm install resolves the identical fixed versions.proxy-addr2.0.8 fixes GHSA-jqcg-44mw-7w3h (critical), which reaches the MCP servers throughexpress.smol-toml1.9.0 andkatex0.18.10 fix GHSA-r4xh-jqrq-34v2 (moderate) and GHSA-238p-pmpm-9mq7 (low), both reaching the root package throughmarkdownlint-cli.npm auditreports zero vulnerabilities in the root package and both MCP servers, and the full suite passes (7076/7076).Written for commit f2dc7a0. Summary will update on new commits.