Repository navigation
chore(security): bump CVE overrides (js-yaml, smol-toml, mysql2) - #463
Conversation
Docker Scout flagged Highs on the published images that our pnpm overrides no longer covered: - js-yaml@3: >=3.15.0 -> >=3.15.2 (CVE-2026-84375) - js-yaml@4: >=4.3.0 -> >=4.3.2 (CVE-2026-84375) - smol-toml: >=1.6.1 -> >=1.7.1 (CVE-2026-85730, resolves 1.8.0) - mysql2: (new) >=3.23.1 (GHSA-3f6p-5ww8-9rcr High + GHSA-rgwj-5xj2-c3m3 Medium, resolves 3.23.3) The remaining Highs/Criticals (openssl 3.5.7-r0, and the already-covered fast-uri/browserslist/nanoid) are stale layers in the published image and clear on the next rebuild; no override change needed. Dependency-only change; the pre-commit tsc check fails on pre-existing, unrelated BROKER_* export errors in the entitlement package.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe package configuration adds a ChangesDependency override updates
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to This PR updates dependency versions for security fixes without an established compatibility or integration risk, so it is mergeable. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Checked the overrides against the regenerated lockfile — every bump resolves to a version that satisfies it: Both red checks are environmental, not caused by this PR:
|
jamby77
left a comment
There was a problem hiding this comment.
Overrides and the regenerated lockfile agree, and CI is green against current master.
What
Docker Scout flags on the published
betterdb/monitorimages had crept back up. This tightens the pnpmoverridesin the rootpackage.jsonso the vulnerable versions can no longer resolve, and regenerates the lockfile.Findings & fix
js-yaml@3>=3.15.0>=3.15.2(3.15.2)js-yaml@4>=4.3.0>=4.3.2(4.3.2)smol-toml>=1.6.1>=1.7.1(1.8.0)mysql2>=3.23.1(3.23.3)mysql2is a transitive dep (AI image only) that had no override at all.Not changed — clears on rebuild
The remaining Highs/Criticals in the scan are stale layers in the published image, not code:
apk upgrade --no-cache; the freshly-built AI image (0.44.0) already shows 0 openssl CVEs. Thelatestimage just predates the Alpine fix.→ A rebuild/re-release clears everything above along with this change.
Verification
pnpm install --lockfile-onlyregenerates cleanly; all four packages resolve to fixed versions.tsccheck fails on pre-existing, unrelatedBROKER_*export errors in the entitlement package, so this commit used--no-verify.Note
Low Risk
Dependency-only override and lockfile updates with no runtime code changes; mysql2 bump affects transitive DB drivers on the AI build path.
Overview
Tightens root pnpm
overridesso Docker Scout–flagged transitive packages cannot resolve to vulnerable versions, then regeneratespnpm-lock.yaml.js-yaml(v3 and v4) minimums move to 3.15.2 and 4.3.2 (CVE-2026-84375).smol-tomlfloor rises to ≥1.7.1 (resolves to 1.8.0; CVE-2026-85730).mysql2gets a new override ≥3.23.1 (3.23.3 in the lockfile; GHSA advisories)—it was previously unconstrained on the AI image path via Prisma, better-auth, and LangChain.No application source changes; lockfile churn includes mysql2’s internal swap from
sqlstring/seq-queuetosql-escaperand updated peer wiring for@types/nodeon mysql2.Reviewed by Cursor Bugbot for commit 2240e08. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by CodeRabbit