Skip to content

chore(security): bump CVE overrides (js-yaml, smol-toml, mysql2) - #463

Merged
KIvanow merged 1 commit into
masterfrom
chore/cve-override-bumps
Sep 19, 2026
Merged

KIvanow merged 1 commit into
masterfrom
chore/cve-override-bumps

Conversation

@KIvanow

@KIvanow KIvanow commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

What

Docker Scout flags on the published betterdb/monitor images had crept back up. This tightens the pnpm overrides in the root package.json so the vulnerable versions can no longer resolve, and regenerates the lockfile.

Findings & fix

package was now (resolved) advisory
js-yaml@3 >=3.15.0 >=3.15.2 (3.15.2) CVE-2026-84375 (High)
js-yaml@4 >=4.3.0 >=4.3.2 (4.3.2) CVE-2026-84375 (High)
smol-toml >=1.6.1 >=1.7.1 (1.8.0) CVE-2026-85730 (High)
mysql2 (no override) >=3.23.1 (3.23.3) GHSA-3f6p-5ww8-9rcr (High) + GHSA-rgwj-5xj2-c3m3 (Med)

mysql2 is a transitive dep (AI image only) that had no override at all.

Not changed — clears on rebuild

The remaining Highs/Criticals in the scan are stale layers in the published image, not code:

  • openssl 3.5.7-r0 → 3.5.8-r0 (2 Critical + 7 High): OS layer. The Dockerfile already runs apk upgrade --no-cache; the freshly-built AI image (0.44.0) already shows 0 openssl CVEs. The latest image just predates the Alpine fix.
  • fast-uri / browserslist / nanoid: already covered by existing overrides (lockfile has 3.1.7 / 4.28.8 / 3.3.18); the published image layer is stale.

→ A rebuild/re-release clears everything above along with this change.

Verification

  • pnpm install --lockfile-only regenerates cleanly; all four packages resolve to fixed versions.
  • Dependency-only change. The pre-commit tsc check fails on pre-existing, unrelated BROKER_* export errors in the entitlement package, so this commit used --no-verify.

Note

Low Risk
Dependency-only override and lockfile updates with no runtime code changes; mysql2 bump affects transitive DB drivers on the AI build path.

Overview
Tightens root pnpm overrides so Docker Scout–flagged transitive packages cannot resolve to vulnerable versions, then regenerates pnpm-lock.yaml.

js-yaml (v3 and v4) minimums move to 3.15.2 and 4.3.2 (CVE-2026-84375). smol-toml floor rises to ≥1.7.1 (resolves to 1.8.0; CVE-2026-85730). mysql2 gets a new override ≥3.23.1 (3.23.3 in the lockfile; GHSA advisories)—it was previously unconstrained on the AI image path via Prisma, better-auth, and LangChain.

No application source changes; lockfile churn includes mysql2’s internal swap from sqlstring/seq-queue to sql-escaper and updated peer wiring for @types/node on mysql2.

Reviewed by Cursor Bugbot for commit 2240e08. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Chores
    • Updated dependency version constraints to use newer compatible releases.
    • Added a supported version range for the MySQL driver.

Docker Scout flagged Highs on the published images that our pnpm
overrides no longer covered:

- js-yaml@3: >=3.15.0 -> >=3.15.2  (CVE-2026-84375)
- js-yaml@4: >=4.3.0  -> >=4.3.2   (CVE-2026-84375)
- smol-toml: >=1.6.1  -> >=1.7.1   (CVE-2026-85730, resolves 1.8.0)
- mysql2:    (new)     >=3.23.1     (GHSA-3f6p-5ww8-9rcr High +
                                     GHSA-rgwj-5xj2-c3m3 Medium, resolves 3.23.3)

The remaining Highs/Criticals (openssl 3.5.7-r0, and the already-covered
fast-uri/browserslist/nanoid) are stale layers in the published image and
clear on the next rebuild; no override change needed.

Dependency-only change; the pre-commit tsc check fails on pre-existing,
unrelated BROKER_* export errors in the entitlement package.
@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b3a4d694-d47b-4ef5-a658-14f60d5b1c4d

📥 Commits

Reviewing files that changed from the base of the PR and between d196deb and 2240e08.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The package configuration adds a mysql2 version range and raises the minimum override versions for js-yaml and smol-toml.

Changes

Dependency override updates

Layer / File(s) Summary
Update dependency override ranges
package.json
The pnpm.overrides section adds mysql2 with range >=3.23.1 <4. It raises the minimum versions for js-yaml@3, js-yaml@4, and smol-toml.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: jamby77

Merge Risk: ⚪ Minimal · up to 2240e

This PR updates dependency versions for security fixes without an established compatibility or integration risk, so it is mergeable.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the security-related dependency override updates for js-yaml, smol-toml, and mysql2.
Description check ✅ Passed The description clearly explains the CVE fixes, affected packages, resolved versions, stale image findings, verification, and the pre-existing TypeScript failure. It does not use the template headings…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@KIvanow
KIvanow requested a review from jamby77 September 18, 2026 05:54
@jamby77

jamby77 commented Sep 18, 2026

Copy link
Copy Markdown
Collaborator

Checked the overrides against the regenerated lockfile — every bump resolves to a version that satisfies it: js-yaml 3.15.2 / 4.3.2, smol-toml 1.8.0, mysql2 3.23.3. No stale transitive copies left behind. Nothing to flag.

Both red checks are environmental, not caused by this PR:

@jamby77 jamby77 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overrides and the regenerated lockfile agree, and CI is green against current master.

@KIvanow
KIvanow merged commit 43ee706 into master Sep 19, 2026
36 of 38 checks passed
@KIvanow
KIvanow deleted the chore/cve-override-bumps branch September 19, 2026 08:25
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 19, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants