fix(deps): clear high dev audit advisories - #1566
Conversation
Upgrade only the direct and transitive packages implicated by the current Bun high-severity audit. Keep the brace-expansion CommonJS compatibility patch on the fixed release and preserve separate compatible undici major lines in the lockfile.\n\nElectron moves to the first fixed 41.x release because 40.x has no patched build. PDF.js moves to its first patched release; its Node legacy entry remains importable under Bun and Node 24.
|
Warning Review limit reached
Next review available in: 4 minutes Limit details: You’ve used all 1 included review currently available under your plan. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe change updates dependency versions and root overrides, retargets the ChangesDependency updates
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: 🔵 Low · up to The PR updates dependency versions and lockfile resolutions to clear high advisories, with the listed validation checks passing. It is mergeable with explicit owner awareness to confirm that overrides for packages outside the stated advisory set are required and remove any unrelated entries. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Clear the high-severity advisories currently reported by the pinned
bun audit --audit-level=highjob after v2026.8.3. This PR intentionally contains only the dependency versions and lockfile resolutions needed for those findings; there is no related issue.Why
The audit baseline contained 10 high findings across nine packages. The remediation boundaries are:
electron: direct desktop dev dependency; 40.x has no patched release, so move to the first fixed 41.x release, 41.10.3.ip-address: introduced by MCP, Arborist, and desktop builder chains, including an exact 10.1.0 edge; pin the first fixed 10.3.1 release at the root.brace-expansion: introduced through minimatch; move the existing security override to 5.0.9 and carry the existing CommonJS compatibility patch forward.nanoid: introduced by Vite through PostCSS; pin the first fixed 3.x release, 3.3.18, without upgrading Vite or PostCSS.pdfjs-dist: direct OpenCode runtime dependency; move from 5.6.205 to the first fixed release, 6.2.108. The supported Node legacy entry imports successfully in Bun and Node 24.socket.io-parser: introduced by the GitLab provider through socket.io-client; pin the compatible fixed 4.2.7 release.undici: keep the unaffected 6.x chain unchanged, move desktop and Electron's optional 7.x chain to 7.29.0, and resolve Effect's existing^8.2.0edge to the first fixed 8.9.0 release.fast-uri: advance the existing root security override to 3.1.5.js-yaml: advance the existing root security override to 4.3.1.No unrelated dependency refresh was run.
Related Issue
None. This follows the release handoff and STATUS item for advisories that remained after v2026.8.3.
Human Review Status
Pending
Review Focus
Please verify that each manifest or lockfile change maps to one current high advisory, that the three compatible undici major lines remain separate, and that the Electron/PDF.js major boundaries have sufficient runtime evidence.
Risk Notes
How To Verify
Screenshots or Recordings
Not applicable; there is no visible UI change.
Checklist
bug,enhancement,task,documentation. Type labels are author-added; the labeler bot does NOT assign them. Add the label in the GitHub UI, then tick this.app,ui,platform,harness,ci. The labeler bot assigns these on PR open based on changed paths. Confirm the bot's choice (or override if wrong), then tick this.P0,P1,P2,P3. The priority-triage bot suggests one on PR open. Confirm or override, then tick this.Pending,Approved by @<reviewer>, orNot required: <reason>(default isPending; "not required" is restricted to bot-authored low-risk PRs).dev, and my PR title and commit messages use Conventional Commits in English.Summary by CodeRabbit