Skip to content

chore(deps): refresh transitive deps to clear npm audit - #30

Merged
htcom-code merged 1 commit into
mainfrom
chore/audit-fix-lockfile
Aug 4, 2026
Merged

htcom-code merged 1 commit into
mainfrom
chore/audit-fix-lockfile

Conversation

@htcom-code

Copy link
Copy Markdown
Owner

Problem

npm audit on main reports 5 advisories (2 high, 3 moderate). All of them
are reached through a single chain — the shadcn CLI dependency tree:

Package Severity Path
@hono/node-server <2.0.5 — serve-static path traversal (Windows) moderate shadcn → sdk
@modelcontextprotocol/sdk 1.25.0–1.29.0 moderate shadcn
hono <4.12.34 — CORS ReDoS moderate shadcn → sdk
fast-uri 3.0.0–3.1.4 — host confusion high shadcn → sdk → ajv
brace-expansion 4.0.0–5.0.8 — DoS high shadcn → ts-morph → minimatch

Previously there was no clean remediation: the fix had to land upstream first
(hono → MCP SDK → shadcn), and npm audit fix --force only offered a major
shadcn downgrade. shadcn cannot be dropped — src/index.css imports
shadcn/tailwind.css as a build-time CSS source.

What changed

Upstream is now fixed. @modelcontextprotocol/sdk@1.30.0 widened its range to
"@hono/node-server": "^1.19.9 || ^2.0.5", which makes the patched 2.x line
reachable. That unblocks a plain lockfile refresh:

@modelcontextprotocol/sdk  1.29.0  -> 1.30.0
@hono/node-server          1.19.15 -> 2.1.0
hono                       4.12.32 -> 4.13.0
fast-uri                   3.1.4   -> 3.1.5
brace-expansion            5.0.8   -> 5.0.9
  • package-lock.json only — package.json is untouched
  • no overrides, no forced majors, no downgrades
  • all five are transitive dev-tooling deps; none reach the shipped bundle

Verification

  • npm audit → found 0 vulnerabilities (was 5)
  • npm ci clean
  • npm run lint → no errors (3 pre-existing only-export-components warnings unchanged)
  • npm run build → passes

Notes

Independent of the open dependabot PRs (#28, #29) — this touches only
transitive lockfile entries, so it applies with or without them. Whichever
merges second will need a trivial lockfile rebase.

- npm audit reported 5 advisories (2 high, 3 moderate), all reached
  through the shadcn CLI dependency chain
- upstream is now fixed: @modelcontextprotocol/sdk 1.30.0 widened
  @hono/node-server to "^1.19.9 || ^2.0.5", so the patched 2.x line
  is finally reachable without an override or a shadcn downgrade
- lockfile-only refresh, package.json untouched, no major bumps:
  @modelcontextprotocol/sdk 1.29.0 -> 1.30.0
  @hono/node-server 1.19.15 -> 2.1.0
  hono 4.12.32 -> 4.13.0
  fast-uri 3.1.4 -> 3.1.5
  brace-expansion 5.0.8 -> 5.0.9
- npm audit now reports 0 vulnerabilities; lint and build both pass

Tags: #deps #security #lockfile
Co-Authored-By: htjulia <htjulia1@gmail.com>
@htcom-code
htcom-code merged commit 4af681d into main Aug 4, 2026
2 checks passed
@htcom-code
htcom-code deleted the chore/audit-fix-lockfile branch August 4, 2026 04:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant