Skip to content

fix(deps): patch transitive undici, fast-uri, brace-expansion, and cache advisories - #305

Draft
amanthanvi wants to merge 1 commit into
mainfrom
cursor/patch-transitive-advisories-8717
Draft

amanthanvi wants to merge 1 commit into
mainfrom
cursor/patch-transitive-advisories-8717

Conversation

@amanthanvi

@amanthanvi amanthanvi commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

What

Raises the pnpm-workspace.yaml override pins that are now vulnerable, and adds floors for two packages:

Package Before After Advisories Path
undici 6.28.0 6.28.1 GHSA-rfgv-xxqx-mfg5 (high), GHSA-3wwx-pv8p-q78v, GHSA-r53p-7pc4-xj5r vercel>undici
fast-uri 3.1.6 3.1.8 GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj vercel>…>ajv>fast-uri
brace-expansion 1.1.18 / 5.0.9 1.1.21 / 5.0.12 (2.x floor 2.1.7) GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr vercel>…>ts-morph, sigstore>…>glob
http-cache-semantics 4.2.0 4.3.0 GHSA-ch52-4w7c-c8xp (high, "through 4.2.0") sigstore>…>make-fetch-happen
source-map-js 1.2.1 1.2.2 GHSA-68fv-2mgg-jv7q (high) nextjs>@tailwindcss/postcss>…

The lockfile diff is 66 lines and only touches these packages.

Why

pnpm audit on main reports 15 findings (10 high, 4 moderate, 1 low), all from advisories published September 18–29. Most sit behind existing exact override pins, which Dependabot can't move, so no Dependabot PR was opened for them. I found this while checking the Next.js/sharp advisories for #299. Those two are already patched on main (next@16.3.8, sharp@0.35.5).

After this change pnpm audit reports one finding: braces ≤3.0.3 (GHSA-vfj7-8cjw-p6xm, high, stack-exhaustion DoS). It has no fixed release (3.0.3 is the latest), and it's only reachable through deploy tooling (vercel>@vercel/backends>ts-morph>@ts-morph/common>fast-glob>micromatch>braces), which processes trusted repository input. It's documented in the CHANGELOG rather than suppressed.

Checklist

  • pnpm next:lint, pnpm next:grammar, pnpm next:test, pnpm convex:test, pnpm convex:typecheck, pnpm -C nextjs build
  • pnpm deps:provenance (Sigstore path with the bumped deps; verified vercel@58.4.4), pnpm ops:test, node scripts/check-osv-exceptions.mjs, vercel --version / vercel build --help smoke (same exit code as main)
  • pnpm ingest:lint, pnpm ingest:test: not affected
  • CHANGELOG.md updated under Unreleased
Open in Web Open in Cursor 

Summary by Sourcery

Patch vulnerable transitive dependencies and reduce the remaining audit findings to an unfixed advisory in trusted Vercel tooling.

Bug Fixes:

  • Update transitive dependency pins to patched releases to address known security advisories across Vercel CLI, Sigstore, and Tailwind dependency trees.

Documentation:

  • Document the dependency security updates and the remaining unfixed braces advisory in the unreleased changelog.

…che advisories

Raise the vulnerable override pins (undici 6.28.0, fast-uri 3.1.6,
brace-expansion 1.1.18 / 5.0.9) to their patched releases and floor
http-cache-semantics at 4.3.0 and source-map-js at 1.2.2. pnpm audit drops
from 15 findings (10 high) to one: braces <=3.0.3 has no fixed release and
is only reachable through the Vercel CLI's ts-morph tooling.

Co-authored-by: Aman Thanvi <amanthanvi@users.noreply.github.com>
@vercel

vercel Bot commented Oct 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
betterman Ready Ready Preview Oct 10, 2026 9:18pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This dependency-maintenance PR updates pnpm workspace overrides so vulnerable transitive packages resolve to patched versions across the Vercel CLI, Sigstore, and Tailwind dependency trees, regenerates the focused lockfile changes, and documents the single remaining advisory without a fix.

Flow diagram for dependency advisory remediation

flowchart TD
    Audit[pnpm audit reports vulnerable transitive packages] --> Overrides[Raise pnpm workspace override floors]
    Overrides --> Lockfile[Regenerate focused lockfile]
    Lockfile --> Patched[Five dependency families resolve to patched versions]
    Patched --> Verify[Run dependency provenance and project checks]
    Verify --> Remaining[One unfixed braces advisory remains]
    Remaining --> Document[Document remaining advisory in CHANGELOG]
Loading

File-Level Changes

Change Details Files
Raise workspace override floors and exact pins for patched transitive dependency versions.
  • Update undici and fast-uri pins used by Vercel/AJV dependency paths.
  • Add patched floors for brace-expansion major versions, http-cache-semantics, and source-map-js.
  • Regenerate the lockfile, limited to the affected dependency entries.
pnpm-workspace.yaml
pnpm-lock.yaml
Document the dependency security remediation and the remaining unfixable advisory.
  • Record patched versions and affected dependency trees in the Unreleased changelog.
  • Explain that braces 3.0.3 remains reachable through Vercel tooling because no fixed release exists.
CHANGELOG.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

This branch was successfully deployed

1 active deployment
Preview — 9a8b09e5 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants