Skip to content

fix(deps): bump lockfile past ip-address, fast-uri, grpc-js and brace-expansion advisories - #131

Merged
idapixl merged 1 commit into
masterfrom
fix/ip-address-10.7.2
Oct 1, 2026
Merged

idapixl merged 1 commit into
masterfrom
fix/ip-address-10.7.2

Conversation

@idapixl

@idapixl idapixl commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Closes Dependabot alerts #88 and #89 (ip-address ≤10.5.0, runtime scope via @modelcontextprotocol/sdk → express-rate-limit) and three more advisories npm audit reports on master:

package from to scope
ip-address 10.4.0 10.7.2 runtime
fast-uri 3.1.7 3.1.8 runtime
@grpc/grpc-js 1.14.4 1.14.5 dev (peer)
brace-expansion 2.1.4 2.1.7 dev (peer)

Every parent range already admits the patched release, so a consumer installing @fozikio/cortex-engine fresh resolves the fixed versions; no release is needed. The lockfile is what CI and the Docker image install from.

Hand-edited (npm 11 drops lockfile libc fields on --package-lock-only). Verified on a fresh clone: npm ci --ignore-scripts → 0 vulnerabilities, tsc clean, 431/431 tests.

Found by the scheduled ecosystem health check.

🤖 Generated with Claude Code

…-expansion advisories

Dependabot alerts #88/#89 (ip-address <=10.5.0, runtime via MCP SDK ->
express-rate-limit) plus three advisories npm audit reported on master.
Every parent range already admits the patched release, so consumers
installing fresh were never pinned to the vulnerable versions; the
lockfile is what CI and the Docker image install from, so it is the
thing that was exposed. Hand-edited rather than regenerated because
npm 11 drops lockfile libc fields on --package-lock-only.

Fresh npm ci: 0 vulnerabilities (full tree), tsc clean, 431/431 tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@idapixl
idapixl merged commit 0a933d2 into master Oct 1, 2026
9 checks passed
@idapixl
idapixl deleted the fix/ip-address-10.7.2 branch October 1, 2026 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant