deps: periodic dependency & security updates - #229
Conversation
Update the Bun example to the current Arcjet SDK and cooled Bun types. Refresh Mastra and Zod in the Mastra agent after the repository 30-day cooldown. Co-authored-by: Codex <noreply@openai.com>
Firebase Tools reaches basic-ftp through get-uri in its PAC proxy path. Override get-uri to use the cooled fixed release while keeping the existing FTP client API. Remove the override when get-uri accepts basic-ftp 6.2.1 or later. Co-authored-by: Codex <codex@openai.com>
There was a problem hiding this comment.
Arcjet Review — 🟢 Low Risk
Decision: Approved
Rationale: This PR is a routine dependency maintenance change scoped to example projects. It bumps @arcjet/bun, @arcjet/inspect, @types/bun, @mastra/core, and zod to newer pinned versions, and adds a pnpm override for basic-ftp 6.2.1 under get-uri in the firebase-functions example to resolve GHSA-c475-qrg2-pj4r. The override is accompanied by a well-written entry in OVERRIDES.md documenting the reason and removal condition. All versions are pinned exactly (no ranges), no source code or runtime behaviour is changed, and nothing touches auth, infra, or production code. The dependency-changes trigger fires but the changes are well understood and low risk.
Summary of Changes
Periodic dependency bumps in three example projects (bun, firebase-functions, mastra-agent) plus a pnpm override pinning get-uri's basic-ftp transitive to 6.2.1 to address GHSA-c475-qrg2-pj4r, with a matching entry in OVERRIDES.md.
Escalation Triggers
- Dependency Changes: Three example package.json files updated and a new pnpm override added for basic-ftp.
Notes
Path filtering: 2 files excluded by ignore paths. 4 of 6 files included in review.
Review: cc06676e | Model: anthropic/claude-opus-4-7 | Powered by Arcjet Review
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring alerts on:
|
|
@SocketSecurity ignore npm/@mastra/core@1.63.2 npm/zod@4.5.4
|
periodic dependency & security updates