chore(deps)(deps): bump the minor-and-patch group across 1 directory with 37 updates - #92
Conversation
…with 37 updates Bumps the minor-and-patch group with 37 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `4.1.11` | | [esbuild](https://github.com/evanw/esbuild) | `0.28.1` | `0.28.2` | | [turbo](https://github.com/vercel/turborepo) | `2.10.5` | `2.10.11` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `4.1.11` | | [@hono/node-server](https://github.com/honojs/node-server) | `2.0.10` | `2.1.1` | | [@langchain/core](https://github.com/langchain-ai/langchainjs) | `1.2.3` | `1.2.9` | | [@langchain/openai](https://github.com/langchain-ai/langchainjs) | `1.5.5` | `1.5.10` | | [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.6.23` | `1.7.1` | | [deepagents](https://github.com/langchain-ai/deepagentsjs) | `1.11.1` | `1.13.0` | | [hono](https://github.com/honojs/hono) | `4.12.31` | `4.13.3` | | [mongoose](https://github.com/Automattic/mongoose) | `9.7.4` | `9.9.3` | | [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.12` | | [@astrojs/starlight](https://github.com/withastro/starlight/tree/HEAD/packages/starlight) | `0.41.3` | `0.41.7` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` | | [@dagrejs/dagre](https://github.com/dagrejs/dagre) | `3.0.0` | `3.1.1` | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.101.2` | `5.101.4` | | [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.170.18` | `1.170.31` | | [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) | `12.11.2` | `12.11.3` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.25.0` | `1.33.0` | | [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.2.8` | | [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.17` | `19.2.18` | | [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.7` | `19.2.8` | | [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.3` | `19.2.4` | | [recharts](https://github.com/recharts/recharts) | `3.9.2` | `3.10.1` | | [sonner](https://github.com/emilkowalski/sonner) | `2.0.7` | `2.0.8` | | [@tanstack/router-plugin](https://github.com/TanStack/router/tree/HEAD/packages/router-plugin) | `1.168.23` | `1.168.34` | | [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.1.0` | | [postcss](https://github.com/postcss/postcss) | `8.5.20` | `8.5.26` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.5` | `8.2.2` | | [@langchain/anthropic](https://github.com/langchain-ai/langchainjs) | `1.5.1` | `1.5.8` | | [isomorphic-git](https://github.com/isomorphic-git/isomorphic-git) | `1.38.9` | `1.41.7` | | [langchain](https://github.com/langchain-ai/langchainjs) | `1.5.3` | `1.5.10` | | [@radix-ui/react-label](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/label) | `2.1.12` | `2.1.15` | | [@radix-ui/react-separator](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/separator) | `1.1.12` | `1.1.15` | | [@radix-ui/react-slot](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/slot) | `1.3.0` | `1.3.3` | | [@radix-ui/react-tooltip](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/tooltip) | `1.2.13` | `1.2.16` | | [radix-ui](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/radix-ui) | `1.6.3` | `1.6.7` | Updates `@vitest/coverage-v8` from 4.1.10 to 4.1.11 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/coverage-v8) Updates `esbuild` from 0.28.1 to 0.28.2 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.28.1...v0.28.2) Updates `turbo` from 2.10.5 to 2.10.11 - [Release notes](https://github.com/vercel/turborepo/releases) - [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md) - [Commits](vercel/turborepo@v2.10.5...v2.10.11) Updates `vitest` from 4.1.10 to 4.1.11 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest) Updates `@hono/node-server` from 2.0.10 to 2.1.1 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v2.0.10...v2.1.1) Updates `@langchain/core` from 1.2.3 to 1.2.9 - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.3...@langchain/core@1.2.9) Updates `@langchain/openai` from 1.5.5 to 1.5.10 - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/openai@1.5.5...@langchain/openai@1.5.10) Updates `better-auth` from 1.6.23 to 1.7.1 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.1/packages/better-auth) Updates `deepagents` from 1.11.1 to 1.13.0 - [Release notes](https://github.com/langchain-ai/deepagentsjs/releases) - [Commits](https://github.com/langchain-ai/deepagentsjs/compare/deepagents@1.11.1...deepagents@1.13.0) Updates `hono` from 4.12.31 to 4.13.3 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.3) Updates `mongoose` from 9.7.4 to 9.9.3 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@9.7.4...9.9.3) Updates `tsx` from 4.23.1 to 4.23.12 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.1...v4.23.12) Updates `@astrojs/starlight` from 0.41.3 to 0.41.7 - [Release notes](https://github.com/withastro/starlight/releases) - [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md) - [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.41.7/packages/starlight) Updates `@playwright/test` from 1.61.1 to 1.62.1 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.61.1...v1.62.1) Updates `@dagrejs/dagre` from 3.0.0 to 3.1.1 - [Release notes](https://github.com/dagrejs/dagre/releases) - [Changelog](https://github.com/dagrejs/dagre/blob/master/changelog.md) - [Commits](dagrejs/dagre@v3.0.0...v3.1.1) Updates `@tanstack/react-query` from 5.101.2 to 5.101.4 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.4/packages/react-query) Updates `@tanstack/react-router` from 1.170.18 to 1.170.31 - [Release notes](https://github.com/TanStack/router/releases) - [Changelog](https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.31/packages/react-router) Updates `@xyflow/react` from 12.11.2 to 12.11.3 - [Release notes](https://github.com/xyflow/xyflow/releases) - [Changelog](https://github.com/xyflow/xyflow/blob/main/packages/react/CHANGELOG.md) - [Commits](https://github.com/xyflow/xyflow/commits/@xyflow/react@12.11.3/packages/react) Updates `lucide-react` from 1.25.0 to 1.33.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.33.0/packages/lucide-react) Updates `react` from 19.2.7 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react) Updates `@types/react` from 19.2.17 to 19.2.18 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `react-dom` from 19.2.7 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom) Updates `@types/react-dom` from 19.2.3 to 19.2.4 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `recharts` from 3.9.2 to 3.10.1 - [Release notes](https://github.com/recharts/recharts/releases) - [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md) - [Commits](recharts/recharts@v3.9.2...v3.10.1) Updates `sonner` from 2.0.7 to 2.0.8 - [Release notes](https://github.com/emilkowalski/sonner/releases) - [Commits](emilkowalski/sonner@v2.0.7...v2.0.8) Updates `@tanstack/router-plugin` from 1.168.23 to 1.168.34 - [Release notes](https://github.com/TanStack/router/releases) - [Changelog](https://github.com/TanStack/router/blob/main/packages/router-plugin/CHANGELOG.md) - [Commits](https://github.com/TanStack/router/commits/@tanstack/router-plugin@1.168.34/packages/router-plugin) Updates `@types/react` from 19.2.17 to 19.2.18 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `@types/react-dom` from 19.2.3 to 19.2.4 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `@vitejs/plugin-react` from 6.0.3 to 6.1.0 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.0/packages/plugin-react) Updates `postcss` from 8.5.20 to 8.5.26 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.20...8.5.26) Updates `vite` from 8.1.5 to 8.2.2 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.2/packages/vite) Updates `@langchain/anthropic` from 1.5.1 to 1.5.8 - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/anthropic@1.5.1...@langchain/anthropic@1.5.8) Updates `isomorphic-git` from 1.38.9 to 1.41.7 - [Release notes](https://github.com/isomorphic-git/isomorphic-git/releases) - [Commits](isomorphic-git/isomorphic-git@v1.38.9...v1.41.7) Updates `langchain` from 1.5.3 to 1.5.10 - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Commits](https://github.com/langchain-ai/langchainjs/compare/langchain@1.5.3...langchain@1.5.10) Updates `@radix-ui/react-label` from 2.1.12 to 2.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/label/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/label) Updates `@radix-ui/react-separator` from 1.1.12 to 1.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/separator/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/separator) Updates `@radix-ui/react-slot` from 1.3.0 to 1.3.3 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/slot/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/slot) Updates `@radix-ui/react-tooltip` from 1.2.13 to 1.2.16 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/tooltip/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/tooltip) Updates `radix-ui` from 1.6.3 to 1.6.7 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/radix-ui/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/1.6.7/packages/react/radix-ui) --- updated-dependencies: - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: esbuild dependency-version: 0.28.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: turbo dependency-version: 2.10.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: vitest dependency-version: 4.1.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@hono/node-server" dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@langchain/core" dependency-version: 1.2.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@langchain/openai" dependency-version: 1.5.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: better-auth dependency-version: 1.7.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: deepagents dependency-version: 1.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: hono dependency-version: 4.13.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: mongoose dependency-version: 9.9.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: tsx dependency-version: 4.23.12 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@astrojs/starlight" dependency-version: 0.41.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@playwright/test" dependency-version: 1.62.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@dagrejs/dagre" dependency-version: 3.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@tanstack/react-query" dependency-version: 5.101.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@tanstack/react-router" dependency-version: 1.170.31 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@xyflow/react" dependency-version: 12.11.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: lucide-react dependency-version: 1.33.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: react dependency-version: 19.2.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/react" dependency-version: 19.2.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: react-dom dependency-version: 19.2.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/react-dom" dependency-version: 19.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: recharts dependency-version: 3.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: sonner dependency-version: 2.0.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@tanstack/router-plugin" dependency-version: 1.168.34 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/react" dependency-version: 19.2.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/react-dom" dependency-version: 19.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@vitejs/plugin-react" dependency-version: 6.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: postcss dependency-version: 8.5.26 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: vite dependency-version: 8.2.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@langchain/anthropic" dependency-version: 1.5.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: isomorphic-git dependency-version: 1.41.7 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: langchain dependency-version: 1.5.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@radix-ui/react-label" dependency-version: 2.1.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@radix-ui/react-separator" dependency-version: 1.1.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@radix-ui/react-slot" dependency-version: 1.3.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@radix-ui/react-tooltip" dependency-version: 1.2.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: radix-ui dependency-version: 1.6.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
There was a problem hiding this comment.
Threat-surface review (PR #92)
Dependabot-only bump: 8 package.json files + pnpm-lock.yaml. No application source, no .env / .env.local, no hardcoded secrets. Surfaces 1–5 are unchanged by this diff; surface 6 is the one that moves.
1. MCP endpoint auth — no change
MCP packages stay at @modelcontextprotocol/server / @modelcontextprotocol/hono 2.0.0-alpha.2 (OSV clean). Bearer lookup, project-slug bind, expiry, and session re-auth still live in apps/api/src/mcp/archmax-route.ts (authenticateRequest before transport.handleRequest; resumed sessions re-check tokenId / projectId / slug). Invalid tokens still return JSON-RPC -32001, not a stack trace. Tool scopes are still enforced in archmax-server.ts / executeScopedQuery.
2. Query execution sandboxing — no change
@duckdb/node-api is not in this group. execute_query still goes through executeScopedQuery with AST validation (rejects INSERT/UPDATE/DELETE/DROP/ALTER/multi-statement), readOnly: true DuckDB attach, VIEW-scoped catalogs, QUERY_TIMEOUT_MS, and MAX_ROWS.
3. Admin auth (Better Auth) — library minor, app controls intact
better-auth 1.6.23 → 1.7.1 (resolved 1.7.1; OSV clean, as are @better-auth/core@1.7.1, @better-auth/mongo-adapter@1.7.1, jose@6.2.9). App-owned controls were not edited:
BETTER_AUTH_SECRETstillz.string().min(32)inpackages/core/src/config/env.ts- Cookies still
httpOnly: true,securein production,sameSite: "lax"inapps/api/src/lib/auth.ts - CSRF still on
/api/*viaapps/api/src/middleware/csrf.ts;/api/auth/*remains Better Auth’strustedOrigins
1.7 tightens a few defaults this app already aligns with: cookie-cache is now bound to the session_token cookie (this repo has cookieCache.enabled); forwarded-host is fail-closed unless trustedProxyHeaders is set (this repo uses a static baseURL, not allowedHosts). Captcha / OAuth / MCP / device-grant breaking changes do not apply — this app is email+password + username() + mongodbAdapter only.
Operational (not a vulnerability): 1.7 scopes account identity by issuer + accountId. Credential-only Mongo installs should smoke-test username/email sign-in after merge; OAuth/SSO backfill does not apply here.
4. API input validation — no change
zod stays ^4.4.3. No Hono handlers, Zod schemas, or Mongo/DuckDB query construction changed.
5. Environment secrets — no change
No secret values added to source or lockfile. .env / .env.* remain gitignored (!.env.example only).
6. Dependency exposure
Security-relevant resolved versions and OSV (querybatch, 2026-08-24):
| Package | Base | Head | OSV |
|---|---|---|---|
hono |
4.12.31 | 4.13.3 | Base hits GHSA-54fx-42gc-7vw4, GHSA-79qm-7rj5-m7r9, GHSA-8j4g-w8fx-2239 (CVE-2026-69207 CORS ReDoS), GHSA-f23p-vx2j-j53r. 4.13.3 is clean. App already sets non-empty allowHeaders in apps/api/src/middleware/cors.ts, so the ReDoS path was already mitigated; the bump still removes the vulnerable parser. |
@hono/node-server |
2.0.10 | 2.1.1 | Clean |
better-auth |
1.6.23 | 1.7.1 | Clean |
mongoose |
9.7.4 | 9.9.3 | Clean (CVE-2026-42334 was fixed in 9.1.6) |
deepagents |
1.11.1 | 1.13.0 | Clean. 1.13 adds recursive delete (still goes through ValidatingFilesystemBackend + virtualMode: true) and caps sandbox glob so root searches cannot OOM. |
isomorphic-git |
1.38.9 | 1.41.7 | Clean (1.38.9 was already past the Aug 2026 fixes) |
vite |
8.1.5 | 8.2.2 | Clean |
| MCP server/hono | 2.0.0-alpha.2 | unchanged | Clean (CVE-2026-25536 is legacy @modelcontextprotocol/sdk v1.x only) |
pnpm audit is 24 vulnerabilities (2 low / 4 moderate / 18 high) — the same pre-existing set, not introduced here:
packages/core→markitdown-ts@0.0.10→xlsx@0.18.5/@xmldom/xmldom- direct
js-yaml@^4.1.1(lockfile also has unused 4.3.1; GHSA-52cp-r559-cp3m / GHSA-h67p-54hq-rp68 need>=4.3.0) ws@8.20.0(needs>=8.20.1; langsmith/openai peer + jsdom→vitest)apps/docsastro@^6.4.8XSS advisories (fix is major>=7.x)
Verdict: No threat-surface defect in this diff. The hono bump is a security fix. The better-auth 1.6→1.7 jump is the highest-risk library change and is OSV-clean with app cookie/CSRF/secret controls still explicit; smoke-test admin login after merge.
Sent by Cursor Automation: archmax Security Review
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit ece1218. Configure here.
| "@modelcontextprotocol/server": "2.0.0-alpha.2", | ||
| "better-auth": "^1.6.23", | ||
| "deepagents": "^1.11.1", | ||
| "better-auth": "^1.7.1", |
There was a problem hiding this comment.
Auth upgrade missing issuer migration
High Severity
Bumping better-auth from 1.6.x to 1.7.1 requires a manual Account.issuer backfill (local:credential for email/password rows) before identity lookups use the new (issuer, accountId) key. This PR only changes the package version—no MongoDB backfill or migration is added—so existing credential accounts can fail sign-in after deploy, including the seeded admin path with disableSignUp: true.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit ece1218. Configure here.
| "@langchain/openai": "^1.5.10", | ||
| "bullmq": "^5.80.9", | ||
| "deepagents": "^1.11.1", | ||
| "deepagents": "^1.13.0", |
There was a problem hiding this comment.
Agent todos silently dropped
Medium Severity
Bumping deepagents from 1.11.x to 1.13.0 makes todoListMiddleware opt-in, so write_todos is no longer installed by default. createDeepAgent callers only register createToolErrorRecoveryMiddleware(), and the chat UI still has dedicated write_todos rendering, so agents lose planning todos without any compensating opt-in.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit ece1218. Configure here.




Bumps the minor-and-patch group with 37 updates in the / directory:
4.1.104.1.110.28.10.28.22.10.52.10.114.1.104.1.112.0.102.1.11.2.31.2.91.5.51.5.101.6.231.7.11.11.11.13.04.12.314.13.39.7.49.9.34.23.14.23.120.41.30.41.71.61.11.62.13.0.03.1.15.101.25.101.41.170.181.170.3112.11.212.11.31.25.01.33.019.2.719.2.819.2.1719.2.1819.2.719.2.819.2.319.2.43.9.23.10.12.0.72.0.81.168.231.168.346.0.36.1.08.5.208.5.268.1.58.2.21.5.11.5.81.38.91.41.71.5.31.5.102.1.122.1.151.1.121.1.151.3.01.3.31.2.131.2.161.6.31.6.7Updates
@vitest/coverage-v8from 4.1.10 to 4.1.11Release notes
Sourced from @vitest/coverage-v8's releases.
Commits
9bd8d46chore: release v4.1.11 (#10995)Updates
esbuildfrom 0.28.1 to 0.28.2Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
609683dpublish 0.28.2 to npm11b1fe4add to release notesab50d91css: fix green/blue channel swap in oklch gamut mapping (#4488)04627b6fix #4498:asyncTLA checks need a worklist5c15177disablegoplsin thegofolderfc2ee9bcss: adjust parser to allow--foo: {...}209db54release notes for css nesting bugfixc625d31fix #4497: preserve nested ampersands during minification (#4500)34474e2better isolation of current part in js parser07f6e8cfix #4507:importassignment tree-shaking bugUpdates
turbofrom 2.10.5 to 2.10.11Release notes
Sourced from turbo's releases.
... (truncated)
Commits
60af39bpublish 2.10.11 to registry3226457fix: Tolerate transient input files (#13734)09bf969docs: Redesign Turborepo homepage (#13702)f924510feat: Expand performance agent toolbox (#13761)9f94a7dchore: Release Turborepo 2.10.11-canary.4 (#13759)45a87a0fix: Respect gitignore without git metadata (#13756)0b501f1chore: Forbid release-age exclusions in examples maintenance (#13751)3f64c07fix: Isolate concurrent generator config bundles (#13750)b08ab5fchore: Release Turborepo 2.10.11-canary.3 (#13749)b4bd235feat: Cache native uv tool tasks (#13748)Updates
vitestfrom 4.1.10 to 4.1.11Release notes
Sourced from vitest's releases.
Commits
9bd8d46chore: release v4.1.11 (#10995)9851dbcfix(browser): trigger playwright/chromium gc on lower disk availability [back...Updates
@hono/node-serverfrom 2.0.10 to 2.1.1Release notes
Sourced from @hono/node-server's releases.
Commits
73c03ad2.1.15515aa0perf: lazily materialize request headers (#389)82ba34e2.1.01f2909afix(listener): avoid uncaught error when force-closing a non-standard socket ...977a242feat: add Early Hints (HTTP 103) middleware (#378)a813b6c2.0.12caf48bafix(response): copy headers when init is a foreign Response (#382)3b1dd68test: replace supertest (#379)834e54f2.0.11ba72bcdperf(request): fast-path PATCH method (#380)Updates
@langchain/corefrom 1.2.3 to 1.2.9Release notes
Sourced from @langchain/core's releases.
Commits
e493ed6chore: version packages (#11393)8384848fix(google-common): release endpoint routing fix as patch (#11413)8cfff4dfeat(google): add gateway support for genai (#11405)7df258cchore(langchain): update langgraph deps (#11412)3ceef4bfix(anthropic): round-trip tool search server-tool result blocks (#11407)fe8eec1fix(openai): drop Gemini functionCall content blocks in Chat Completions mess...0e7c765fix(google-genai): throw ContentBlockedError when Gemini candidate has no con...5c9fdf2fix(openai): retain cache_write_tokens, update to v7 sdk (#11399)5ff9179fix(google-genai): guard streaming chunks when candidate has no content (#10742)43e4396fix(core): include tool_call blocks and skip empty text blocks in ChatVertexA...Updates
@langchain/openaifrom 1.5.5 to 1.5.10Release notes
Sourced from @langchain/openai's releases.
Commits
d5264a1chore: version packages (#11427)c26c87efix(openai): send content null (not []) for tool-call-only v1 assistant messa...041a755fix(anthropic): preserve generic tool_search_tool_result blocks (#11421)e493ed6chore: version packages (#11393)8384848fix(google-common): release endpoint routing fix as patch (#11413)8cfff4dfeat(google): add gateway support for genai (#11405)7df258cchore(langchain): update langgraph deps (#11412)3ceef4bfix(anthropic): round-trip tool search server-tool result blocks (#11407)fe8eec1fix(openai): drop Gemini functionCall content blocks in Chat Completions mess...0e7c765fix(google-genai): throw ContentBlockedError when Gemini candidate has no con...Updates
better-authfrom 1.6.23 to 1.7.1Release notes
Sourced from better-auth's releases.
... (truncated)
Changelog
Sourced from better-auth's changelog.
... (truncated)
Commits
2344536chore: release v1.7.1 (#10864)845bbd1fix(db): refuse adding required no-default columns to populated tables (#10863)ccd57c2docs(changelog): align v1.7 release notes with final behavior (#10846)f577ec5chore: exit pre-release mode for v1.7.069258d1chore: sync main to nexte84ec5echore: release v1.6.30 (#10840)bc93b27chore: release v1.7.0-rc.6 (#10772)58c49ebchore: release v1.6.29 (Cursor Bugbot for commit ece1218. Bugbot is set up for automated code reviews on this repo. Configure here.