Skip to content

fix(deps): resolve high and critical npm advisories (SEC-213) - #1123

Open
Uneven-Ben wants to merge 1 commit into
relayprotocol:mainfrom
Uneven-Ben:sec-213
Open

fix(deps): resolve high and critical npm advisories (SEC-213)#1123
Uneven-Ben wants to merge 1 commit into
relayprotocol:mainfrom
Uneven-Ben:sec-213

Conversation

@Uneven-Ben

@Uneven-Ben Uneven-Ben commented Sep 7, 2026

Copy link
Copy Markdown

SEC-213 dependency fix: relay-kit (2026-09-07)

Scope and base

  • Repository: the relay-kit repository (origin https://github.com/relayprotocol/relay-kit.git, branch main).
  • Worktree: a dedicated work branch checkout, branch sec-213, created from origin/main.
  • Base commit: 79ae537c46a835af106a7660c4bc9997e2c01d06 (Version Packages (Release the: Zippy Sloth! #1122), 2026-09-03).
  • Package manager: pnpm 10.33.0 (packageManager field, pnpm-lock.yaml v9), run via corepack inside node:22 Docker. Engines declare node ^24.x; pnpm emitted a non-fatal engine warning under node 22. Workspace enforces minimumReleaseAge: 10080 (7 days); every version chosen below clears it.
  • Existing checkout: git fetch origin --prune run. git pull --ff-only was NOT run because the checkout has a modified tracked file (CLAUDE.md); it sits on main, 4 commits behind origin/main, untouched.
  • Raw audits: relay-kit_audit_before_2026-09-07.json (133 high, 6 critical, 152 moderate, 23 low) and relay-kit_audit_after_2026-09-07.json (2 high, 1 critical, 26 moderate, 5 low). Counts are advisory entries as pnpm reports them (one entry per advisory per affected version range), not distinct packages.

Advisories before (high and critical, grouped by package)

32 distinct packages, 139 advisory entries.

Package Severity Entries GHSA ids Vulnerable versions present Patched
@hpke/core critical (some high) 1 GHSA-73g8-5h73-26h4 1.7.1 >=1.7.5
axios high 25 GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw, GHSA-43fc-jf86-j433, GHSA-4hjh-wcwx-xvwj, GHSA-6chq-wfr3-2hj9, GHSA-777c-7fjr-54vf, GHSA-gcfj-64vw-6mp9, GHSA-hfxv-24rg-xrqf, GHSA-j5f8-grm9-p9fc, GHSA-jr5f-v2jv-69x6, GHSA-p92q-9vqr-4j8v, GHSA-pf86-5x62-jrwf, GHSA-pjwm-pj3p-43mv, GHSA-pmwg-cvhr-8vh7, GHSA-q8qp-cvcw-x6jj 0.27.2, 1.12.0, 1.12.2, 1.15.2, 1.16.0, 1.7.9 >=0.30.0; >=0.30.3; >=0.31.1; >=0.32.0; >=1.12.0; >=1.13.5; >=1.15.1; >=1.15.2; >=1.16.0; >=1.18.0; >=1.8.2
base-x high 3 GHSA-xq7p-g2vc-g82p 3.0.10, 4.0.0, 5.0.0 >=3.0.11; >=4.0.1; >=5.0.1
bigint-buffer high 1 GHSA-3gc7-fjrx-p6mg 1.1.5 <0.0.0
brace-expansion high 6 GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 1.1.11, 2.0.1 >=1.1.16; >=1.1.17; >=1.1.18; >=2.1.2; >=2.1.3; >=2.1.4
defu high 1 GHSA-737v-mqg7-c878 6.1.4 >=6.1.5
effect high 1 GHSA-38f7-945m-qr2g 3.17.13 >=3.20.0
elliptic critical (some high) 1 GHSA-vjh7-7g9h-fjfh 6.5.4 >=6.6.1
flatted high 2 GHSA-25h7-pfq9-p65f, GHSA-rf6f-7fwh-wjgh 3.3.3 >=3.4.0; >=3.4.2
form-data critical (some high) 2 GHSA-fjxv-7rqg-78g4, GHSA-hmw2-7cc7-3qxx 4.0.2, 4.0.4, 4.0.5 >=4.0.4; >=4.0.6
glob high 1 GHSA-5j98-mcp5-4vw2 10.4.5 >=10.5.0
h3 high 2 GHSA-22cc-p3c6-wpvm, GHSA-mp2g-9vg9-f4cg 1.15.0 >=1.15.5; >=1.15.6
js-yaml high 4 GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj 3.14.1, 4.1.0 >=3.15.0; >=3.15.1; >=4.3.0; >=4.3.1
lodash high 1 GHSA-r5fr-rjxr-66jc 4.17.21 >=4.18.0
lodash-es high 1 GHSA-r5fr-rjxr-66jc 4.17.21 >=4.18.0
minimatch high 6 GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj 3.1.2, 9.0.5 >=3.1.3; >=3.1.4; >=9.0.6; >=9.0.7
nanoid high 3 GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, GHSA-xwg4-73v4-xw9w 3.3.11, 3.3.8 >=3.3.12; >=3.3.16; >=3.3.18
next high 12 GHSA-267c-6grr-h53f, GHSA-26hh-7cqf-hhc6, GHSA-36qx-fr4f-26g5, GHSA-492v-c6pp-mqqv, GHSA-89xv-2m56-2m9x, GHSA-8h8q-6873-q5fj, GHSA-c4j6-fc7j-m34r, GHSA-h25m-26qc-wcjf, GHSA-m99w-x7hq-7vfj, GHSA-mg66-mrh9-m8jx, GHSA-p9j2-gv94-2wf4, GHSA-q4gf-8mx6-v5v3 15.5.9 >=15.5.10; >=15.5.15; >=15.5.16; >=15.5.18; >=15.5.21
path-to-regexp high 1 GHSA-37ch-88jc-xwx2 0.1.12 >=0.1.13
picomatch high 2 GHSA-c2c7-rcm5-vvqj 2.3.1, 4.0.3 >=2.3.2; >=4.0.4
postcss high 2 GHSA-6g55-p6wh-862q, GHSA-r28c-9q8g-f849 8.4.31, 8.5.3, 8.5.8 >=8.5.12; >=8.5.18
rollup high 1 GHSA-mw96-cpmx-2vgc 4.34.8 >=4.59.0
sha.js critical (some high) 1 GHSA-95m3-7q98-8xr5 2.4.11 >=2.4.12
sharp high 1 GHSA-f88m-g3jw-g9cj 0.33.5, 0.34.3 >=0.35.0
shell-quote critical (some high) 2 GHSA-395f-4hp3-45gv, GHSA-w7jw-789q-3m8p 1.8.2 >=1.8.4; >=1.9.0
socket.io-parser high 2 GHSA-2m8v-j782-fhvr, GHSA-677m-j7p3-52f9 4.2.4 >=4.2.6; >=4.2.7
tmp high 1 GHSA-ph9p-34f9-6g65 0.0.33 >=0.2.6
undici high 3 GHSA-v9p9-hfj2-hcw8, GHSA-vrm6-8vpv-qv8q, GHSA-vxpw-j846-p89q 5.28.5 >=6.24.0; >=6.27.0
valibot high 1 GHSA-vqpr-j7v3-hqw9 1.1.0 >=1.2.0
vite high 1 GHSA-fx2h-pf6j-xcff 5.4.14 >=6.4.3
vitest critical (some high) 1 GHSA-5xrq-8626-4rwp 1.6.1 >=3.2.6
ws high 3 GHSA-3h5v-q93c-6h6q, GHSA-96hv-2xvq-fx4p 7.4.6, 7.5.10, 8.17.1, 8.18.0, 8.18.1, 8.18.2, 8.18.3, 8.20.1 >=7.5.10; >=7.5.11; >=8.21.0

Advisories after

GHSA Package Severity Present Patched Why still open
GHSA-3gc7-fjrx-p6mg bigint-buffer high 1.1.5 none published Upstream has no fix; reached only via demo > @dynamic-labs/bitcoin > ... > @solana/buffer-layout-utils. Not shipped in any published package.
GHSA-5xrq-8626-4rwp vitest critical 1.6.1 >=3.2.6 Direct devDependency (^1.6.0) of packages/sdk and packages/relay-lighter-wallet-adapter. Fix requires a 1.x to 3.x major bump; left for review. Dev-only test runner, advisory needs the Vitest UI server listening.
GHSA-fx2h-pf6j-xcff vite high 5.4.14 >=6.4.3 Transitive of vitest 1.x, which pins vite ^5. Resolves with the vitest major bump above.

Changes made (all staged, not committed)

Direct dependency bumps (manifests):

Manifest Package Before After Note
packages/hooks/package.json axios ^1.7.2 ^1.18.0 resolves 1.20.0
packages/ui/package.json axios ^1.7.2 ^1.18.0 resolves 1.20.0
packages/ui/package.json postcss (dev) ^8 ^8.5.18 resolves 8.5.26
packages/sdk/package.json axios ^1.6.5 ^1.18.0 resolves 1.20.0
packages/relay-tron-wallet-adapter/package.json axios ^1.6.5 ^1.18.0 resolves 1.20.0
packages/relay-bitcoin-wallet-adapter/package.json axios ^1.6.5 ^1.18.0 resolves 1.20.0
packages/relay-svm-wallet-adapter/package.json axios ^1.6.5 ^1.18.0 resolves 1.20.0
packages/relay-ethers-wallet-adapter/package.json axios ^0.27.2 ^0.33.0 0.x line kept; 0.32.0 carries GHSA-gcfj-64vw-6mp9 so 0.33.0 is the first clean 0.x. Nothing in this package's source imports axios; reviewers may prefer to delete the dependency.
demo/package.json next 15.5.9 15.5.21 exact pin kept

Transitive overrides (root package.json, resolutions block, which pnpm reads as overrides; the block already held @solana/web3.js and tronweb). pnpm update --recursive --depth Infinity <pkg> was tried first and did not move any of these (several are pinned exactly by their dependents: ethers v5 pins ws 7.4.6 and elliptic 6.5.4, express pins path-to-regexp 0.1.12, next pins postcss 8.4.31), so overrides were added. Selectors are scoped per major where more than one major line exists.

Override Target Resolved Dependents affected
axios@^1.0.0 ^1.18.0 1.20.0 @sats-connect/core, @ton/ton, @dynamic-labs-wallet/core (demo)
base-x@^3.0.0 / @^4.0.0 / @^5.0.0 ^3.0.11 / ^4.0.1 / ^5.0.1 3.0.11 / 4.0.1 / 5.0.1 bs58 (demo)
brace-expansion@^1.0.0 / @^2.0.0 ^1.1.18 / ^2.1.4 1.1.18 / 2.1.4 minimatch (eslint tooling)
defu ^6.1.5 6.1.7 h3 (demo)
effect ^3.20.0 3.22.1 porto (demo)
elliptic ^6.6.1 6.6.1 @ethersproject/signing-key (ethers adapter)
flatted ^3.4.2 3.4.4 flat-cache (eslint tooling)
glob@^10.0.0 ^10.5.0 10.5.0 rimraf 5
h3 ^1.15.6 1.15.11 unstorage (demo)
@hpke/core ^1.7.5 1.9.0 hpke-js (demo)
js-yaml@^3.0.0 / @^4.0.0 ^3.15.1 / ^4.3.1 3.15.2 / 4.3.2 @changesets/parse, openapi-typescript
lodash ^4.18.0 4.18.1 concurrently
lodash-es ^4.18.0 4.18.1 formik (demo)
minimatch@^3.0.0 / @^9.0.0 ^3.1.4 / ^9.0.7 3.1.5 / 9.0.9 eslint, @typescript-eslint
nanoid@^3.0.0 ^3.3.18 3.3.18 postcss
path-to-regexp@^0.1.0 ^0.1.13 0.1.13 express (demo, next-remote-watch)
picomatch@^2.0.0 / @>=3.0.0 ^2.3.2 / ^4.0.4 2.3.2 / 4.0.7 micromatch, @parcel/watcher
postcss ^8.5.18 8.5.26 next, vite, packages/ui
rollup ^4.59.0 4.63.1 vite
sharp ^0.35.0 0.35.4 next (optional dep, was ^0.34.3), @dynamic-labs/iconic (was 0.33.5). Demo only.
shell-quote ^1.9.0 1.10.0 concurrently
socket.io-parser ^4.2.7 4.2.7 socket.io-client (demo)
tmp ^0.2.6 0.2.7 external-editor (changesets CLI); crosses 0.0.x to 0.2.x, dev tooling only
undici ^6.27.0 6.28.0 openapi-typescript 6 (declares ^5); dev-only syncSdkTypes script. Alternative is openapi-typescript 7.x, a major bump of a direct devDependency, left for review.
valibot ^1.2.0 1.2.0 sats-connect (demo)
ws@^7.0.0 / @^8.0.0 ^7.5.11 / ^8.21.0 7.5.13 / 8.21.3 @ethersproject/providers (ethers adapter), viem, ably, walletconnect, metamask, tronweb > ethers

sha.js moved 2.4.11 to 2.4.12 and form-data to 4.0.6 through normal re-resolution, no override needed.

Lockfile scope check: every added or removed entry in pnpm-lock.yaml traces to one of the packages above or to their own dependency trees (sharp and rollup platform binaries, undici 6 dropping @fastify/busboy, tmp 0.2 dropping os-tmpdir, sharp 0.35 replacing color/color-string/simple-swizzle with @img/colour, h3 1.15.11 pulling newer ufo/destr/crossws/cookie-es, axios 1.20 adding https-proxy-agent, next 15.5.21 swc binaries). No unrelated package changed.

Unfixable or deferred for review

  1. vitest 1.6.1 (packages/sdk, packages/relay-lighter-wallet-adapter, devDependency ^1.6.0): GHSA-5xrq-8626-4rwp needs >=3.2.6, a two-major bump that changes config and API. Dev-only; the advisory requires the Vitest UI server to be listening. Bring vite 5.4.14 (GHSA-fx2h-pf6j-xcff) along when this is done.
  2. bigint-buffer 1.1.5 (demo, via @dynamic-labs/bitcoin and @solana/spl-token): GHSA-3gc7-fjrx-p6mg has no patched release. Not in any published package.
  3. Peer-dependency warnings printed by pnpm for the demo (viem 2.29.4 against @dynamic-labs and porto peers, @ton/core 0.61.0, react 19 against valtio) are pre-existing in the base lockfile and untouched.

Sanity checks

  • pnpm install --frozen-lockfile (full install, node:22 container): passed, 40s. Native builds for bigint-buffer, esbuild, sharp, keccak completed.
  • pnpm run build (sdk, hooks, ui including its prebuild lint, ethers, svm, bitcoin, tron, ton, lighter adapters): passed, exit 0, well inside the 10 minute cap.
  • Post-change frozen consistency check (pnpm install --frozen-lockfile --lockfile-only) after the final manifest tidy: passed.
  • Root pnpm typecheck (tsc --noEmit on the root tsconfig): fails with 7 errors in packages/ui (TS2686 React UMD global, TS7022 implicit any in useCodexBalances.ts). These are unrelated to the changed dependencies and the ui package's own tsc build passed; CI runs pnpm build and pnpm lint, not the root typecheck. Not verified against base by a base install, so treat as likely pre-existing.
  • Skipped: pnpm run -C packages/sdk test (vitest suite, run by CI), demo Next.js build, lint outside the ui prebuild.

Notes for the PR

  • Published packages (sdk, hooks, ui, six adapters) have dependency changes; the repo releases via changesets. Add a patch changeset if the fix should ship to npm consumers (.changeset/*.md, prose or [internal] opener passes scripts/lint-changesets.mjs).
  • The ethers adapter's axios dependency appears unused; deleting it is cleaner than carrying ^0.33.0.
  • sharp 0.35 under next 15.5 is only exercised by the demo image pipeline; run the demo once before merging if that matters.

Commands for the human

gh pr create --base main --head sec-213 --title "fix(deps): resolve high and critical npm advisories (SEC-213)" --body "Bumps axios, next and postcss to patched versions and adds scoped pnpm overrides for transitive advisories (ws, elliptic, sharp, undici, path-to-regexp and others), taking pnpm audit from 133 high and 6 critical entries to 2 high and 1 critical. Remaining entries are vitest 1.x (major bump deferred for review) and bigint-buffer (no upstream fix), both dev or demo only."

Note: the GitHub account in use has read-only access to relayprotocol repos; if the push is rejected, push to a fork and use gh pr create --head <fork-owner>:sec-213 instead.

@vercel

vercel Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

@Uneven-Ben is attempting to deploy a commit to the Uneven Labs Team on Vercel.

A member of the Team first needs to authorize it.

@greptile-apps

greptile-apps Bot commented Sep 7, 2026

Copy link
Copy Markdown

Greptile Summary

Summary

This change updates direct and transitive dependency resolutions for SEC-213, including Axios, Next.js, PostCSS, and scoped pnpm overrides.

A frozen-lockfile installation completed successfully on both the base revision and this change. All seven directly affected packages built successfully, including the UI PostCSS/Tailwind build, and the Lighter wallet adapter suite passed all 21 tests. The SDK gas-estimation test timeouts and the demo build failure caused by an unresolved workspace package occurred on both revisions, so they are not introduced by these dependency updates.

Merge safety: Safe to merge; no defect attributable to this change was found.

Confidence Score: 5/5

The dependency upgrades and overrides are safe to merge based on successful clean installs, builds, and adapter tests.

The frozen lockfile, affected package builds, installed package resolutions, and available adapter behavior were checked on the updated revision, with base-revision comparisons confirming that the observed SDK and demo failures predate this change.

Files Needing Attention: No changed files require follow-up. The pre-existing SDK gas-estimation test timeouts and demo workspace-package resolution failure remain outside the scope of these dependency updates.

T-Rex T-Rex Logs

What T-Rex did

  • Ran pnpm install --frozen-lockfile on both the base revision and the PR, and confirmed both reported a current lockfile and exited successfully.
  • Queried the installed dependency graph and observed Axios 1.20.0, PostCSS 8.5.26, and Next.js 15.5.21.
  • Built all seven changed packages on both revisions; every build succeeded, including the UI PostCSS/Tailwind compilation, and the Lighter adapter suite passed all 21 tests.
  • Ran the SDK suite and the demo build on both revisions; the same two SDK gas-estimation timeouts and the same unresolved Lighter workspace-package demo build failure occurred before and after, indicating no new issues were introduced by this change.

View all artifacts

T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "fix(deps): resolve high and critical npm..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant