Skip to content

deps: periodic dependency and security updates - #6287

Merged
qw-in merged 4 commits into
mainfrom
quinn/dependency-update
Sep 15, 2026
Merged

qw-in merged 4 commits into
mainfrom
quinn/dependency-update

Conversation

@qw-in

@qw-in qw-in commented Sep 15, 2026

Copy link
Copy Markdown
Member

Update dependencies, audit "overrides", and patch resolvable security notices.

#6286 & #6285 were split out

@qw-in qw-in self-assigned this Sep 15, 2026
@qw-in
qw-in requested a review from a team as a code owner September 15, 2026 21:43

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟡 Medium Risk

Decision: Needs Review

Rationale: This PR is composed entirely of dependency, override, and toolchain pin changes across many workspace package.json files, including removal of numerous root overrides and restoration of scoped minimum-version overrides. The dependency-changes escalation trigger fires. I did not find hardcoded secrets, auth changes, injection risks, or direct application-code security issues in the diff. However, because the changes alter supply-chain controls broadly and no lockfile changes are visible in the provided files changed list, human review should verify the effective dependency graph and confirm the intended security advisory remediation is actually reflected in install resolution.

Summary of Changes

Updates npm from 12.0.1 to 12.0.2 in the pinned action and root packageManager, bumps many devDependencies such as tsdown, framework/tooling packages, and turbo, removes many broad root overrides, and replaces some overrides with scoped minimum-version overrides for cookie, undici, and sharp.

Escalation Triggers

  • Dependency Changes: The PR changes many package.json files, including root devDependencies, workspace devDependencies, packageManager, and npm overrides.

Review Focus Areas

Notes

Path filtering: 1 file excluded by ignore paths. 38 of 39 files included in review.

Review: 4583a932 | Model: openai/gpt-5.5 | Powered by Arcjet Review

@socket-security

socket-security Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

@arcjet-review arcjet-review Bot added needs review Awaiting human review and removed ai-review-in-progress labels Sep 15, 2026
@arcjet-review arcjet-review Bot added ready Ready to merge and removed needs review Awaiting human review labels Sep 15, 2026
@qw-in
qw-in added this pull request to the merge queue Sep 15, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 15, 2026
qw-in and others added 4 commits September 15, 2026 15:11
Every entry in the root overrides block already resolves to the pinned
version on its own — removing the block produces a byte-identical
package-lock.json. adm-zip, fast-uri, nanoid, postcss, sharp, svgo, and
uuid all already satisfy their pin naturally; @nosecone/sveltekit's
nested @sveltejs/kit/cookie pin and miniflare's nested undici pin are
likewise already met without forcing; rolldown-plugin-dts's typescript
pin is unneeded; rollup: npm:@rollup/wasm-node was vestigial, since
rollup isn't in the tree at all anymore, aliased or not; and
@anthropic-ai/sdk / @bufbuild/protobuf both already match what
@arcjet/guard, transport, protocol, and arcjet request directly in
their own manifests.

That last pair is worth watching: they exist to route around
optional-peer version collisions between @arcjet/guard's bundled AI
framework integrations (@strands-agents/sdk wants openai ^6.x while
@openai/agents wants ^7.x; @google/adk's transitive
opentelemetry-exporter range collides with genkit's), both pre-existing
and independent of any version bump. They're redundant only because
nothing on this branch has moved those two versions yet — a future bump
of either without updating (or dropping) a same-named override would
silently re-pin the old version underneath it, which is exactly what
happened upstream before this cleanup. Revisit deliberately when that
bump happens, rather than re-adding the override reflexively.

Verified: lint, format, and typecheck are clean; tests pass for every
package except @arcjet/transport and its dependents, which hit a
pre-existing, unrelated hang in that package's own test suite (already
being fixed separately).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Safe subset of the periodic dependency update: tsdown 0.22.14 -> 0.23.0
across all 36 packages, turbo 2.10.10 -> 2.10.12, npm 12.0.1 -> 12.0.2
(and .github/actions/pin-npm/action.yml synced to match, which
otherwise hardcodes the version separately and would desync CI), and
framework-adjacent devDependencies: astro, bun-types, undici-types,
fastify, @nestjs/common, next (arcjet-next and nosecone-next),
react-router, @sveltejs/kit/svelte/vite (nosecone-sveltekit), rolldown
(arcjet), and @tanstack/intent (arcjet-guard and arcjet-skills).

Deliberately excludes @arcjet/guard's bundled AI framework
devDependencies (@strands-agents/sdk, @openai/agents, @mastra/core,
@langchain/langgraph, @tanstack/ai, ai, eve, genkit, @google/adk,
@anthropic-ai/sdk, @anthropic-ai/claude-agent-sdk,
@ai-sdk/provider-utils) — those carry the optional-peer collisions the
removed root overrides were papering over, and need their own pass.
Also excludes @bufbuild/protobuf and @connectrpc/* (bumped alongside the
transport HTTP/2 test fix) and oxlint/oxfmt/oxlint-tsgolint (bumped
alongside the lint config unification).

Verified: build, lint, and format are clean; typecheck passes for all
55 typecheck targets; tests pass for every package except
@arcjet/transport and its dependents, which hit the pre-existing,
unrelated hang in that package's own test suite (fixed separately).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…523-8j87)

Transitive via astro's own ^4.0.1 range, which already permitted 4.1.0 —
it was just never re-resolved after the root override pinning it to
4.0.2 was removed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
GHSA-pxg6-pf52-xh8x (cookie), GHSA-8xcm-r25x-g524 /
GHSA-4cwx-7wf7-3272 / GHSA-m8rv-5g2x-5cg5 / GHSA-jr45-8vmc-qm54 /
GHSA-v3r7-h72x-cjcm (undici), GHSA-f88m-g3jw-g9cj /
GHSA-rgj7-g3m4-5g8c (sharp)

All three were among the overrides removed as redundant earlier in this
branch — correctly so at the time, since nothing had bumped their
consumers yet. They're live again: `@sveltejs/kit@2.70.3` hard-caps
cookie at `^0.6.0` (vulnerable), `miniflare@4.20260730.0` exact-pins
`undici@7.28.0` (vulnerable) and `sharp@0.35.2` (vulnerable), and
`@huggingface/transformers@4.2.0` caret-pins `sharp@^0.34.5` (also
vulnerable) — none of the three can clear their own advisory without
forcing past a range their parent declares.

Scoped rather than blanket: each override targets only the specific
parent that actually needs forcing (`@huggingface/transformers` and
`miniflare` for sharp, `@nosecone/sveltekit` → `@sveltejs/kit` for
cookie), not every package in the tree. astro and next already resolve
sharp to 0.35.4 on their own and are left alone. Floor ranges
(`>=x`) rather than exact pins, so a dedup that already lands on
something newer/safer elsewhere in the tree isn't flagged as a
mismatch by `npm ls`.

Landing this needed more than editing package.json: `npm install`
alone doesn't retroactively re-resolve nested lockfile entries that
predate an override change, so the three affected nested entries
(miniflare's sharp and undici, @huggingface/transformers's sharp and
its per-platform binaries, nosecone-sveltekit's cookie) had to be
deleted from package-lock.json's `packages` map directly before
`npm install` would honor the new ranges there.

`npm audit`: 65 -> 57 (low 2 -> 0, high 13 -> 6). `npm ls` is clean
(exit 0, no invalid/extraneous entries) for all three packages.
Verified: lint and typecheck clean; sensitive-info-rampart (the
@huggingface/transformers consumer) 41/41; full suite 21/21 excluding
@arcjet/transport and its dependents, which hit the pre-existing,
unrelated hang fixed separately.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@qw-in
qw-in force-pushed the quinn/dependency-update branch from 8ec6fe7 to 1555bc5 Compare September 15, 2026 22:14
@qw-in
qw-in enabled auto-merge September 15, 2026 22:15
@qw-in
qw-in added this pull request to the merge queue Sep 15, 2026
@arcjet-review arcjet-review Bot removed the ready Ready to merge label Sep 15, 2026
Merged via the queue into main with commit b3336b0 Sep 15, 2026
45 of 46 checks passed
@qw-in
qw-in deleted the quinn/dependency-update branch September 15, 2026 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants