Skip to content

chore(deps): refresh lockfile transitives; clears hono/fast-uri/ip-address advisories - #2

Merged
idapixl merged 1 commit into
masterfrom
chore/security-audit-fix-2026-09-07
Sep 7, 2026
Merged

chore(deps): refresh lockfile transitives; clears hono/fast-uri/ip-address advisories#2
idapixl merged 1 commit into
masterfrom
chore/security-audit-fix-2026-09-07

Conversation

@idapixl

@idapixl idapixl commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Last tools-* repos on the July lockfile (hono 4.12.28, fast-uri 3.1.2, ip-address 10.2.0) — the exact versions behind tools-cognition's 21 open Dependabot alerts, while these repos reported zero despite alerts being enabled. Detection gap, not a clean bill of health.

npm update → hono 4.13.7, fast-uri 3.1.7, ip-address 10.7.0, cortex-engine 1.2.2→1.4.1.

Verified locally: npm audit 0 vulnerabilities, tsc builds clean on the new engine.

All of these are devDependencies — the published tarballs declare no runtime dependencies, so no npm consumer was ever exposed.

…dress advisories

These five repos were the only tools-* repos left on the July lockfile
(hono 4.12.28, fast-uri 3.1.2, ip-address 10.2.0) - the exact versions
that generate 21 open Dependabot alerts on tools-cognition, yet these
repos reported zero. Alerts are enabled here, so the silence was a
detection gap, not a clean bill of health.

npm update pulls hono 4.13.7, fast-uri 3.1.7, ip-address 10.7.0 and
cortex-engine 1.2.2 -> 1.4.1. npm audit: 0 vulnerabilities. tsc builds
clean on the new engine. All deps are devDependencies - the published
tarballs carry no runtime deps, so no user was ever exposed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 7, 2026 16:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@idapixl
idapixl merged commit 12f547d into master Sep 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants