Skip to content

Commit 9641e29

Browse files
committed
fix(security): address Dependabot vulnerabilities
- Upgrade lodash 4.17.21 → 4.17.23 (fixes prototype pollution in _.unset/_.omit) - Upgrade diff 8.0.2 → 8.0.3 (fixes DoS in parsePatch/applyPatch) - Upgrade ai 5.0.0 → 5.0.52 (fixes file type whitelist bypass) - Add @ai-sdk/provider and @ai-sdk/provider-utils overrides to fix version conflicts Closes 11 Dependabot alerts (4 medium lodash, 4 low diff, 3 low ai)
1 parent c9e4927 commit 9641e29

File tree

4 files changed

+34
-32
lines changed

4 files changed

+34
-32
lines changed

bun.lock

Lines changed: 26 additions & 26 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

common/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,9 +26,9 @@
2626
"@types/pg": "^8.11.10",
2727
"@types/readable-stream": "^4.0.18",
2828
"@types/seedrandom": "^3.0.8",
29-
"ai": "^5.0.0",
29+
"ai": "^5.0.52",
3030
"ignore": "5.3.2",
31-
"lodash": "4.17.21",
31+
"lodash": "4.17.23",
3232
"next-auth": "^4.24.11",
3333
"partial-json": "^0.1.7",
3434
"pg": "^8.14.1",

package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,9 @@
4343
"overrides": {
4444
"baseline-browser-mapping": "^2.9.14",
4545
"zod": "^4.2.1",
46-
"signal-exit": "3.0.7"
46+
"signal-exit": "3.0.7",
47+
"@ai-sdk/provider": "2.0.1",
48+
"@ai-sdk/provider-utils": "3.0.20"
4749
},
4850
"devDependencies": {
4951
"@tanstack/react-query": "^5.90.12",
@@ -59,7 +61,7 @@
5961
"eslint-plugin-import": "^2.29.1",
6062
"eslint-plugin-unused-imports": "^4.1.4",
6163
"ignore": "^6.0.2",
62-
"lodash": "4.17.21",
64+
"lodash": "4.17.23",
6365
"prettier": "^3.7.4",
6466
"ts-node": "^10.9.2",
6567
"ts-pattern": "^5.5.0",

sdk/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,8 @@
6161
"@ai-sdk/anthropic": "2.0.50",
6262
"@jitl/quickjs-wasmfile-release-sync": "0.31.0",
6363
"@vscode/tree-sitter-wasm": "0.1.4",
64-
"ai": "^5.0.0",
65-
"diff": "8.0.2",
64+
"ai": "^5.0.52",
65+
"diff": "8.0.3",
6666
"ignore": "7.0.5",
6767
"micromatch": "^4.0.8",
6868
"web-tree-sitter": "0.25.6",

0 commit comments

Comments
 (0)