Skip to content

fix: pass security audit by patching vulnerable dependencies#24

Draft
cursor[bot] wants to merge 1 commit intomainfrom
cursor/ci-branch-failures-b31b
Draft

fix: pass security audit by patching vulnerable dependencies#24
cursor[bot] wants to merge 1 commit intomainfrom
cursor/ci-branch-failures-b31b

Conversation

@cursor
Copy link
Copy Markdown

@cursor cursor bot commented Mar 30, 2026

Summary

  • upgrade @modelcontextprotocol/sdk to ^1.28.0
  • upgrade direct yaml dependency to ^2.8.3
  • add pnpm.overrides for hono (^4.12.9) and path-to-regexp (^8.4.0) to force patched transitive versions
  • regenerate pnpm-lock.yaml

Validation

  • pnpm audit --prod now reports: No known vulnerabilities found
Open in Web View Automation 

Co-authored-by: Dylan Boudro <starmorph@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant