Skip to content

fix(deps): bump proxy-addr to 2.0.8 and source-map-js to 1.2.2 - #93

Merged
aaronjmars merged 1 commit into
mainfrom
security/dependabot-bumps-2026-10-10
Oct 10, 2026
Merged

aaronjmars merged 1 commit into
mainfrom
security/dependabot-bumps-2026-10-10

Conversation

@aaronjmars

Copy link
Copy Markdown
Collaborator

Clears both open Dependabot alerts on main.

Package Where From To Advisory
proxy-addr opendia-mcp (via express 5.2.1) 2.0.7 2.0.8 GHSA-jqcg-44mw-7w3h - critical, IP spoofing via IPv4-mapped IPv6 trust subnet
source-map-js opendia-extension (dev only) 1.2.1 1.2.2 GHSA-68fv-2mgg-jv7q - high, event-loop DoS via indexed source-map offsets

Lockfile-only change: both versions are within their parents' existing caret ranges, so no package.json or override edits.

Checked locally after npm ci:

  • opendia-mcp: npm audit reports 0 vulnerabilities; test-config, test-connection, test-helpers, test-protocol all pass
  • opendia-extension: npm run build and node build.js validate pass

Left as is: 3 high findings in opendia-extension from node-forge 1.4.0 (GHSA-86w9-cpqp-85rv) via web-ext's adbkit. Every published node-forge version (latest 1.4.0) is affected, so there is nothing to bump to yet. Dev-only, never shipped in the built extension.

Co-Authored-By: Claude noreply@anthropic.com

- proxy-addr 2.0.7 -> 2.0.8 (opendia-mcp, via express): GHSA-jqcg-44mw-7w3h,
  critical, IP spoofing via IPv4-mapped IPv6 trust subnet
- source-map-js 1.2.1 -> 1.2.2 (opendia-extension, dev only): GHSA-68fv-2mgg-jv7q,
  high, event-loop DoS through indexed source-map section offsets

Lockfile-only: both are in range of their parents' existing caret pins.

Co-Authored-By: Claude <noreply@anthropic.com>
@aaronjmars
aaronjmars merged commit 87e8b00 into main Oct 10, 2026
2 checks passed
@aaronjmars
aaronjmars deleted the security/dependabot-bumps-2026-10-10 branch October 10, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant