Skip to content

fix(deps): patch tmp & js-yaml in mcp-server (Dependabot #58/#59/#71) - #3412

Merged
Marfuen merged 2 commits into
mainfrom
mariano/fix-mcp-server-dependabot
Jul 15, 2026
Merged

Marfuen merged 2 commits into
mainfrom
mariano/fix-mcp-server-dependabot

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Clears the 3 open Dependabot alerts, all in apps/mcp-server/package-lock.json (a standalone npm project, excluded from the bun workspaces). All are dev-scope transitives.

Alert Sev Package Via Fix
#59 High tmp (path traversal via prefix/postfix) external-editor → tmp@0.0.33 tmp ≥ 0.2.6
#58 Low tmp (symlink dir write) same tmp ≥ 0.2.6
#71 Moderate js-yaml (quadratic-complexity DoS) @eslint/eslintrc → js-yaml@4.1.1 js-yaml ≥ 4.2.0

Fix

Added two overrides in apps/mcp-server/package.json, caret-pinned to stay within the safe major:

"tmp": "^0.2.6",       // → 0.2.7
"js-yaml": "^4.2.0"    // → 4.3.0
  • js-yaml deliberately capped at ^4.2.0. An open >=4.2.0 floats to v5.2.1, but @eslint/eslintrc declares ^4.1.1 — forcing an unvetted v5 major onto it is risky, and 4.3.0 already clears the DoS while satisfying eslintrc.
  • tmp ^0.2.6 → 0.2.7. external-editor requests ^0.0.33, but tmp's fileSync API is stable across the jump and it's dev-only (interactive editor prompts in @anthropic-ai/mcpb).

Verification

  • ✅ npm audit — 0 vulnerabilities
  • ✅ npm run build (bun bundle + tsc) passes
  • ✅ npm run lint (eslint, which consumes js-yaml) passes
  • Only package.json + package-lock.json change. bun.lock is gitignored and re-migrated from package-lock.json at build, so it inherits the patched versions.

🤖 Generated with Claude Code


Summary by cubic

Patches dev transitive dependencies in apps/mcp-server to clear 3 Dependabot alerts. Uses npm overrides for tmp and js-yaml; no runtime changes, and build/lint/audit all pass.

  • Dependencies
    • Added overrides in apps/mcp-server/package.json.
    • tmp: ^0.2.6 → resolves to 0.2.7 (fixes path traversal/symlink issues via external-editor).
    • js-yaml: ^4.2.0 → resolves to 4.3.0 under @eslint/eslintrc (fixes DoS; stays on 4.x to avoid unvetted 5.x).
    • Verified: npm audit 0; build and lint pass.

Written for commit 9d364b2. Summary will update on new commits.

Review in cubic

apps/mcp-server is a standalone npm project (excluded from the bun
workspaces). Three open Dependabot alerts, all dev-scope transitives:
- #59 (high) + #58 (low): tmp path traversal / symlink write — tmp@0.0.33
  via external-editor; patched in tmp>=0.2.6
- #71 (moderate): js-yaml quadratic-complexity DoS — js-yaml@4.1.1 via
  @eslint/eslintrc; patched in js-yaml>=4.2.0

Add npm overrides (caret-pinned to stay within the safe major):
- tmp ^0.2.6  -> resolves 0.2.7 (fileSync API is stable, external-editor works)
- js-yaml ^4.2.0 -> resolves 4.3.0 (satisfies eslintrc's ^4.1.1; NOT floated to
  v5, which would be an unvetted breaking major)

Verified: npm audit 0 vulnerabilities; mcp-server build + lint pass.
(bun.lock is gitignored and regenerated from package-lock.json at build.)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 2:55pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 2:55pm
portal Ready Ready Preview, Comment Jul 15, 2026 2:55pm

Request Review

@vercel
vercel Bot temporarily deployed to Preview – portal July 15, 2026 14:52 Inactive
@Marfuen
Marfuen merged commit 59a6b0f into main Jul 15, 2026
8 of 9 checks passed
@Marfuen
Marfuen deleted the mariano/fix-mcp-server-dependabot branch July 15, 2026 14:54
claudfuen pushed a commit that referenced this pull request Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15)

### Bug Fixes

* **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024))
* **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd))
* **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c))
* **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f))
* **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37))
* **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c))
* **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b))
* **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116)
* **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85)

### Features

* **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

2 active and 1 inactive deployments
Preview – app — 9d364b25 Deployed Jul 15, 2026 by vercel[bot]
Preview – comp-framework-editor — 9d364b25 Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — 9d364b25 Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants