Skip to content

fix(deps): override uuid to ^11.1.1 (Dependabot #85) - #3418

Merged
Marfuen merged 1 commit into
mainfrom
mariano/fix-dependabot-bun-residuals
Jul 15, 2026
Merged

Marfuen merged 1 commit into
mainfrom
mariano/fix-dependabot-bun-residuals

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes the one Dependabot alert (of the 8 open bun.lock alerts) that has a safe, published fix and is prod-reachable.

#85 — uuid (medium): uuid < 11.1.1 missing buffer-bounds check in v3/v5/v6 when a buffer is passed. Vulnerable copies: uuid@8.3.2 (via exceljs in @trycompai/api — prod-reachable xlsx export) and uuid@9.0.1 (via @trigger.dev/sdk).

Fix: flat override uuid: ^11.1.1 → resolves to a single uuid@11.1.1. uuid's v1/v3/v4/v5 named API is stable across 8→11 and v11 keeps a dual CJS/ESM build (verified require('uuid').v4 works), so exceljs / @azure/core-http / @trigger.dev/sdk stay drop-in compatible. Caret stops before the still-vulnerable 12.0.0.

Verification

  • ✅ turbo build 20/20 (uuid@11 force-applied to all consumers)
  • ✅ bun audit 15 → 14 (uuid cleared)
  • Only package.json + bun.lock change

The other 7 alerts — no override, by design

Per our policy (bump/override to a published fix, else dismiss-with-rationale — never patch lib source), these have no safe fix and aren't prod-runtime-reachable, so they'll be dismissed with rationale rather than force-overridden:

🤖 Generated with Claude Code


Summary by cubic

Override uuid to ^11.1.1 to resolve the security alert (missing buffer-bounds check) and enforce a single safe version across the repo. No runtime changes; existing uses via exceljs in @trycompai/api and @trigger.dev/sdk stay compatible.

  • Dependencies
    • Add flat override uuid: ^11.1.1 (stays within 11.x; avoids vulnerable 12.0.0).
    • Verified: builds pass; bun audit reduced by 1.

Written for commit 7cfcea2. Summary will update on new commits.

Review in cubic

uuid <11.1.1 has a missing buffer-bounds check in v3/v5/v6 when a buffer
arg is passed (GHSA, medium). Vulnerable copies were uuid@8.3.2 (via exceljs
in @trycompai/api — prod-reachable) and uuid@9.0.1 (via @trigger.dev/sdk).
Add a flat override to ^11.1.1: uuid's v1/v3/v4/v5 named API is stable across
these majors and v11 keeps a dual CJS/ESM build, so exceljs / @azure/core-http
/ @trigger.dev/sdk remain drop-in compatible. Caret stays in 11.x (12.0.0 is
still vulnerable). Resolves to a single uuid@11.1.1.

Verified: turbo build 20/20; bun audit 15 -> 14 (uuid cleared).

The other 7 open bun.lock alerts (minimatch x3, esbuild x2, cookie,
@ai-sdk/provider-utils) have no safe published fix and are not
prod-runtime-reachable -> handled via dismiss-with-rationale, not overrides.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 4:01pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 4:01pm
portal Ready Ready Preview, Comment Jul 15, 2026 4:01pm

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@Marfuen
Marfuen merged commit 598ff8c into main Jul 15, 2026
11 checks passed
@Marfuen
Marfuen deleted the mariano/fix-dependabot-bun-residuals branch July 15, 2026 16:09
claudfuen pushed a commit that referenced this pull request Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15)

### Bug Fixes

* **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024))
* **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd))
* **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c))
* **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f))
* **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37))
* **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c))
* **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b))
* **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116)
* **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85)

### Features

* **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

3 active deployments
Preview – app — 7cfcea21 Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — 7cfcea21 Deployed Jul 15, 2026 by vercel[bot]
Preview – comp-framework-editor — 7cfcea21 Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants