chore(#2496): clear five newly-disclosed production advisories (#2497)

* chore(#2496): clear five newly-disclosed production advisories

The `#3588: npm audit --omit=dev reports zero advisories` gate began
failing mid-release. The v1.8.0 finalize dry run was green at 17:27:27Z;
GHSA-frvp-7c67-39w9 and GHSA-xgm2-5f3f-mvvc published at 18:17:25Z and
18:18:13Z, with fast-uri and two further hono advisories in the same
window. Nothing in the tree changed — the advisory database did.

All five arrive transitively through the one declared dependency
@anthropic-ai/claude-agent-sdk -> @modelcontextprotocol/sdk.

Two-part fix, both following existing repo precedent:

1. `npm audit fix --omit=dev` (no --force) re-resolves fast-uri and hono
   inside their already-declared ranges. package.json untouched — the
   same approach as .changeset/witty-badgers-hum.md (body-parser) and
   .changeset/archived/fix-3588-npm-audit-clean.md. Clears the only high.

2. overrides["@hono/node-server"] = ">=2.0.5" for the remaining chain,
   which cannot resolve in-range (^1.19.9 cannot reach 2.0.5) because
   @modelcontextprotocol/sdk@1.29.0 is already latest and still declares
   the vulnerable range. Extends the block that already pins qs and
   body-parser. Resolves to 2.0.11.

Bumping @anthropic-ai/claude-agent-sdk to ^0.3.x was tested and REJECTED:
0.3.216 moves @modelcontextprotocol/sdk to peerDependencies, which npm
auto-installs, so the chain survives and resolution pulls extra
advisories — 5 vulnerabilities including a high, versus 4 moderate.

Forced major sits under a dependency no tracked source imports (see
src/mcp-server.cts:22 — the JSON-RPC loop is hand-rolled precisely to
avoid the MCP SDK), so runtime risk is minimal. Revisit once upstream
ships a release depending on patched @hono/node-server.

npm audit --omit=dev: found 0 vulnerabilities.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#2496): add changeset fragment for the advisory clearance

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-07-21 18:37:49 -04:00
committed by GitHub
parent 3435218089
commit 360b3ebc5a
3 changed files with 17 additions and 11 deletions

View File

@@ -0,0 +1,5 @@
---
type: Fixed
pr: 2497
---
**Production dependency tree carries no known advisories** — five advisories disclosed against the transitive tree under `@anthropic-ai/claude-agent-sdk` → `@modelcontextprotocol/sdk` were cleared: `fast-uri` (GHSA-4c8g-83qw-93j6, high) and `hono` (GHSA-xgm2-5f3f-mvvc, GHSA-hvrm-45r6-mjfj, GHSA-w62v-xxxg-mg59) re-resolved to patched releases inside their already-declared ranges with no `package.json` change, and `@hono/node-server` (GHSA-frvp-7c67-39w9) pinned to `>=2.0.5` via `overrides` because `@modelcontextprotocol/sdk@1.29.0` — already the latest published version — still declares the vulnerable `^1.19.9` range. `npm audit --omit=dev` reports zero advisories. (#2496)

20
package-lock.json generated
View File

@@ -1098,12 +1098,12 @@
]
},
"node_modules/@hono/node-server": {
"version": "1.19.14",
"resolved": "https://registry.npmjs.org/@hono/node-server/-/node-server-1.19.14.tgz",
"integrity": "sha512-GwtvgtXxnWsucXvbQXkRgqksiH2Qed37H9xHZocE5sA3N8O8O8/8FA3uclQXxXVzc9XBZuEOMK7+r02FmSpHtw==",
"version": "2.0.11",
"resolved": "https://registry.npmjs.org/@hono/node-server/-/node-server-2.0.11.tgz",
"integrity": "sha512-bjD221KPLoJTWUwso1J6fGKiTXEUFedG/s0visavY4zakFPkeGURMRNly+FhBHs7T8Dz4qHaZIMX9ZoJHSJtKA==",
"license": "MIT",
"engines": {
"node": ">=18.14.1"
"node": ">=20"
},
"peerDependencies": {
"hono": "^4"
@@ -3206,9 +3206,9 @@
}
},
"node_modules/fast-uri": {
"version": "3.1.2",
"resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.2.tgz",
"integrity": "sha512-rVjf7ArG3LTk+FS6Yw81V1DLuZl1bRbNrev6Tmd/9RaroeeRRJhAt7jg/6YFxbvAQXUCavSoZhPPj6oOx+5KjQ==",
"version": "3.1.4",
"resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.4.tgz",
"integrity": "sha512-8JnbkQ4juDyvYs4mgFGQqg4yCYtFDtUtmp2QIQq11ZZe5CFQ5wcqm1rqDgAh/QdMySuBnPzMUiJUNZG5N/AiQw==",
"funding": [
{
"type": "github",
@@ -3573,9 +3573,9 @@
}
},
"node_modules/hono": {
"version": "4.12.25",
"resolved": "https://registry.npmjs.org/hono/-/hono-4.12.25.tgz",
"integrity": "sha512-2NFaIyNVgJmBs/ecmtGzlmluTFs5cHEWGTdu0t1HBwYzoGXOL5nUQBRMXsXWla5i4KkG//QMzVP88m1+I3fdAQ==",
"version": "4.12.31",
"resolved": "https://registry.npmjs.org/hono/-/hono-4.12.31.tgz",
"integrity": "sha512-zJIHFrl6bq3RDd2YusFNCDlM8qUprxKswyi/OPzPyzKDdyBXDqWx8bZlZ7R+saTdSTatUmb3O7K4SspGPaEOQg==",
"license": "MIT",
"engines": {
"node": ">=16.9.0"

View File

@@ -71,7 +71,8 @@
},
"overrides": {
"qs": ">=6.15.2",
"body-parser": ">=2.3.0"
"body-parser": ">=2.3.0",
"@hono/node-server": ">=2.0.5"
},
"optionalDependencies": {
"fallow": "^2.70.0"