Repository navigation
Tracking: resolve open Dependabot and code scanning security alerts #1706
Description
Activity
PRs opened (one per group)
Group Alerts PR shell-quote (Critical) #120 #1711 vitest (Critical) #119 #1707 hono #126, #128, #127, #125, #124 #1708 vite #123, #129 #1709 minimatch #69, #66, #61 #1715 form-data #130 #1710 js-yaml #134, #133 #1713 esbuild #121 #1714 @babel/core #132 #1712 Each PR applies the minimal fix (direct bump or a targeted
overridesentry), verifies the vulnerable version is gone vianpm ls, and passes the local check suite:prettier --check,check-version, client lint, client tests (535), cli tests (85), andnpm run build. E2e (Playwright) was not run locally and is left to CI.Note
Heads-up on CI formatting:
maincurrently has pre-existing Prettier drift on 5 client source files under the latest Prettier (3.9.5), while the lockfile pins 3.7.4. Because CI runsnpx prettier --check .beforenpm install, it fetches the latest Prettier and this step will show red on these PRs regardless of their changes. This should be addressed separately (reformat + pin, or run the format check after install).Code scanning + CI follow-ups
- Code scanning Fix server dying when an error occurs #53 (
js/request-forgery, SSRF in/fetch) → fix(server): guard the /fetch proxy against SSRF to link-local/metadata (alert 53) #1717. Narrow SSRF guard: blocks link-local/cloud-metadata targets (169.254.0.0/16, IPv6 link-local, AWS IPv6 IMDS) with DNS resolution + per-redirect re-validation, while keeping loopback/RFC1918 reachable (local MCP-server testing is a core use case). Adds endpoint tests. - CI format check → chore: pin prettier to 3.9.5 and run format check after install #1716.
main'snpx prettier --check .ran beforenpm install, fetching the latest Prettier and failing on pre-existing drift (would show red on all the PRs above). Pins Prettier to 3.9.5, reformats the 5 drifted files, and moves the format check to run after install using the pinned version.
That covers all 17 Dependabot alerts + the 1 code-scanning alert on the Security tab, one PR per checkbox group.
- Code scanning Fix server dying when an error occurs #53 (
- added 5 commits that reference this issue
on Jul 17, 2026 Code scanning #53 (SSRF) — dismissed as
won't fixwith justification. The/fetchproxy must accept dynamic user URLs (localhost/LAN are core use cases), so the allowlist CodeQL requires as a sanitizer isn't viable. PR #1717 adds defense-in-depth instead (DNS-resolved blocklist of link-local/cloud-metadata ranges + per-redirect re-validation, incl. the IPv4-mapped IPv6 form). Alert instances #53 and #62 dismissed.- linked a pull request that will close this issuechore(deps): override esbuild to ^0.28.1 (CVE fix) #1714
on Jul 17, 2026 - linked a pull request that will close this issuechore(deps): override js-yaml (3.15.0 / 4.2.0) (DoS fixes) #1713
on Jul 17, 2026 - linked a pull request that will close this issuechore(deps): override @babel/core to ^7.29.6 (CVE fix) #1712
on Jul 17, 2026 10 remaining items
- added 4 commits that reference this issue
on Jul 18, 2026 - added a commit that references this issue
on Jul 18, 2026 ✅ All items resolved.
mainaudits clean: 0 open Dependabot alerts, and the code-scanning SSRF alert is dismissed with mitigation.Merged: #1716 (prettier/CI), #1707 vitest, #1709 vite, #1711 shell-quote, #1708 hono, #1710 form-data, #1712 @babel/core, #1717 SSRF, and #1718 (lockfile regen finalizing esbuild/minimatch/@babel/core + js-yaml guard). PRs #1713/#1714/#1715 were superseded by #1718.
Note: npm wouldn't apply several transitive overrides to the existing lockfile minimally (leaving residual vulnerable copies), so #1718 regenerated the lockfile with version-targeted overrides — verified 0 vulnerable copies across all nine packages, build + client (535) + cli tests passing.
Summary
Tracking issue for the open GitHub security alerts on this repository. This covers both:
As of triage there are 17 open Dependabot alerts and 1 open code scanning alert. Items are grouped so that alerts fixable by a single dependency bump / PR share one checkbox, with the individual alerts bulleted underneath. Resolve each by upgrading the affected dependency (or applying a fix), or dismiss with a rationale if it doesn't apply to how the Inspector uses it.
Code scanning
server/src/index.tsjs/request-forgery— Server-side request forgeryDependabot
honoupgrade (High + Medium)origindefaults to wildcardContent-Lengthserve-staticon Windows via encoded backslash (%5C)Set-Cookieheaders, dropping cookiesminimatchupgrade (High)matchOne()combinatorial backtracking via non-adjacent GLOBSTAR segments*()extglobs generate catastrophically backtracking regexesviteupgrade (High + Medium)server.fs.denybypass on Windows alternate pathslaunch-editor(transitive): NTLMv2 hash disclosure via UNC path handling on Windowsjs-yamlupgrade (Medium)shell-quoteupgrade (Critical)quote()does not escape newlines in object.opvaluesvitestupgrade (Critical)form-dataupgrade (High)@babel/coreupgrade (Low)sourceMappingURLcommentesbuildupgrade (Low)Counts and links captured at time of filing; check the Security tab for the current live state.