Skip to content

fix(ci): clear stale audit-gate entries and bump fixed advisories - #1960

Merged
LucasSantana-Dev merged 3 commits into
mainfrom
fix/audit-gate-stale-overrides
Aug 10, 2026
Merged

LucasSantana-Dev merged 3 commits into
mainfrom
fix/audit-gate-stale-overrides

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Aug 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fixes #1959 — the required Security check has failed on every PR since 2026-08-05 (5+ days), regardless of what's changed.

Root cause: undici was override-pinned to exactly 7.28.0, itself inside the current advisory range (7.0.0-7.28.0, fixed at 7.29.0); ip-address had no ceiling clearing its vulnerable range (<=10.3.0). Both predate this PR, confirmed via git stash + node scripts/audit-gate.mjs against clean main.

Fix:

  • Bumped undici to ^7.29.0 and ip-address to >=10.3.1 in root overrides.
  • packages/frontend had its own direct undici@7.28.0 devDependency, independent of the root override — bumped it too. (Root cause of a detour: a bare overrides entry alone doesn't reliably force-resolve a hoisted version when a workspace has a conflicting direct pin in this repo — same shape as the documented piscina fix in 10b68e6. The direct pin wins; bump it in place rather than fighting the override.)
  • The react-router advisory (previously accepted with an exit condition tied to a v8 migration, security(frontend): migrate to react-router v8 to clear GHSA-qwww-vcr4-c8h2 #1878) cleared on its own during the lockfile regen — react-router-dom now resolves to 7.18.2, past the vulnerable range, via ordinary semver resolution. Removed the now-stale ACCEPTED entries per the gate's own hygiene enforcement, closed security(frontend): migrate to react-router v8 to clear GHSA-qwww-vcr4-c8h2 #1878 as moot.

A detour worth flagging: mid-fix I hit what looked like nondeterministic package resolution (a busboy module-not-found, then an unrelated jsdom one) even across repeated clean reinstalls. Root cause was local npm cache corruption (npm cache verify reported garbage-collecting 94 stale entries) — unrelated to this fix, resolved with npm cache clean --force + reinstall. Mentioning in case it recurs for someone else.

Test plan

  • npm ci (exact lockfile install, no re-resolution — same install mode as this repo's own CI) succeeds clean
  • node scripts/audit-gate.mjs — zero findings
  • npx tsc --noEmit clean across all 4 workspaces
  • Full test suite green: shared 1404, bot 3212 (+1 skipped), backend 1352, frontend 1038 — 8006 tests total
  • npm run lint — no new findings (pre-existing warnings in .agents/browser-automation/*.js untouched)

Follow-up

Once this merges, #1950 and #1958 (both currently blocked on this same check) should pass once rebased.


Summary by cubic

Unblocks the failing Security check by bumping vulnerable packages and removing stale audit-gate overrides. Fixes #1959.

  • Dependencies

    • Override undici to ^7.29.0; bump frontend devDependency to ^7.29.0.
    • Set ip-address to >=10.3.1.
    • Add fast-uri override ^3.1.5 (cap to 3.x to match ajv).
    • Bump frontend vendor-state gzip limit to 26.5 KB after axios minor update increased bundle size slightly.
  • Bug Fixes

    • Clear ACCEPTED entries for react-router/react-router-dom now that resolved versions are past advisories.
    • Root cause was undici@7.28.0 and missing ip-address ceiling keeping installs in vulnerable ranges.
    • Security gate now passes on npm ci; CI is unblocked.

Written for commit 153c909. Summary will update on new commits.

Review in cubic

Repo-wide required security check has failed since 2026-08-05 regardless
of what a PR changes. Root cause: undici was override-pinned to exactly
7.28.0, itself inside the current advisory range (7.0.0-7.28.0, fixed at
7.29.0); ip-address had no ceiling clearing its vulnerable range
(<=10.3.0). Both predate this PR — confirmed on clean main.

Bumped undici to ^7.29.0 and ip-address to >=10.3.1 in root overrides.
packages/frontend also had its own direct undici@7.28.0 devDependency
pin, independent of the root override (same shape as the piscina fix in
10b68e6: a bare override alone doesn't reliably re-resolve a hoisted
version in this workspace, a direct pin does) — bumped it too so it
doesn't fight the override and break npm ci's lockfile consistency
check.

The react-router advisory (previously accepted with an exit condition
tied to a v8 migration, #1878) cleared on its own during the lockfile
regen — react-router-dom now resolves to 7.18.2, past the vulnerable
range, via ordinary semver resolution. Removed the now-stale ACCEPTED
entries per the gate's own hygiene check, and closed #1878 as moot.

Verified: npm ci (no re-resolution, exact lockfile install) succeeds
clean, node scripts/audit-gate.mjs passes with zero findings, full test
suite green across all 4 workspaces (shared 1404, bot 3212, backend
1352, frontend 1038 — 8006 tests total), tsc --noEmit clean.
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The pull request updates dependency constraints for undici, fast-uri, and ip-address. It removes react-router advisory exceptions from the audit gate and raises the frontend vendor bundle size limit.

Changes

Security and bundle updates

Layer / File(s) Summary
Dependency constraints and bundle limit
package.json, packages/frontend/package.json, packages/frontend/.size-limit.json
The npm overrides raise minimum versions for undici, fast-uri, and ip-address. The frontend allows undici 7.29.x releases. The vendor gzip limit increases to 26.5 KB.
Audit acceptance rules
scripts/audit-gate.mjs
The audit gate no longer pre-accepts react-router or react-router-dom advisories.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: cubic-dev-ai

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning Dependency and audit-gate updates are present, but no react-router v8 dependency or import migration is shown; the excluded lockfile also prevents resolution verification. Add the required react-router v8 migration and provide reviewable evidence that the excluded package-lock.json resolves safe undici and ip-address versions.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed All reported changes support the linked security objectives, including the vendor-state budget adjustment documented as an incidental dependency-size update.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main changes: removing stale audit-gate entries and updating dependencies for fixed advisories.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/audit-gate-stale-overrides

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file frontend infra size/xl labels Aug 10, 2026
@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@socket-security

socket-security Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedreact-router-dom@​7.18.1 ⏵ 7.18.21001006597 +2100
Updated@​radix-ui/​react-label@​2.1.14 ⏵ 2.1.15100 +110066 +199 +1100
Updated@​radix-ui/​react-slot@​1.3.2 ⏵ 1.3.3100 +11006998100
Updated@​radix-ui/​react-avatar@​1.2.5 ⏵ 1.2.699 +11006999 +1100
Updated@​radix-ui/​react-tabs@​1.1.20 ⏵ 1.1.2199 +11007099 +1100
Updated@​radix-ui/​react-switch@​1.3.6 ⏵ 1.3.799 +110070 +199 +1100
Updated@​radix-ui/​react-checkbox@​1.3.10 ⏵ 1.3.1199 +110071 +199 +1100
Updated@​radix-ui/​react-dropdown-menu@​2.1.23 ⏵ 2.1.2499 +110071 +199 +1100
Updated@​radix-ui/​react-dialog@​1.1.22 ⏵ 1.1.2399 +11007199 +1100
Updated@​radix-ui/​react-tooltip@​1.2.15 ⏵ 1.2.16991007299 +1100
Updated@​radix-ui/​react-toast@​1.2.22 ⏵ 1.2.23991007299 +1100
Updated@​radix-ui/​react-scroll-area@​1.2.17 ⏵ 1.2.18991007299 +1100
Updated@​radix-ui/​react-select@​2.3.6 ⏵ 2.3.7991007399 +1100
Updated@​types/​react-dom@​19.2.3 ⏵ 19.2.4100 +110075 +188100
Updated@​types/​luxon@​3.7.2 ⏵ 3.7.41001007790 +4100
Updated@​types/​react@​19.2.15 ⏵ 19.2.181001007992100
Updatedsonner@​2.0.7 ⏵ 2.0.810010083 +180100
Updatedlucide-react@​1.26.0 ⏵ 1.31.010010098 +196 +180
Updatedplaywright@​1.62.0 ⏵ 1.62.11001001009980
Updated@​types/​node@​25.9.3 ⏵ 25.9.510010081 +195100
Updatedtsx@​4.23.1 ⏵ 4.23.12100 +1210081 +195 +1100
Updatedpostcss@​8.5.23 ⏵ 8.5.26100 +110082 +195100
Updatedyoutube-dl-exec@​3.1.9 ⏵ 3.1.1283 +110010095 +1100
Updatedreact@​19.2.6 ⏵ 19.2.81001008497100
Updatedeslint-plugin-react-refresh@​0.5.3 ⏵ 0.5.410010099 +188100
Updated@​testing-library/​user-event@​14.6.1 ⏵ 14.6.310010010092 +6100
Updated@​swc/​core@​1.15.46 ⏵ 1.15.479210010096 +1100
Updatedreact-dom@​19.2.6 ⏵ 19.2.81001009298100
Updatedundici@​7.28.0 ⏵ 7.29.093100 +21100 +198100
Updatedaxios@​1.18.1 ⏵ 1.19.098 +110010093 -1100
Addedioredis@​5.11.19410010095100
See 9 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @sentry/node-core is 60.0% likely obfuscated

Confidence: 0.60

Location: Package overview

From: package-lock.json → npm/@sentry/node@10.70.0 → npm/@sentry/node-core@10.70.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/node-core@10.70.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm strtok3 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.json → npm/file-type@21.3.4 → npm/strtok3@10.3.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/strtok3@10.3.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.json → npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-android-arm-eabi

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-android-arm-eabi@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-android-arm-eabi@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-android-arm64

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-android-arm64@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-android-arm64@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-darwin-arm64

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-darwin-arm64@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-darwin-arm64@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-darwin-universal

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-darwin-universal@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-darwin-universal@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-darwin-x64

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-darwin-x64@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-darwin-x64@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-freebsd-x64

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-freebsd-x64@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-freebsd-x64@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-linux-arm-gnueabihf

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-linux-arm-gnueabihf@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-linux-arm-gnueabihf@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-linux-arm-musleabihf

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-linux-arm-musleabihf@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-linux-arm-musleabihf@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-linux-arm64-gnu

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-linux-arm64-gnu@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-linux-arm64-gnu@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-linux-arm64-musl

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-linux-arm64-musl@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-linux-arm64-musl@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-linux-riscv64-gnu

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-linux-riscv64-gnu@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-linux-riscv64-gnu@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-linux-x64-musl

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-linux-x64-musl@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-linux-x64-musl@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-win32-arm64-msvc

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-win32-arm64-msvc@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-win32-arm64-msvc@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-win32-ia32-msvc

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-win32-ia32-msvc@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-win32-ia32-msvc@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm mediaplex-win32-x64-msvc

Location: Package overview

From: package-lock.json → npm/discord-player@7.2.0 → npm/mediaplex-win32-x64-msvc@1.0.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mediaplex-win32-x64-msvc@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

github-actions Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Warnings
⚠️

Big PR — 10524 lines changed across 5 files. Consider splitting into smaller, reviewable chunks.

Generated by 🚫 dangerJS against 153c909

Incidental fallout from the lockfile regen in the audit-gate fix — axios
picked up a routine minor bump (1.18.1 -> 1.19.0) within its existing
semver range, adding 133B gzipped to the vendor-state chunk (zustand +
react-query + axios). Not a regression to fix by re-pinning; that
reintroduces the exact override/pin fragility this PR is cleaning up.
Small headroom bump.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed

Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.

Re-trigger cubic

Comment thread package.json Outdated
cubic-dev-ai[bot]
cubic-dev-ai Bot previously approved these changes Aug 10, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Auto-approved: Security fix bumping vulnerable dependencies (undici, ip-address) and removing stale audit-gate accepted entries after resolved versions clear advisories; audit gate passes with zero findings and full test suite green.

Re-trigger cubic

An unbounded >=3.1.5 floor let npm resolve fast-uri to 4.1.2 on
lockfile regen, even though its only consumer (ajv) declares
^3.0.1 -- npm overrides ignore that range. Caps to ^3.1.5 so the
advisory fix stays within the major version ajv supports.

Addresses cubic's review finding on this PR.
@sonarqubecloud

Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 2 files (changes from recent commits).

Requires human review: Lockfile diff is omitted, so I cannot verify that resolved versions actually clear the advisories or that the 10k-line lockfile change is confined to the intended bumps. Removing the accepted advisories requires human confirmation that the new resolutions are safe.

Re-trigger cubic

@LucasSantana-Dev
LucasSantana-Dev merged commit 2c17c99 into main Aug 10, 2026
43 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/audit-gate-stale-overrides branch August 10, 2026 18:32
LucasSantana-Dev added a commit that referenced this pull request Aug 11, 2026
🤖 I have created a release *beep* *boop*
---


<details><summary>2.39.2</summary>

##
[2.39.2](v2.39.1...v2.39.2)
(2026-08-10)


### Bug Fixes

* **bot:** guard voice/session mutations with stop/suppress flags
([#1998](#1998))
([23eaba2](23eaba2))
* **ci:** clear stale audit-gate entries and bump fixed advisories
([#1942](#1942))
([adf710b](adf710b))
* **ci:** clear stale audit-gate entries and bump fixed advisories
([#1960](#1960))
([2c17c99](2c17c99))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
LucasSantana-Dev added a commit that referenced this pull request Aug 21, 2026
Closes #2010. **Unblocks the release PR #2039**, whose only failing
check is `Size Limit Check`.

## The number

| Bundle | Limit | Actual | Headroom |
|---|---|---|---|
| Main | 75 kB | 70.33 | 6.2% |
| Vendor UI | 70 kB | 66.40 | 5.1% |
| Vendor React | 60 kB | 55.63 | 7.3% |
| **Vendor Radix** | **48 kB** | **48.94** | **-2.0% (over by 942 B)** |
| Vendor Forms | 28 kB | 26.35 | 5.9% |
| Vendor State | 26.5 kB | 26.14 | 1.4% |

## I tried to reduce it first

Four Radix packages have **zero imports** in `packages/frontend/src` —
`tabs`, `toast`, `tooltip`, `slot` — yet all four are listed in
`vite.config.ts` `manualChunks` for `vendor-radix`. That looked like a
free win. Removing them drops the chunk to **48.61 kB**, comfortably
under the old limit.

**It is a regression.** Measuring the whole output rather than the one
chunk:

| | Total JS, gzipped, all 63 chunks |
|---|---|
| current config | **496,709 B** |
| 4 packages removed | **498,088 B** |
| | **+1,379 B worse** |

`@radix-ui/react-slot` is a shared transitive dependency of the other
Radix packages. Grouping it into `vendor-radix` **deduplicates** it;
splitting it out copies it into every chunk that needs it. So the "fix"
shrinks the measured chunk by growing the real bundle — exactly the
thing a size budget exists to prevent.

`vite.config.ts` is therefore unchanged.

## So: raise it

With no reduction available that does not make the bundle worse, 48.94
kB is the honest size of what the app actually uses. 50 kB gives ~2.1%
headroom, in line with the other five budgets (1.4%–6.6%), and matches
the `26 → 26.5 kB` precedent set for Vendor State in #1960.

Verified locally: `npx size-limit` exits **0**, all six budgets pass.

## Follow-up, not done here

`@radix-ui/react-tabs`, `react-toast` and `react-tooltip` have no
imports anywhere in `src` and are almost certainly not in the bundle at
all (unreachable from the entry, so tree-shaken before chunking).
Removing them from `packages/frontend/package.json` is genuine
dependency hygiene, but it touches the lockfile and will not change any
bundle number — worth its own PR rather than riding along with a release
unblock. Say the word and I will file it.

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Raises the Vendor Radix size-limit from 48 KB to 50 KB to match the
actual gzipped chunk size (48.94 kB) and keep CI green. Old behavior: CI
failed at 48 KB; new behavior: budget is 50 KB; no runtime or bundling
behavior changes.

- No change to `vite.config.ts` or chunking. Removing
`@radix-ui/react-tabs`, `@radix-ui/react-toast`,
`@radix-ui/react-tooltip`, and `@radix-ui/react-slot` from the
`vendor-radix` chunk shrank that chunk but increased total gzipped JS
(~1.4 kB) due to duplicated `@radix-ui/react-slot`.
- New headroom is ~2.1%, consistent with other budgets; `npx size-limit`
passes locally.
- Single file touched: `packages/frontend/.size-limit.json` (sets
"Vendor Radix (gzip)" limit to 50 KB).

<sup>Written for commit 32ad800.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2068?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file frontend infra size/xl

Projects

None yet

1 participant