Skip to content

fix(deps): override deepmerge-ts to 8.0.1 to close security gate - #2038

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
fix/2037-deepmerge-ts-audit
Aug 19, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
fix/2037-deepmerge-ts-audit

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Aug 19, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fixes #2037 — required Security check (npm run audit:high) is failing repo-wide, blocking every open PR.

Root cause: prisma@7.9.1 (latest) → @prisma/config@7.9.1 → deepmerge-ts@7.1.5, which has GHSA-ggr8-5vv4-36mx (stack exhaustion on recursive object graphs, fixed at 8.0.1). No newer prisma/@prisma/config release exists yet that bumps this off 7.1.5.

Fix: force it via overrides in root package.json, same pattern as the earlier #1959 fix (undici/ip-address).

Test plan


Summary by cubic

Overrides transitive deepmerge-ts to 8.0.1 to close the high/critical security audit gate and hardens the Docker build for backend dependencies. Previously prisma@7.9.1 pulled deepmerge-ts@7.1.5 (GHSA-ggr8-5vv4-36mx) and the deps-production-backend stage could fail when packages/backend/node_modules was absent; now we force 8.0.1 and ensure the directory exists before COPY.

Review notes

  • Adds overrides: { "deepmerge-ts": "^8.0.1" } in root package.json; regenerates package-lock.json.
  • Dockerfile: mkdir -p packages/backend/node_modules to prevent COPY failures when npm hoists all deps to the root.
  • Verified: npm ls deepmerge-ts resolves to 8.0.1 across all workspaces; npm run audit:high, npx prisma generate, TS builds, and shared/backend tests pass unchanged.
  • Risk: transitive deepmerge-ts major bump; monitor for Prisma tooling regressions.

Written for commit c283265. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes

    • Improved production build reliability by ensuring required application directories are available during image assembly.
    • Updated package configuration to improve compatibility and consistency across installations.
  • Chores

    • Strengthened deployment preparation for environments where packages are consolidated during installation.

prisma@7.9.1 (latest) pins @prisma/config@7.9.1, which pins
deepmerge-ts@7.1.5 — GHSA-ggr8-5vv4-36mx, stack exhaustion on recursive
object graphs, fixed upstream at 8.0.1. No prisma/config release yet
bumps it, so force it via overrides same as the #1959 fix pattern.

Verified: npm ls deepmerge-ts resolves to 8.0.1 everywhere (not just
hoisted root), npm run audit:high passes clean, prisma client
regenerates fine, shared (1407 tests) + backend (1352 tests) suites
pass unchanged.
@coderabbitai

coderabbitai Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8afaf62b-aa90-493b-9429-602cee3035fd

📥 Commits

Reviewing files that changed from the base of the PR and between a3fdd44 and c283265.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • Dockerfile
  • package.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Dockerfile now creates the backend node_modules directory during production assembly. The root npm configuration now overrides deepmerge-ts to ^8.0.1.

Changes

Production dependency reliability

Layer / File(s) Summary
Ensure backend dependency directory
Dockerfile
The production dependency stage creates packages/backend/node_modules before the production image copy.
Pin transitive dependency version
package.json
The npm overrides block pins deepmerge-ts to ^8.0.1.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to c2832

The dependency override and Dockerfile adjustment are validated by the listed security, build, type-check, and test results, and no actionable merge-blocking risk remains after normal checks.

Possibly related PRs

Suggested reviewers: cubic-dev-ai

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ❓ Inconclusive The override addresses issue #2037, but the excluded package-lock.json prevents verification of lockfile updates, workspace resolution, and audit results. Include package-lock.json in review or provide reviewable evidence that all workspace copies resolve to 8.0.1 and npm run audit:high passes.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the dependency override and its security purpose, which matches the primary change.
Out of Scope Changes check ✅ Passed The Dockerfile change supports the dependency override by handling npm hoisting, so the reviewed changes remain related to the PR objectives.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/2037-deepmerge-ts-audit

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

package.json

typescript-eslint does not support TS 7.0.
Please see https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/#running-side-by-side-with-typescript-6.0 to run typescript-eslint using the TS 6 API.
See also typescript-eslint/typescript-eslint#10940 for tracking typescript-eslint's support for TS >=7.1

Oops! Something went wrong! :(

ESLint: 10.8.1

Error: typescript-eslint does not support TS 7.0.
at Object. (/node_modules/@typescript-eslint/eslint-plugin/dist/index.js:50:11)
at Module._compile (node:internal/modules/cjs/loader:1830:14)
at Object..js (node:internal/modules/cjs/loader:1961:10)
at Module.load (node:internal/modules/cjs/loader:1553:32)
at Module._load (node:internal/modules/cjs/loader:1355:12)
at wrapModuleLoad (node:internal/modules/cjs/loader:255:19)
at loadCJSModuleWithModuleLoad (node:internal/modules/esm/translators:326:3)
at ModuleWrap. (node:internal/modules/esm/translators:231:7)
at ModuleJob.run (node:internal/modules/esm/module_job:437:25)
at async node:internal/modules/esm/loader:639:26

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file size/xl labels Aug 19, 2026
@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Warnings
⚠️

Big PR — 4953 lines changed across 3 files. Consider splitting into smaller, reviewable chunks.

Generated by 🚫 dangerJS against c283265

@socket-security

socket-security Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

@socket-security

socket-security Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Low adoption: npm @rolldown/binding-android-arm-eabi

Location: Package overview

From: package-lock.json → npm/vite@8.2.1 → npm/rollup-plugin-visualizer@7.1.1 → npm/@rolldown/binding-android-arm-eabi@1.2.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@rolldown/binding-android-arm-eabi@1.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Requires human review: Override deepmerge-ts from 7.x to 8.x to fix security vulnerability. Major version bump of transitive dependency requires human evaluation of compatibility risk.
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.

Re-trigger cubic

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Pins the dev toolchain and adds new package.json scripts (test:backend, test:bot, test:ci, test:coverage, test:e2e, audit:critical, build, prepare) alongside secretlint, Stryker, and lint-staged configuration. Bumps and reorganizes package-lock.json dependencies (dropping @bcoe/v8-coverage to 0.2.3, deduping nested lru-cache/ansi-regex/source-map, retagging @babel/* and @emnapi/* entries), and pulls in new deps including jintr, prom-client, piscina, prisma, and @discord-player/*.

No blocking issues surfaced. 2 lower-confidence candidates did not survive cross-model review.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 171 functions depend on the 171 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 171 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 171 function(s) in the blast radius were not formally verified this run

Build — backend failed on #2038: the COPY --from=deps-production-backend
packages/backend/node_modules step hard-fails when that path doesn't
exist. Whether npm nests any deps there vs fully hoisting to root
depends on lockfile resolution, and the deepmerge-ts override regen
(this branch) flipped it to zero nested deps for backend — confirmed:
main's lockfile nests @types/node + undici-types there, the
regenerated one hoists both to root instead.

mkdir -p guarantees the dir exists regardless of hoisting outcome —
empty is harmless, real nested deps still copy normally. Fixes the
underlying fragility instead of fighting npm's resolver.
@github-actions github-actions Bot added the infra label Aug 19, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Requires human review: Overrides deepmerge-ts to 8.0.1 (major version bump) to fix a security vulnerability; the compatibility impact on Prisma is not verifiable from the diff and requires human evaluation.

Re-trigger cubic

@sonarqubecloud

Copy link
Copy Markdown

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Splits the production dependency install so the backend npm prune runs in a dedicated deps-production-backend stage, and adds mkdir -p packages/backend/node_modules so the later COPY --from can't hard-fail when npm hoists all nested deps to root. Regenerates package-lock.json accordingly (dep hoisting shifts, several devOptional→dev reclassifications, and version bumps for packages like @bcoe/v8-coverage, @emnapi/*, @hookform/resolvers).

No blocking issues surfaced. 1 lower-confidence candidate did not survive cross-model review.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 171 functions depend on the 171 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 171 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 171 function(s) in the blast radius were not formally verified this run

@LucasSantana-Dev
LucasSantana-Dev merged commit 04a7f85 into main Aug 19, 2026
45 of 46 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/2037-deepmerge-ts-audit branch August 19, 2026 17:07
LucasSantana-Dev added a commit that referenced this pull request Aug 19, 2026
🤖 I have created a release *beep* *boop*
---


<details><summary>2.39.5</summary>

##
[2.39.5](v2.39.4...v2.39.5)
(2026-08-19)


### Bug Fixes

* **bot:** support yt-dlp cookies file to dodge YouTube 403
([#2036](#2036))
([2ec1868](2ec1868))
* **deps:** override deepmerge-ts to 8.0.1 to close security gate
([#2038](#2038))
([04a7f85](04a7f85))
* drop dead guild-guard entry for nonexistent features route
([#2030](#2030))
([522139c](522139c))
* unblock ioredis/bullmq bumps by deduping stale lockfile
([#2033](#2033))
([0c6cb0d](0c6cb0d))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
LucasSantana-Dev added a commit that referenced this pull request Aug 19, 2026
…ndeclared (#2040)

## Summary

**Production-breaking regression, urgent.** After #2038's clean
node_modules/lockfile regen (needed for the deepmerge-ts security fix)
busted a stale Docker npm-install cache layer, YouTube extractor
registration now throws on every bot boot:

```
Error [ERR_MODULE_NOT_FOUND]: Cannot find package 'youtube-dl-exec' imported from /app/node_modules/discord-player-youtubei/dist/index.mjs
YouTube extractor unavailable after retries — #play of YouTube URLs will fail until restart. Falling back to SoundCloud/Spotify only.
```

Discovered live on homelab after redeploying #2036 (the yt-dlp-cookies
fix for #2034) — the cookies fix itself is correct, but it's moot
because `createResilientStream` (the function it patches) never gets
wired in at all when this registration fails, since it's passed as `{
createStream: createResilientStream }` at the
`player.extractors.register(YoutubeExtractor, ...)` call site
(`packages/bot/src/handlers/player/playerFactory.ts:166-169`).

## Root cause

`discord-player-youtubei`'s compiled `dist/index.mjs` has a hard
top-level `import youtubeDl from "youtube-dl-exec"` (confirmed: `grep -n
youtube-dl-exec node_modules/discord-player-youtubei/dist/index.mjs`)
that it never declares anywhere in its own `package.json`
(dependencies/optionalDependencies/peerDependencies all empty) — an
upstream packaging bug.

`youtube-dl-exec` was a real dependency of ours until `a20a6c29` (5 days
ago, "remove the download feature for top.gg compliance", #1956)
correctly dropped it since our own `/download` command no longer used
it. Nobody knew `discord-player-youtubei` also needed it internally. It
kept working in production purely because Docker's npm-install layer
(keyed by `package-lock.json` hash) was still cached from before that
removal — until #2038's full lockfile regen busted that cache for the
first time, surfacing the gap.

## Fix

Re-declare `youtube-dl-exec` in `packages/bot/package.json` — purely as
a transitive requirement for `discord-player-youtubei`, no
download-feature code restored. `Dockerfile` already sets
`YOUTUBE_DL_SKIP_DOWNLOAD=1` (see #1827/#874), so its postinstall
binary-download stays skipped as before.

## Test plan

- [x] `node -e "import('discord-player-youtubei').then(...)"` resolves
cleanly, `YoutubeExtractor` export present
- [x] `npx jest` (bot package) — 3139/3140 pass (1 pre-existing skip)
- [x] `tsc --noEmit` clean
- [x] `npm run audit:high` clean
- [ ] Deploy + confirm `/play` of a YouTube URL works and the
extractor-registration error is gone from logs

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Restores `youtube-dl-exec` in `packages/bot` to satisfy
`discord-player-youtubei`’s undeclared import and fix the boot-time
ERR_MODULE_NOT_FOUND that prevented YouTube extractor registration and
playback. Documents `YOUTUBE_DL_SKIP_DOWNLOAD=1` for local installs to
avoid postinstall downloads.

- Declares `youtube-dl-exec` in `packages/bot/package.json` only for the
extractor; no download feature is restored.
- Behavior: YouTube extractor registers on boot; YouTube URLs play; no
other code paths change.
- Docs: README instructs `YOUTUBE_DL_SKIP_DOWNLOAD=1 npm install` for
local dev; Docker and CI already skip postinstall.
- Rollout: rebuild and redeploy the bot image. Developers must run
`YOUTUBE_DL_SKIP_DOWNLOAD=1 npm install` locally.

<sup>Written for commit 823c1e2.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2040?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added support for retrieving media from YouTube and other supported
platforms.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file infra size/xl

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: required Security check failing repo-wide — deepmerge-ts stack exhaustion via prisma@7.9.1

1 participant