Repository navigation
fix(deps): override deepmerge-ts to 8.0.1 to close security gate - #2038
Conversation
prisma@7.9.1 (latest) pins @prisma/config@7.9.1, which pins deepmerge-ts@7.1.5 — GHSA-ggr8-5vv4-36mx, stack exhaustion on recursive object graphs, fixed upstream at 8.0.1. No prisma/config release yet bumps it, so force it via overrides same as the #1959 fix pattern. Verified: npm ls deepmerge-ts resolves to 8.0.1 everywhere (not just hoisted root), npm run audit:high passes clean, prisma client regenerates fine, shared (1407 tests) + backend (1352 tests) suites pass unchanged.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Dockerfile now creates the backend ChangesProduction dependency reliability
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to The dependency override and Dockerfile adjustment are validated by the listed security, build, type-check, and test results, and no actionable merge-blocking risk remains after normal checks. Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 ESLint
package.jsontypescript-eslint does not support TS 7.0. Oops! Something went wrong! :( ESLint: 10.8.1 Error: typescript-eslint does not support TS 7.0. Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Failed to generate code suggestions for PR |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
No issues found across 2 files
Requires human review: Override deepmerge-ts from 7.x to 8.x to fix security vulnerability. Major version bump of transitive dependency requires human evaluation of compatibility risk.
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Pins the dev toolchain and adds new package.json scripts (test:backend, test:bot, test:ci, test:coverage, test:e2e, audit:critical, build, prepare) alongside secretlint, Stryker, and lint-staged configuration. Bumps and reorganizes package-lock.json dependencies (dropping @bcoe/v8-coverage to 0.2.3, deduping nested lru-cache/ansi-regex/source-map, retagging @babel/* and @emnapi/* entries), and pulls in new deps including jintr, prom-client, piscina, prisma, and @discord-player/*.
No blocking issues surfaced. 2 lower-confidence candidates did not survive cross-model review.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 171 functions depend on the 171 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 171 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 171 function(s) in the blast radius were not formally verified this run
Build — backend failed on #2038: the COPY --from=deps-production-backend packages/backend/node_modules step hard-fails when that path doesn't exist. Whether npm nests any deps there vs fully hoisting to root depends on lockfile resolution, and the deepmerge-ts override regen (this branch) flipped it to zero nested deps for backend — confirmed: main's lockfile nests @types/node + undici-types there, the regenerated one hoists both to root instead. mkdir -p guarantees the dir exists regardless of hoisting outcome — empty is harmless, real nested deps still copy normally. Fixes the underlying fragility instead of fighting npm's resolver.
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Requires human review: Overrides deepmerge-ts to 8.0.1 (major version bump) to fix a security vulnerability; the compatibility impact on Prisma is not verifiable from the diff and requires human evaluation.
Re-trigger cubic
|
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Splits the production dependency install so the backend npm prune runs in a dedicated deps-production-backend stage, and adds mkdir -p packages/backend/node_modules so the later COPY --from can't hard-fail when npm hoists all nested deps to root. Regenerates package-lock.json accordingly (dep hoisting shifts, several devOptional→dev reclassifications, and version bumps for packages like @bcoe/v8-coverage, @emnapi/*, @hookform/resolvers).
No blocking issues surfaced. 1 lower-confidence candidate did not survive cross-model review.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 171 functions depend on the 171 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 171 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 171 function(s) in the blast radius were not formally verified this run
🤖 I have created a release *beep* *boop* --- <details><summary>2.39.5</summary> ## [2.39.5](v2.39.4...v2.39.5) (2026-08-19) ### Bug Fixes * **bot:** support yt-dlp cookies file to dodge YouTube 403 ([#2036](#2036)) ([2ec1868](2ec1868)) * **deps:** override deepmerge-ts to 8.0.1 to close security gate ([#2038](#2038)) ([04a7f85](04a7f85)) * drop dead guild-guard entry for nonexistent features route ([#2030](#2030)) ([522139c](522139c)) * unblock ioredis/bullmq bumps by deduping stale lockfile ([#2033](#2033)) ([0c6cb0d](0c6cb0d)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
…ndeclared (#2040) ## Summary **Production-breaking regression, urgent.** After #2038's clean node_modules/lockfile regen (needed for the deepmerge-ts security fix) busted a stale Docker npm-install cache layer, YouTube extractor registration now throws on every bot boot: ``` Error [ERR_MODULE_NOT_FOUND]: Cannot find package 'youtube-dl-exec' imported from /app/node_modules/discord-player-youtubei/dist/index.mjs YouTube extractor unavailable after retries — #play of YouTube URLs will fail until restart. Falling back to SoundCloud/Spotify only. ``` Discovered live on homelab after redeploying #2036 (the yt-dlp-cookies fix for #2034) — the cookies fix itself is correct, but it's moot because `createResilientStream` (the function it patches) never gets wired in at all when this registration fails, since it's passed as `{ createStream: createResilientStream }` at the `player.extractors.register(YoutubeExtractor, ...)` call site (`packages/bot/src/handlers/player/playerFactory.ts:166-169`). ## Root cause `discord-player-youtubei`'s compiled `dist/index.mjs` has a hard top-level `import youtubeDl from "youtube-dl-exec"` (confirmed: `grep -n youtube-dl-exec node_modules/discord-player-youtubei/dist/index.mjs`) that it never declares anywhere in its own `package.json` (dependencies/optionalDependencies/peerDependencies all empty) — an upstream packaging bug. `youtube-dl-exec` was a real dependency of ours until `a20a6c29` (5 days ago, "remove the download feature for top.gg compliance", #1956) correctly dropped it since our own `/download` command no longer used it. Nobody knew `discord-player-youtubei` also needed it internally. It kept working in production purely because Docker's npm-install layer (keyed by `package-lock.json` hash) was still cached from before that removal — until #2038's full lockfile regen busted that cache for the first time, surfacing the gap. ## Fix Re-declare `youtube-dl-exec` in `packages/bot/package.json` — purely as a transitive requirement for `discord-player-youtubei`, no download-feature code restored. `Dockerfile` already sets `YOUTUBE_DL_SKIP_DOWNLOAD=1` (see #1827/#874), so its postinstall binary-download stays skipped as before. ## Test plan - [x] `node -e "import('discord-player-youtubei').then(...)"` resolves cleanly, `YoutubeExtractor` export present - [x] `npx jest` (bot package) — 3139/3140 pass (1 pre-existing skip) - [x] `tsc --noEmit` clean - [x] `npm run audit:high` clean - [ ] Deploy + confirm `/play` of a YouTube URL works and the extractor-registration error is gone from logs <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Restores `youtube-dl-exec` in `packages/bot` to satisfy `discord-player-youtubei`’s undeclared import and fix the boot-time ERR_MODULE_NOT_FOUND that prevented YouTube extractor registration and playback. Documents `YOUTUBE_DL_SKIP_DOWNLOAD=1` for local installs to avoid postinstall downloads. - Declares `youtube-dl-exec` in `packages/bot/package.json` only for the extractor; no download feature is restored. - Behavior: YouTube extractor registers on boot; YouTube URLs play; no other code paths change. - Docs: README instructs `YOUTUBE_DL_SKIP_DOWNLOAD=1 npm install` for local dev; Docker and CI already skip postinstall. - Rollout: rebuild and redeploy the bot image. Developers must run `YOUTUBE_DL_SKIP_DOWNLOAD=1 npm install` locally. <sup>Written for commit 823c1e2. Summary will update on new commits.</sup> <a href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2040?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for retrieving media from YouTube and other supported platforms. <!-- end of auto-generated comment: release notes by coderabbit.ai -->



Summary
Fixes #2037 — required
Securitycheck (npm run audit:high) is failing repo-wide, blocking every open PR.Root cause:
prisma@7.9.1(latest) →@prisma/config@7.9.1→deepmerge-ts@7.1.5, which has GHSA-ggr8-5vv4-36mx (stack exhaustion on recursive object graphs, fixed at8.0.1). No newerprisma/@prisma/configrelease exists yet that bumps this off7.1.5.Fix: force it via
overridesin rootpackage.json, same pattern as the earlier #1959 fix (undici/ip-address).Test plan
npm ls deepmerge-ts→ resolves to8.0.1everywhere (not just hoisted root — ci: required Security check failing repo-wide, blocking every PR (stale undici/ip-address override pins) #1959 flagged partial-override resolution as a risk)npm run audit:high→No unaccepted high/critical findings in production dependencies.npx prisma generate— cleantsc --noEmiton shared + bot workspaces — cleanpackages/sharedtest suite — 73 suites / 1407 tests passpackages/backendtest suite (heaviest Prisma consumer) — 85 suites / 1352 tests passSummary by cubic
Overrides transitive
deepmerge-tsto8.0.1to close the high/critical security audit gate and hardens the Docker build for backend dependencies. Previouslyprisma@7.9.1pulleddeepmerge-ts@7.1.5(GHSA-ggr8-5vv4-36mx) and thedeps-production-backendstage could fail whenpackages/backend/node_moduleswas absent; now we force8.0.1and ensure the directory exists before COPY.Review notes
overrides: { "deepmerge-ts": "^8.0.1" }in rootpackage.json; regeneratespackage-lock.json.mkdir -p packages/backend/node_modulesto prevent COPY failures when npm hoists all deps to the root.npm ls deepmerge-tsresolves to8.0.1across all workspaces;npm run audit:high,npx prisma generate, TS builds, and shared/backend tests pass unchanged.deepmerge-tsmajor bump; monitor for Prisma tooling regressions.Written for commit c283265. Summary will update on new commits.
Summary by CodeRabbit
Bug Fixes
Chores