Skip to content

fix(security): update vulnerable Cuabot dependencies - #2453

Closed
0xjohnnydev wants to merge 1 commit into
mainfrom
agent/security-cuabot-20260722
Closed

fix(security): update vulnerable Cuabot dependencies#2453
0xjohnnydev wants to merge 1 commit into
mainfrom
agent/security-cuabot-20260722

Conversation

@0xjohnnydev

Copy link
Copy Markdown
Contributor

Summary

Update Cuabot packages that GitHub marked as vulnerable.

Why

The new alerts affect request handling, URL parsing, and image processing dependencies used by Cuabot.

What changed

  • Update Hono to 4.12.27.
  • Update @hono/node-server to 2.0.5.
  • Update fast-uri to 3.1.4.
  • Update Sharp to the patched 0.35 release line.

Definition of Done

Test plan

  • pnpm install --frozen-lockfile --ignore-scripts
  • pnpm build
  • Import Sharp and confirm its runtime version.

Supersedes Dependabot PRs #1463, #1847, and #2423.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Publishable packages changed

  • npm/cuabot

Add release:<service> labels to auto-release on merge (+ optional bump:minor or bump:major, default is patch).
Or add no-release to skip.

@0xjohnnydev
0xjohnnydev marked this pull request as ready for review July 22, 2026 18:18
@0xjohnnydev

Copy link
Copy Markdown
Contributor Author

Superseded by #2719, which carries the current Cuabot security resolutions and validates the full package graph. Closing this older split PR so review stays on the canonical dependency draft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant