Skip to content

fix: bump proxy-addr, fast-uri, js-yaml, hono, qs, @humanfs/node to patched versions - #86

Open
devin-ai-integration[bot] wants to merge 2 commits into
mainfrom
devin/dep-vulns-minor/2026-09-28
Open

devin-ai-integration[bot] wants to merge 2 commits into
mainfrom
devin/dep-vulns-minor/2026-09-28

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Dependency vulnerability fixes (automated)

Generated by the Devin Dependency Security Vuln Fix automation run on 2026-10-05.
Change type: Minor/patch version bumps — manifest and lockfile changes, no source edits.

Warning

We're not just looking for a review like a normal PR. Security can offer this fix as a recommendation, but doesn't have the tooling or domain knowledge to safely verify changes like this end-to-end for each repo. Please review, test, and own deployment before merging. For more information: https://launchdarkly.atlassian.net/wiki/spaces/SEC/pages/5360943572/Dependency+Vulnerability+Remediation+with+Devin.

Findings addressed

Package Ecosystem Bump type Current → Target Severity Age Source(s) Advisory
proxy-addr npm Patch 2.0.7 → 2.0.8 Critical 4d (Wiz) Wiz CVE-2026-90711
fast-uri npm Patch 3.1.5 → 3.1.6 High 32d Dependabot, Wiz GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp
js-yaml npm Patch 4.3.1 → 4.3.2 High 22d Dependabot, Wiz GHSA-2883-xcg3-v3hh
hono npm Patch 4.13.2 → 4.13.5 Medium 25d Dependabot GHSA-crvj-82cr-hjcx, GHSA-g6gw-c38x-mqfc, GHSA-gqvv-2mrq-wpjv
qs npm Minor 6.15.3 → 6.16.0 Medium 32d Dependabot GHSA-4mjr-xmp4-gh2g, GHSA-x5fp-wj9c-mxmx
@humanfs/node npm Patch 0.16.6 → 0.16.8 Medium 32d Dependabot GHSA-p498-v437-472g

Deferred / excluded findings

  • Still within the 7-day hold — fast-uri 3.1.6 → 3.1.8 (Wiz-only, High/Medium, 4d); ip-address 10.5.0 → 10.5.1 (Medium, 6d).
  • Wiz Go findings matched by name belong to an unrelated basy-mcp-server-slop asset and were excluded.

Verification

  • Install: ✅ (npm ci)
  • Build: ✅ (npm run build); smoke-tested mcp start --transport sse → /sse returns 200 text/event-stream
  • Tests: ✅ via CI
  • Lint: ✅ (npm run lint)

Link to Devin session: https://app.devin.ai/sessions/130a63ac1d5c413689626c1835f2f859
Open in Devin Desktop: https://app.devin.ai/desktop/session/130a63ac1d5c413689626c1835f2f859?variant=devin

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration devin-ai-integration Bot added automated-security-deps Automated dependency security fixes devin-pr PR created by Devin exempt Exempt from stale automation labels Sep 28, 2026
@devin-ai-integration
devin-ai-integration Bot requested a review from a team September 28, 2026 13:12
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: bump vulnerable npm dependencies to patched versions fix: bump proxy-addr, fast-uri, js-yaml, hono, qs, @humanfs/node to patched versions Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated-security-deps Automated dependency security fixes devin-pr PR created by Devin exempt Exempt from stale automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants