[PR #7599] Correct dependencies #7433

Open
opened 2026-03-13 13:36:11 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/better-auth/better-auth/pull/7599
Author: @Bekacru
Created: 1/24/2026
Status: 🔄 Open

Base: canaryHead: cursor/correct-dependencies-f854


📝 Commits (1)

  • 7d48e53 fix: resolve 34 security vulnerabilities in dependencies

📊 Changes

6 files changed (+754 additions, -2242 deletions)

View changed files

📝 e2e/integration/solid-vinxi/package.json (+3 -3)
📝 e2e/smoke/test/fixtures/cloudflare/package.json (+2 -2)
📝 package.json (+25 -0)
📝 packages/better-auth/package.json (+1 -1)
📝 pnpm-lock.yaml (+722 -2235)
📝 test/package.json (+1 -1)

📄 Description

Fixes 34 security vulnerabilities by updating direct dependencies and adding pnpm overrides.

Added pnpm overrides in root package.json to fix transitive dependencies:

  • glob, qs, cookie, lodash, lodash-es, hono, h3, devalue
  • @remix-run/react, @remix-run/router, react-router, svelte, undici
  • brace-expansion, diff, validator, tar, seroval, esbuild, js-yaml, mdast-util-to-hast

Updated direct dependencies:

  • test/package.json: undici ^7.0.0^7.18.2
  • packages/better-auth/package.json: @sveltejs/kit ^2.49.5^2.50.1
  • e2e/integration/solid-vinxi/package.json: @solidjs/start ^1.1.7^1.2.1, vinxi ^0.5.8^0.5.11, solid-js ^1.9.7^1.9.11
  • e2e/smoke/test/fixtures/cloudflare/package.json: @cloudflare/vitest-pool-workers ^0.8.69^0.12.6, wrangler 4.33.2^4.60.0

All checks pass (format:check, lint, typecheck) and pnpm audit now reports no known vulnerabilities.


Slack Thread

Open in Cursor Open in Web


Summary by cubic

Resolved 34 security vulnerabilities by updating direct dependencies and adding pnpm overrides for vulnerable transitive packages. pnpm audit is now clean and format:check, lint, and typecheck all pass.

  • Dependencies
    • Added root pnpm overrides to bump vulnerable transitive packages (glob, lodash/lodash-es, qs, cookie, hono, h3, devalue, @remix-run/react/router, react-router, svelte, undici, brace-expansion, diff, validator, tar, seroval, esbuild, js-yaml, mdast-util-to-hast).
    • Updated direct packages: undici (test), @sveltejs/kit (better-auth), solid/vinxi/solid-js (e2e), Cloudflare tooling (vitest pool workers, wrangler) in smoke tests.
    • Regenerated pnpm-lock.yaml.

Written for commit 7d48e539d5. Summary will update on new commits.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/better-auth/better-auth/pull/7599 **Author:** [@Bekacru](https://github.com/Bekacru) **Created:** 1/24/2026 **Status:** 🔄 Open **Base:** `canary` ← **Head:** `cursor/correct-dependencies-f854` --- ### 📝 Commits (1) - [`7d48e53`](https://github.com/better-auth/better-auth/commit/7d48e539d594284a28b098cb47424f2b0f0ecaad) fix: resolve 34 security vulnerabilities in dependencies ### 📊 Changes **6 files changed** (+754 additions, -2242 deletions) <details> <summary>View changed files</summary> 📝 `e2e/integration/solid-vinxi/package.json` (+3 -3) 📝 `e2e/smoke/test/fixtures/cloudflare/package.json` (+2 -2) 📝 `package.json` (+25 -0) 📝 `packages/better-auth/package.json` (+1 -1) 📝 `pnpm-lock.yaml` (+722 -2235) 📝 `test/package.json` (+1 -1) </details> ### 📄 Description Fixes 34 security vulnerabilities by updating direct dependencies and adding pnpm overrides. **Added pnpm overrides in root `package.json`** to fix transitive dependencies: - `glob`, `qs`, `cookie`, `lodash`, `lodash-es`, `hono`, `h3`, `devalue` - `@remix-run/react`, `@remix-run/router`, `react-router`, `svelte`, `undici` - `brace-expansion`, `diff`, `validator`, `tar`, `seroval`, `esbuild`, `js-yaml`, `mdast-util-to-hast` **Updated direct dependencies:** - `test/package.json`: undici `^7.0.0` → `^7.18.2` - `packages/better-auth/package.json`: @sveltejs/kit `^2.49.5` → `^2.50.1` - `e2e/integration/solid-vinxi/package.json`: @solidjs/start `^1.1.7` → `^1.2.1`, vinxi `^0.5.8` → `^0.5.11`, solid-js `^1.9.7` → `^1.9.11` - `e2e/smoke/test/fixtures/cloudflare/package.json`: @cloudflare/vitest-pool-workers `^0.8.69` → `^0.12.6`, wrangler `4.33.2` → `^4.60.0` All checks pass (`format:check`, `lint`, `typecheck`) and `pnpm audit` now reports no known vulnerabilities. --- [Slack Thread](https://betterauth.slack.com/archives/C0A8B5BARUK/p1769289942671509?thread_ts=1769289942.671509&cid=C0A8B5BARUK) <a href="https://cursor.com/background-agent?bcId=bc-fe4c489e-4d70-491f-b518-d5a0fa5bac5f"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/open-in-cursor-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/open-in-cursor-light.svg"><img alt="Open in Cursor" src="https://cursor.com/open-in-cursor.svg"></picture></a>&nbsp;<a href="https://cursor.com/agents?id=bc-fe4c489e-4d70-491f-b518-d5a0fa5bac5f"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/open-in-web-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/open-in-web-light.svg"><img alt="Open in Web" src="https://cursor.com/open-in-web.svg"></picture></a> <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Resolved 34 security vulnerabilities by updating direct dependencies and adding pnpm overrides for vulnerable transitive packages. pnpm audit is now clean and format:check, lint, and typecheck all pass. - **Dependencies** - Added root pnpm overrides to bump vulnerable transitive packages (glob, lodash/lodash-es, qs, cookie, hono, h3, devalue, @remix-run/react/router, react-router, svelte, undici, brace-expansion, diff, validator, tar, seroval, esbuild, js-yaml, mdast-util-to-hast). - Updated direct packages: undici (test), @sveltejs/kit (better-auth), solid/vinxi/solid-js (e2e), Cloudflare tooling (vitest pool workers, wrangler) in smoke tests. - Regenerated pnpm-lock.yaml. <sup>Written for commit 7d48e539d594284a28b098cb47424f2b0f0ecaad. Summary will update on new commits.</sup> <!-- End of auto-generated description by cubic. --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-03-13 13:36:11 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/better-auth#7433