Skip to content

Fix Dependabot security alerts - #7

Merged
roshni-shah-promact merged 1 commit into
masterfrom
chore/fix-dependabot-alerts
Oct 5, 2026
Merged

roshni-shah-promact merged 1 commit into
masterfrom
chore/fix-dependabot-alerts

Conversation

@roshni-shah-promact

@roshni-shah-promact roshni-shah-promact commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Resolves all open Dependabot alerts (nodemailer, axios, ip-address, http-cache-semantics, js-yaml, brace-expansion). Supersedes #2, #3, #4 and #5. Dependabot should close them automatically once this merges.

Package Before After Pulled in by Shipped to consumers?
nodemailer 6.10.1 10.0.14 (major) email-service (direct) yes
axios 1.19.0 1.20.0 email-service → @sendgrid/mail yes
ip-address 10.5.0 10.7.3 feature-flag-management → unleash-client yes
http-cache-semantics 4.2.0 4.3.0 feature-flag-management → unleash-client yes
js-yaml 3.15.1 / 4.3.1 3.15.2 / 4.3.2 eslint, jest no (dev only)
brace-expansion 1.1.18 / 5.0.9 1.1.21 / 5.0.12 eslint, typescript-eslint no (dev only)

unleash-client is bumped to 6.12.2 so its own range requires the patched ip-address. Consumers installing @promact/feature-flag-management then can't resolve the vulnerable version.

The nodemailer major bump needed no code changes. It requires Node ≥ 20, and this repo already requires 22.

Not addressed

  • npm audit also reports braces ≤ 3.0.3 (GHSA-vfj7-8cjw-p6xm), reached via jest → micromatch. No patched version of braces exists. The only fix is upgrading Jest 29 → 30, and Jest is dev-only, never shipped. That belongs in a separate PR.
  • mailcomposer (used by the SES provider to build raw MIME messages) is marked unmaintained on npm. It isn't flagged by any advisory. It could later be replaced by nodemailer's built-in MailComposer.

Testing

  • npm run build, npm run lint, npm test: 79/79 passing.
  • Re-packed all three packages and installed the tarballs into a fresh sample consumer project:
    • SMTP send through nodemailer 10 against a real local SMTP server (STARTTLS + auth): delivered, with the correct From, Subject, HTML body and no empty Cc.
    • Unleash 6.12.2's real SDK against a local fake server: enabled/unknown flags, raw Authorization header, subscription constraint.
    • PostHog, LaunchDarkly (offline) and Azure Blob (Azurite: upload/exists/download/SAS URL/pagination/delete) unchanged and passing.
    • TypeScript strict typecheck plus CJS and ESM imports OK.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

- email-service: nodemailer 6.10.1 -> 10.0.14, @types/nodemailer -> 8.0.2
- feature-flag-management: unleash-client 6.12.1 -> 6.12.2
- Lockfile: axios 1.20.0, ip-address 10.7.3, http-cache-semantics 4.3.0,
  js-yaml 3.15.2/4.3.2, brace-expansion 1.1.21/5.0.12

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 5132e445-03d6-46ce-bc49-d252609c6b82
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@roshni-shah-promact
roshni-shah-promact merged commit 980e8c4 into master Oct 5, 2026
3 checks passed
@roshni-shah-promact
roshni-shah-promact deleted the chore/fix-dependabot-alerts branch October 5, 2026 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants