Skip to content

chore: 보안 취약 의존성 업데이트 - #585

Merged
manNomi merged 1 commit into
mainfrom
fix/issue-584-security-alerts-direct
Jun 26, 2026
Merged

chore: 보안 취약 의존성 업데이트#585
manNomi merged 1 commit into
mainfrom
fix/issue-584-security-alerts-direct

Conversation

@manNomi

@manNomi manNomi commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

관련 이슈

작업 내용

  • Dependabot alert를 줄이기 위해 직접 의존성을 업데이트했습니다.
    • axios, firebase-admin, @sentry/nextjs, vite, vitest, jsdom, turbo, @commitlint/*
  • 직접 업데이트로 해결되지 않는 transitive 취약점은 root pnpm.overrides로 patched 버전을 고정했습니다.
    • protobufjs, form-data, minimatch, picomatch, rollup, svgo, ws, yaml
  • packages/bruno-api-typescript의 별도 npm lockfile도 업데이트하고, npm overrides를 추가했습니다.

특이 사항

  • 로컬 기준 pnpm auditpackages/bruno-api-typescriptnpm audit는 모두 0건입니다.
  • GitHub Security 탭은 default branch 기준이라, 이 PR이 merge되고 Dependabot이 다시 스캔하기 전까지는 기존 77건이 계속 보일 수 있습니다.
  • vitest는 보안 알림 정리를 위해 3.x에서 4.x로 올렸고, admin 테스트는 통과했습니다.
  • 로컬 Node가 v23.10.0이라 프로젝트 요구 버전인 Node 22.x 경고가 표시됩니다.
  • 기존 peer warning이 남아 있습니다: @tailwindcss/vite의 Vite peer range, nitro > unstoragechokidar peer. 관련 ci/build는 통과했습니다.

리뷰 요구사항 (선택)

  • pnpm.overrides 범위가 과하게 넓지 않은지 확인 부탁드립니다.
  • firebase-admin/@sentry/nextjs/vitest 업데이트 영향 범위를 한 번 더 봐주세요.

검증

  • git diff --check
  • pnpm install --frozen-lockfile
  • pnpm audit --json → vulnerabilities 0건
  • cd packages/bruno-api-typescript && npm audit --json → vulnerabilities 0건
  • pnpm --filter @solid-connect/web run ci:check
  • pnpm --filter @solid-connect/university-web run ci:check
  • pnpm --filter @solid-connect/admin run ci:check
  • pnpm --filter @solid-connect/admin test
  • NODE_ENV=production UNIVERSITY_WEB_DOMAIN=https://university-web.ci.local pnpm --filter @solid-connect/web run build
  • NODE_ENV=production pnpm --filter @solid-connect/university-web run build
  • NODE_ENV=production pnpm --filter @solid-connect/admin run build
  • pnpm --filter bruno-api-typescript run build
  • pnpm --filter @solid-connect/api-schema run typecheck
  • git push pre-push parity checks: web/university-web/admin ci:check 및 production build 통과

확인된 기존 테스트 이슈

  • pnpm --filter bruno-api-typescript testtests/fixtures/bruno fixture 디렉터리가 없어 실패합니다. 이번 dependency 변경 전제와 별개로 fixture가 repo에 없는 상태입니다.

@vercel

vercel Bot commented Jun 26, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
solid-connect-university-web Ready Ready Preview, Comment Jun 26, 2026 6:27am
solid-connect-web-admin Ready Ready Preview, Comment Jun 26, 2026 6:27am
solid-connection-web Ready Ready Preview, Comment Jun 26, 2026 6:27am

@coderabbitai

coderabbitai Bot commented Jun 26, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@manNomi, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 20 minutes and 9 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more credits in the billing tab to continue.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e982b53c-3c51-478f-b738-e505b9e994e3

📥 Commits

Reviewing files that changed from the base of the PR and between 5ceca2f and 93b42bb.

⛔ Files ignored due to path filters (2)
  • packages/bruno-api-typescript/package-lock.json is excluded by !**/package-lock.json
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (6)
  • apps/admin/package.json
  • apps/university-web/package.json
  • apps/web/package.json
  • package.json
  • packages/api-schema/package.json
  • packages/bruno-api-typescript/package.json
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/issue-584-security-alerts-direct

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 93b42bb7e2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"version": "10.5.0",
"resolved": "https://registry.npmjs.org/glob/-/glob-10.5.0.tgz",
"integrity": "sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==",
"deprecated": "Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid locking the CLI to deprecated glob

When packages/bruno-api-typescript is installed with its standalone npm lockfile, this now resolves glob to 10.5.0, and the lockfile itself records that release as deprecated because old glob versions contain public security vulnerabilities fixed in the current version. Since this change is explicitly a security dependency update, leaving a deprecated vulnerable direct dependency here will keep standalone installs/audits of this package failing; upgrade to a non-deprecated glob release or remove the unused dependency.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant