fix(deps): patch HIGH/CRITICAL advisories
masterplan-lock / check (push) Successful in 6s
masterplan-lock / check (pull_request) Successful in 33s

Lockfile-level update of the packages trivy flags on main, all within
their current major:

- next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL)
- js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375)
- nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj)
- sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c)
- undici 6.28.0 -> 6.29.0 (CVE-2026-19534)
- brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev)
- minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev)

next, js-yaml and nodemailer were exact-pinned, so their pins move too.
PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without
it the pinned-dep guard fails.

Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major
bump of a direct dependency, left for a separate reviewed change).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
Claude Code
2026-09-30 17:17:51 +02:00
co-authored by Claude Sonnet 5.5
parent 23f99f94b9
commit 0250b4bab2
3 changed files with 250 additions and 211 deletions
+4 -2
View File
@@ -758,10 +758,12 @@ const PINNED_DEPS = [
},
{
name: 'nodemailer',
version: '9.0.5',
version: '9.1.1',
reason:
'SMTP mailer for self-hosts (extensions/general/email/lib/smtp-service.ts). Zero-dependency MIT-0 ' +
'package on the outbound-mail path; bumps are deliberate, reviewed PRs (audit surface), never silent.',
'package on the outbound-mail path; bumps are deliberate, reviewed PRs (audit surface), never silent. ' +
'Bumped 9.0.5 -> 9.1.1 (2026-09-30) for HIGH advisories GHSA-2x7j-588g-ccc2 / GHSA-8m3c-c648-2xjj, ' +
'same major; the rest of the 9.x advisories are only fixed in 10.x (major, separate reviewed PR).',
},
]