Skip to content

chore: refresh lockfile to resolve audit vulnerabilities#1

Merged
starmorph merged 1 commit intomainfrom
cursor/ci-failure-investigation-9af7
Mar 8, 2026
Merged

chore: refresh lockfile to resolve audit vulnerabilities#1
starmorph merged 1 commit intomainfrom
cursor/ci-failure-investigation-9af7

Conversation

@cursor
Copy link

@cursor cursor bot commented Mar 8, 2026

Regenerates pnpm-lock.yaml so @modelcontextprotocol/sdk transitive dependencies resolve to patched versions (hono, @hono/node-server, express-rate-limit), fixing the failing audit CI check.

Open in Web View Automation 


Note

Medium Risk
Although changes are limited to the lockfile, they upgrade runtime networking/auth-related dependencies (express-rate-limit, hono, jose), which can introduce subtle behavior changes in production.

Overview
Refreshes pnpm-lock.yaml so @modelcontextprotocol/sdk resolves to newer transitive versions, including hono/@hono/node-server, express-rate-limit (and its ip-address dependency), and jose.

No application code changes; this is strictly a lockfile update intended to address dependency/audit findings.

Written by Cursor Bugbot for commit ba5fdce. This will update automatically on new commits. Configure here.

Co-authored-by: Dylan Boudro <starmorph@users.noreply.github.com>
@starmorph starmorph marked this pull request as ready for review March 8, 2026 23:56
@starmorph starmorph self-requested a review March 8, 2026 23:56
@starmorph starmorph merged commit cd07d0b into main Mar 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants