chore(deps): bump ip-address from 10.5.0 to 10.7.2 - #990
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.5.0 to 10.7.2. - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.5.0...v10.7.2) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.7.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
freshtonic
left a comment
There was a problem hiding this comment.
Automated review of a2853e40. The change is pnpm-lock.yaml only.
The security fix is correct. This PR closes Dependabot alert #216 (GHSA-2vr4-cq9g-pvrc, NAT64 range SSRF, fixed in 10.5.1). ip-address moves to 10.7.2. The path is packages/wizard → @anthropic-ai/claude-agent-sdk → @modelcontextprotocol/sdk → express-rate-limit → ip-address. No changeset is necessary. A lockfile change does not change the published package surface.
The lockfile change is larger than the title says. The re-resolution also moved these transitives:
- MCP SDK subtree:
express-rate-limit8.6.2→8.7.0,hono4.13.7→4.13.11,jose6.2.9→6.2.12,negotiator1.0.0→1.1.0,proxy-addr2.0.7→2.0.8 - vite 7.3.6 subtree:
esbuild0.28.1→0.28.2,rollup4.60.4→4.63.5,postcss8.5.26→8.5.28,tinyglobby0.2.16→0.2.17,picomatch4.0.4→4.0.7,nanoid,@types/estree shell-quote1.10.0→1.11.0
These are all minor or patch updates, and the vite subtree is dev-only. But a security update does not use the Dependabot 7-day cooldown. Also, pnpm install --frozen-lockfile does not examine minimumReleaseAge. Thus a green CI does not show that these collateral versions obey the 7-day cooldown (minimumReleaseAge: 10080 in pnpm-workspace.yaml). I could not query the registry from this environment. Before you merge, do this check:
npm view rollup time --json | jq ".\"4.63.5\"" # repeat for each package above
Examine one new native binary. rollup@4.63.5 adds a new optional dependency, @napi-rs/lzma-linux-x64-gnu@1.5.1. The lockfile has only the linux-x64-gnu variant, with no equivalent packages for the other platforms. That package installs on CI runners (Linux x64). It is possibly a correct upstream change. But it is a new prebuilt binary in the tree, so confirm that it comes from the rollup package manifest before you merge.
CI: Lint, E2E, Bun, OSV and ci-required pass. Run Tests (Node 22), Run Tests (Node 24) and Run WASM E2E Tests (Deno) did not complete when I did this review.
Not a blocker: Dependabot cannot find the supply-chain label, which .github/dependabot.yml names for all four ecosystems. Create the label, or remove it from the config.
I did not approve because of the cooldown and binary checks. When they are satisfactory and the pending jobs pass, this PR is safe to merge.
Bumps ip-address from 10.5.0 to 10.7.2.
Release notes
Sourced from ip-address's releases.
Commits
974b48d10.7.24dfe8e5Accept an arpa suffix in any case and without the root dot in fromArpa (#227)f0c25df10.7.18b34a21Merge commit from fork13b6155Merge commit from fork469ead1Reject an address longer than the family allows before parsing it1343629Report an address of the other family as not contained4c2184aBump js-yaml and brace-expansion in the lockfile (#226)2b7cab510.7.087fae23Add offset() and nextNetwork(), accept prefix-length ip6.arpa names, correct ...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.