Repository navigation
v0.2.6 — qs security patch
A security-patch release. It moves the qs transitive dependency to 6.16.0,
clearing two moderate advisories from the runtime dependency tree. No runtime
behaviour changed.
Security
qs6.15.3 → 6.16.0, clearing two moderate advisories:
GHSA-4mjr-xmp4-gh2g
(denial of service via attacker-controlledisBuffer) and
GHSA-x5fp-wj9c-mxmx
(array-limit bypass via bracket-key comma parsing). Both alerts were
runtime scope —qsis reached through
@stride/mcp > @modelcontextprotocol/sdk > express > body-parser.
body-parser@2.3.0declaresqs: ^6.15.2andexpress@5.2.1declares
^6.14.0, so 6.16.0 satisfies both parents and needs nopnpm.overrides
pin — only the lockfile was holding the stale resolution. (#92)
Knowingly deferred
esbuild 0.27.7
(GHSA-g7r4-m6w7-qqqr,
low, dev scope) is left in place. tsup@8.5.1 — the current latest — pins
esbuild: ^0.27.0, so 0.28.1+ cannot be reached without forcing an override
against its declared range, and the vulnerable path is esbuild's own
development server, which tsup never starts. vite@8.2.2 already resolves
esbuild 0.28.2 independently. To be revisited when tsup widens its range.
Full changelog: v0.2.5...v0.2.6