Skip to content

fix(deps): patch fast-uri production audit advisories - #29758

Merged
aqrln merged 1 commit into
mainfrom
fix/pnpm-audit
Jul 22, 2026
Merged

fix(deps): patch fast-uri production audit advisories#29758
aqrln merged 1 commit into
mainfrom
fix/pnpm-audit

Conversation

@tensordreams

Copy link
Copy Markdown
Contributor

Overview

pnpm audit --prod (the audit CI gates on in test-template.yml) flags two advisories, both in fast-uri via the shipped dependency path packages/cli > @prisma/dev > @prisma/streams-local > ajv:

Changes

Raises the existing override in pnpm-workspace.yaml from fast-uri@<=3.1.1: '>=3.1.2' to fast-uri@<=3.1.3: '>=3.1.4 <4', resolving fast-uri to 3.1.4. The upper bound keeps the resolution within the ^3.x range ajv declares — without it, pnpm resolves to fast-uri@4.x, a major ajv is not tested against.

The lockfile also picks up incidental re-resolution churn (peer-suffix normalization, libc metadata, small transitive patch bumps). This is what pnpm 11 produces whenever overrides change; a plain pnpm install on an untouched checkout leaves the lockfile alone, so the churn is unavoidable when touching overrides.

Out of scope

Dev-tooling-only advisories reported by the full pnpm audit (vitest, wrangler, jest transitive deps, etc.) are intentionally left untouched, consistent with prior audit fixes — they are not part of any published package's runtime dependency tree.

Verification

  • pnpm audit --prodNo known vulnerabilities found
  • CI=true pnpm install --frozen-lockfile passes

`pnpm audit --prod` flagged two advisories in a shipped dependency path,
both in fast-uri via packages/cli > @prisma/dev > @prisma/streams-local > ajv:

- GHSA-4c8g-83qw-93j6 (host confusion via failed IDN canonicalization),
  patched >=3.1.3
- GHSA-v2hh-gcrm-f6hx (host confusion via literal backslash authority
  delimiter), patched >=3.1.4

Raise the existing fast-uri override from '>=3.1.2' to '>=3.1.4 <4' so it
resolves to 3.1.4; the upper bound keeps the resolution within the ^3.x
range ajv declares. `pnpm audit --prod` is now clean.

The lockfile also picks up incidental re-resolution churn (peer-suffix
normalization, libc metadata, small transitive patch bumps) that pnpm 11
produces whenever overrides change.

Dev-tooling-only advisories (vitest, wrangler, jest transitive deps, etc.)
are intentionally left untouched — they are not part of any published
package's runtime dependency tree, and CI gates on `pnpm audit --prod`.

Signed-off-by: Alexey Orlenko's AI Agent <robot@aqrln.net>
@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 11cabe7d-483b-4901-8894-0a087ed8e447

📥 Commits

Reviewing files that changed from the base of the PR and between 3005a01 and ba76d4b.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Summary by CodeRabbit

  • Chores
    • Updated internal package version constraints to ensure compatible fast-uri versions are resolved.

Walkthrough

Updated the pnpm workspace override for fast-uri to cover versions up to 3.1.3 and enforce versions >=3.1.4 <4.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches the main change: patching fast-uri to address production audit advisories.
Description check ✅ Passed The description is directly related to the override update, the advisories it fixes, and the verification performed.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/pnpm-audit
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch fix/pnpm-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dosubot dosubot Bot added the lgtm This PR has been approved by a maintainer label Jul 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size
packages/client/runtime/index-browser.js 2.29 KB (0%)
packages/client/runtime/index-browser.d.ts 3.37 KB (0%)
packages/cli/build/index.js 110 B (0%)
packages/client/prisma-client-0.0.0.tgz 26.72 MB (-0.01% 🔽)
packages/cli/prisma-0.0.0.tgz 14.04 MB (0%)
packages/bundle-size/da-workers-libsql/output.tgz 1.33 MB (0%)
packages/bundle-size/da-workers-neon/output.tgz 1.39 MB (0%)
packages/bundle-size/da-workers-pg/output.tgz 1.39 MB (0%)
packages/bundle-size/da-workers-planetscale/output.tgz 1.33 MB (0%)
packages/bundle-size/da-workers-d1/output.tgz 1.31 MB (0%)

@codspeed-hq

codspeed-hq Bot commented Jul 22, 2026

Copy link
Copy Markdown

Merging this PR will improve performance by 22.56%

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

⚡ 1 improved benchmark
✅ 16 untouched benchmarks
⏩ 30 skipped benchmarks1

Performance Changes

Benchmark BASE HEAD Efficiency
getBinaryTargetForCurrentPlatform 2.1 ms 1.7 ms +22.56%

Tip

Curious why this is faster? Comment @codspeedbot explain why this is faster on this PR, or directly use the CodSpeed MCP with your agent.


Comparing fix/pnpm-audit (ba76d4b) with main (3005a01)

Open in CodSpeed

Footnotes

  1. 30 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@aqrln
aqrln merged commit fd5e681 into main Jul 22, 2026
254 checks passed
@aqrln
aqrln deleted the fix/pnpm-audit branch July 22, 2026 11:03
aqrln pushed a commit that referenced this pull request Jul 27, 2026
## Overview

Backport of #29758 to the `7.9.x` release branch.

`pnpm audit --prod` (the audit CI gates on in `test-template.yml`) flags
two advisories on `7.9.x`, both in `fast-uri` via the shipped dependency
path `packages/cli > @prisma/dev > @prisma/streams-local > ajv`:

-
[GHSA-4c8g-83qw-93j6](GHSA-4c8g-83qw-93j6)
— host confusion via failed IDN canonicalization (patched `>=3.1.3`)
-
[GHSA-v2hh-gcrm-f6hx](GHSA-v2hh-gcrm-f6hx)
— host confusion via literal backslash authority delimiter (patched
`>=3.1.4`)

The branch still carries `fast-uri@<=3.1.1: '>=3.1.2'`, which resolves
to a version inside both advisories' vulnerable ranges.

## Changes

Raises the existing override in `pnpm-workspace.yaml` from
`fast-uri@<=3.1.1: '>=3.1.2'` to `fast-uri@<=3.1.3: '>=3.1.4 <4'`,
resolving `fast-uri` to 3.1.4. The upper bound keeps the resolution
within the `^3.x` range `ajv` declares — without it, pnpm resolves to
`fast-uri@4.x`, a major `ajv` is not tested against.

The override line is byte-identical to the one already on `main`. Unlike
#29758, the lockfile picks up no incidental re-resolution churn here —
the diff is 12 lines, confined to `fast-uri` moving 3.1.2 → 3.1.4 at
each call site — because `7.9.x`'s lockfile was regenerated recently by
#29795.

## Out of scope

Dev-tooling-only advisories reported by the full `pnpm audit` are
intentionally left untouched, consistent with #29758 and prior audit
fixes — they are not part of any published package's runtime dependency
tree.

## Verification

- `pnpm audit --prod` → `No known vulnerabilities found` (exit 0). This
is the exact command CI gates on.
- `CI=true pnpm install --frozen-lockfile --lockfile-only` passes — no
lockfile drift.
- `fast-uri` resolves to a single version, `3.1.4`, at every site in the
lockfile.

Note: `pnpm build` was **not** run locally — the machine ran out of disk
during `pnpm install`, so no `node_modules` tree could be materialised.
`fast-uri` is a runtime transitive dependency of the published CLI
rather than a build input, and this change touches no source, so `pnpm
audit --prod` is the relevant gate; CI will exercise the build
regardless.
lh0x00 pushed a commit to lh0x00/prisma that referenced this pull request Aug 9, 2026
## Overview

`pnpm audit --prod` (the audit CI gates on in `test-template.yml`) flags
two advisories, both in `fast-uri` via the shipped dependency path
`packages/cli > @prisma/dev > @prisma/streams-local > ajv`:

-
[GHSA-4c8g-83qw-93j6](GHSA-4c8g-83qw-93j6)
— host confusion via failed IDN canonicalization (patched `>=3.1.3`)
-
[GHSA-v2hh-gcrm-f6hx](GHSA-v2hh-gcrm-f6hx)
— host confusion via literal backslash authority delimiter (patched
`>=3.1.4`)

## Changes

Raises the existing override in `pnpm-workspace.yaml` from
`fast-uri@<=3.1.1: '>=3.1.2'` to `fast-uri@<=3.1.3: '>=3.1.4 <4'`,
resolving `fast-uri` to 3.1.4. The upper bound keeps the resolution
within the `^3.x` range `ajv` declares — without it, pnpm resolves to
`fast-uri@4.x`, a major `ajv` is not tested against.

The lockfile also picks up incidental re-resolution churn (peer-suffix
normalization, `libc` metadata, small transitive patch bumps). This is
what pnpm 11 produces whenever overrides change; a plain `pnpm install`
on an untouched checkout leaves the lockfile alone, so the churn is
unavoidable when touching overrides.

## Out of scope

Dev-tooling-only advisories reported by the full `pnpm audit` (vitest,
wrangler, jest transitive deps, etc.) are intentionally left untouched,
consistent with prior audit fixes — they are not part of any published
package's runtime dependency tree.

## Verification

- `pnpm audit --prod` → `No known vulnerabilities found`
- `CI=true pnpm install --frozen-lockfile` passes

Signed-off-by: Alexey Orlenko's AI Agent <robot@aqrln.net>
OIRNOIR pushed a commit to OIRNOIR/YouTube-Helper-Server that referenced this pull request Sep 1, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [@prisma/adapter-pg](https://github.com/prisma/prisma) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/adapter-pg)) | imports | minor | [`7.9.1` -> `7.10.0`](https://renovatebot.com/diffs/npm/@prisma%2fadapter-pg/7.9.1/7.10.0) |
| [@prisma/client](https://www.prisma.io) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/client)) | imports | minor | [`7.9.1` -> `7.10.0`](https://renovatebot.com/diffs/npm/@prisma%2fclient/7.9.1/7.10.0) |

---

### Release Notes

<details>
<summary>prisma/prisma (@&#8203;prisma/adapter-pg)</summary>

### [`v7.10.0`](https://github.com/prisma/orm/releases/tag/7.10.0)

[Compare Source](prisma/orm@7.9.1...7.10.0)

##### Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

##### Highlights

##### Run Prisma 7 alongside Prisma 8

This release introduces `@prisma/prisma7`, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

```sh
npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0
```

Use `prisma` for the directly installed Prisma 8 CLI and `prisma7` for Prisma 7:

```sh
npx prisma --version
npx prisma7 --version

npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push
```

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's `prisma.config.*` files:

```ts
// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'

export default defineConfig({
  schema: 'prisma/schema.prisma',
  migrations: {
    path: 'prisma/migrations',
  },
})
```

Without an explicit `--config` option, Prisma 7 searches for:

1. Root-level `prisma7.config.*` files.
2. `.config/prisma7.*` files.
3. Existing `prisma.config.*` files as a backwards-compatible fallback.

The supported extensions are `.js`, `.ts`, `.mjs`, `.cjs`, `.mts`, and `.cts`. An explicit config path always takes precedence:

```sh
npx prisma7 generate --config ./custom/prisma7.config.ts
```

New projects initialized by the Prisma 7 CLI use `prisma7.config.ts`. Existing projects containing only `prisma.config.*` continue to work without migration or additional warnings. If a `prisma7.config.*` file exists but cannot be loaded, Prisma reports the error rather than silently falling back to another configuration.

The `prisma7` identity is carried through CLI help, version output, shell completion, initialization, migration, database, and generation guidance. Stable Prisma concepts such as `schema.prisma`, Prisma Migrate, `@prisma/client`, and `PRISMA_*` environment variables remain unchanged.

Together, the separate executable and configuration namespace make it possible to operate Prisma 7 and Prisma 8 side by side without command or config-file collisions.

[#&#8203;29949](prisma/orm#29949), [#&#8203;29969](prisma/orm#29969), [#&#8203;29994](prisma/orm#29994), [#&#8203;30000](prisma/orm#30000), [#&#8203;30002](prisma/orm#30002), [#&#8203;30020](prisma/orm#30020)

##### Prisma Studio security hardening

Prisma Studio's local HTTP server now:

- Binds explicitly to `127.0.0.1` instead of all network interfaces.
- Rejects browser requests from origins other than the active `localhost` or `127.0.0.1` Studio URL.
- No longer returns wildcard CORS headers.
- Applies the same protections across Node.js, Bun, and Deno.

This prevents network clients or malicious websites from accessing Studio's database endpoints while Studio is running.

[#&#8203;29890](prisma/orm#29890)

##### Prisma Client

- Fixed `P2002` errors from nested writes so `meta.modelName` identifies the model where the unique constraint violation occurred, including models using `@@map` and `@@schema`. [#&#8203;29628](prisma/orm#29628)
- Fixed automatically batched `findUniqueOrThrow()` calls so every missing record rejects with `P2025`; later misses no longer resolve to `undefined`. [#&#8203;29654](prisma/orm#29654)
- Parameter-chunked statements are now executed atomically in a transaction and rolled back if a later chunk fails. [#&#8203;29771](prisma/orm#29771)
- Improved interactive transaction cleanup during `$disconnect()`, including transactions whose driver-level startup is still in progress. [#&#8203;28768](prisma/orm#28768)
- Prevented transaction cleanup failures after a timeout or backend termination from becoming unhandled promise rejections. [#&#8203;29611](prisma/orm#29611)
- Fixed fluent relation queries when relation fields are literally named `select` or `include`. [#&#8203;29683](prisma/orm#29683)
- Fixed handling of `Date` and `Uint8Array` values created in other JavaScript realms, such as iframes, jsdom, and Node.js `vm` contexts. [#&#8203;29177](prisma/orm#29177)
- Invalid `Date` values passed to `$queryRaw` or `$executeRaw` now throw `PrismaClientValidationError` instead of a generic error. [#&#8203;29718](prisma/orm#29718)
- Fixed `moduleFormat` inference for the `prisma-client` generator in TypeScript projects using `module: "node16"` or `"nodenext"`. Generated output now follows the nearest `package.json` `type`, defaulting to CommonJS when absent. [#&#8203;29712](prisma/orm#29712)
- Deserialized `Bytes` values now own standalone `ArrayBuffer`s rather than exposing unrelated contents from Node.js's shared `Buffer` pool. This applies to both regular and raw query results. [#&#8203;29701](prisma/orm#29701)
- Fixed an incorrect logging context in the remote executor, including Accelerate-backed query execution. [#&#8203;28892](prisma/orm#28892)

##### Client extensions and observability

- Result-extension `compute` callbacks now receive the current model name as a typed second argument:

  ```ts
  compute(data, modelName) {
    // ...
  }
  ```

  The model name is also preserved when multiple extensions compose the same computed field. [#&#8203;29782](prisma/orm#29782)

- Improved OpenTelemetry context for remotely executed queries:

  - `$on('query')` callbacks run within the matching `db_query` span.
  - Events from one operation share the same trace.
  - Error events are recorded as span exceptions.
  - Log events continue to be emitted when tracing is disabled or their reported span is unavailable.

  [#&#8203;28892](prisma/orm#28892)

##### Driver adapters

##### MariaDB

- `@prisma/adapter-mariadb` now accepts an existing `mariadb` pool. External pools remain caller-owned unless `disposeExternalPool: true` is supplied. [#&#8203;27992](prisma/orm#27992)
- Fixed pooled connection leaks during commit, rollback, and failed transaction startup. Connections are now returned with `release()` and transaction-specific listeners are removed before reuse. [#&#8203;29612](prisma/orm#29612)
- Added support for bracketed IPv6 addresses in both `mysql://` and `mariadb://` connection strings. [#&#8203;29026](prisma/orm#29026)
- Prevented malformed connection strings from exposing embedded passwords in retained debug output and diagnostic reports. [#&#8203;27992](prisma/orm#27992)

##### PostgreSQL, Neon, and Prisma Postgres Serverless

- PostgreSQL deadlocks using SQLSTATE `40P01` are now reported as `P2034` transaction write conflicts. [#&#8203;29717](prisma/orm#29717)
- PostgreSQL `RESTRICT` violations using SQLSTATE `23001` are now reported as `P2003`, preserving an available field or constraint name. [#&#8203;29554](prisma/orm#29554)
- `@prisma/adapter-pg` now preserves database constraint names when reporting unique constraint violations through `P2002`. [#&#8203;29587](prisma/orm#29587)
- Prisma Postgres Serverless now prefers the named constraint for `P2002`, falling back to parsed field names when no constraint name is available. [#&#8203;29801](prisma/orm#29801)
- Fixed Neon HTTP adapter serialization for typed parameters such as `Bytes` and `DateTime`. [#&#8203;29747](prisma/orm#29747)

##### SQLite

- `@prisma/adapter-better-sqlite3` now converts previously unhandled SQLite result codes into typed database errors instead of exposing raw driver errors.
- The complete `SQLITE_BUSY` family is now mapped to socket timeout errors, with numeric extended result codes preserved where available.

[#&#8203;29794](prisma/orm#29794)

##### CLI and Migrate

- `prisma generate` can now offer to install Prisma's agent skills. The opt-in prompt:

  - Is shown at most once per machine.
  - Is skipped in CI, containers, Git hooks, npm lifecycle scripts, and watch mode.
  - Is skipped when `--no-hints` is used or Prisma skills are already installed.
  - Times out after 30 seconds.
  - Never causes generation to fail if installation is unsuccessful.

  [#&#8203;29690](prisma/orm#29690)

- A globally installed CLI now warns during `prisma generate` when its version differs from the project's local `prisma` or `@prisma/client`, and recommends running the local CLI. The check is best-effort and does not fail generation. [#&#8203;29593](prisma/orm#29593)

- `prisma version` and `prisma version --json` now include the resolved Prisma CLI package path, making global-versus-local installation issues easier to diagnose. [#&#8203;29573](prisma/orm#29573)

- Empty or generator-only schema files now report `Schema must contain a datasource block` from `db pull`, `db push`, and `migrate dev`, rather than reaching the schema engine and potentially producing inconsistent errors. [#&#8203;29657](prisma/orm#29657)

- CLI commands now tolerate corrupt, unreadable, or unwritable command-state files. Invalid state is reinitialized, writes are atomic, and persistence failures fall back to in-memory state. [#&#8203;29609](prisma/orm#29609)

- Studio now recognizes semicolon-delimited `sqlserver://` connection strings before reporting the existing explicit message that SQL Server is not supported by Studio. [#&#8203;29623](prisma/orm#29623)

- The AI-agent safety checkpoint now also covers interactive `prisma db push` confirmations involving data-loss warnings, rather than only invocations using `--accept-data-loss`. [#&#8203;29793](prisma/orm#29793)

##### Performance and reliability

- Optimized query-plan execution by eagerly evaluating plans with one unconditional database operation and synchronously interpreting the remaining pure plan. Cached plans remain immutable. [#&#8203;29004](prisma/orm#29004)
- Prevented call-stack overflows when rendering very large parameter lists or combining chunked results containing hundreds of thousands of rows. [#&#8203;29751](prisma/orm#29751)
- Reduced ordinary query setup overhead by constructing fluent-relation field maps lazily and in linear time. Non-fluent queries no longer build this map. [#&#8203;29752](prisma/orm#29752)

##### Dependencies

- Updated the transitive `fast-uri` dependency to a patched release addressing production audit advisories affecting versions through `3.1.3`. [#&#8203;29758](prisma/orm#29758)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMC4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Reviewed-on: https://git.oirnoir.dev/OIRNOIR/YouTube-Helper-Server/pulls/41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm This PR has been approved by a maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants