Skip to content

Fix remaining npm dependency vulnerabilities - #373

Merged
vicancy merged 1 commit into
mainfrom
vicancy-fix-dependency-vulnerabilities
Aug 5, 2026
Merged

Fix remaining npm dependency vulnerabilities#373
vicancy merged 1 commit into
mainfrom
vicancy-fix-dependency-vulnerabilities

Conversation

@vicancy

@vicancy vicancy commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • pin fast-uri 3.1.5 for the Whiteboard MCP server and upgrade its MCP/Hono adapter chain to patched releases
  • pin brace-expansion 5.0.9 in both affected Azure Functions v4 samples
  • preserve the already-patched hono 4.13.0 and ip-address 10.4.0 resolutions while using reproducible HTTPS release tarballs where the npm mirror has not yet published the advisory fixes

Validation

  • npm ci --ignore-scripts and npm audit in all three changed samples (0 vulnerabilities)
  • npm test in both Azure Functions samples
  • AJV URI validation and MCP SDK import smoke test in samples/Whiteboard/MCPServer

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@vicancy
vicancy merged commit 7ee759c into main Aug 5, 2026
3 checks passed
@vicancy
vicancy deleted the vicancy-fix-dependency-vulnerabilities branch August 5, 2026 23:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants