Skip to content

fix(deps): override qs to 6.16.0 - #159

Draft
joshuaboys wants to merge 1 commit into
mainfrom
dependabot/fix/qs
Draft

joshuaboys wants to merge 1 commit into
mainfrom
dependabot/fix/qs

Conversation

@joshuaboys

Copy link
Copy Markdown
Contributor

Dependabot Alert Fix

Alerts addressed: #53, #54
Severity: medium
Strategy: Override (qs@^6.16.0 in mcp/pnpm-workspace.yaml)

What was vulnerable

qs@6.15.2 via express@5.2.1 ← @modelcontextprotocol/sdk@1.29.0:

This MCP server uses stdio only; Express/querystring is unused. Both issues still need the patched version so scanners close.

What was done

  • Added qs: ^6.16.0 to the existing MCP pnpm overrides (same pattern as hono/body-parser).
  • Refreshed mcp/pnpm-lock.yaml so the tree resolves qs@6.16.0.
  • Did not bump @modelcontextprotocol/sdk; 1.31.0 still depends on express@^5.2.1, which does not pull a patched qs on its own.

Research sources

What was tested

  • Build: n/a (lockfile override only; no compile step for mcp/)
  • MCP tests: pass (14 tests)
  • CLI suite (./test/run.sh): pass (including MCP server ORCH-006)
  • Affected packages: mcp/ (aps-mcp)
  • Pre-existing failures (not caused by this change): none

Escalated items

(none)

Force patched qs into the MCP SDK / Express tree so Dependabot
alerts #53 and #54 (CVE-2026-82417, CVE-2026-82562) resolve.
Parent ranges already allow 6.16.0; the lockfile was stuck on 6.15.2.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant