Skip to content

fix(deps): refresh express-rate-limit to pull in patched ip-address - #1245

Draft
ChrisPrapas wants to merge 1 commit into
mksglu:nextfrom
ChrisPrapas:fix/ip-address-advisory
Draft

ChrisPrapas wants to merge 1 commit into
mksglu:nextfrom
ChrisPrapas:fix/ip-address-advisory

Conversation

@ChrisPrapas

Copy link
Copy Markdown

What / Why / How

Fixes #1225.

bun.lock resolved express-rate-limit@8.2.1, which depends on the exact version ip-address@10.0.1. That version is affected by five published advisories, all fixed in 10.7.1 or earlier:

The package is only reached through @modelcontextprotocol/sdk -> express-rate-limit, so the exposure is limited to that chain. Refreshing the lock is still the cheapest way to clear the advisories.

This PR only refreshes the two transitive lock entries (bun update express-rate-limit ip-address --lockfile-only):

  • express-rate-limit 8.2.1 -> 8.7.0 (now depends on ip-address ^10.2.0)
  • ip-address 10.0.1 -> 10.7.3

package.json is unchanged. The ^8.2.1 range from the SDK already allows the new version.

Affected platforms

  • All platforms

Test plan

No source changes, so no new tests. Checked on a fresh checkout of next:

  • bun install --frozen-lockfile accepts the new lock
  • tsc --noEmit passes
  • vitest run tests/core: 16 files, 994 passed, 1 skipped
  • import('express-rate-limit') and the SDK's server/mcp.js both load
  • Installed versions are express-rate-limit@8.7.0 and ip-address@10.7.3

I ran the core test directory only, not the full suite or the cross-platform CI matrix.

Checklist

  • Tests added/updated (n/a, lockfile only)
  • npm test passes (core tests only, see above; full suite left to CI)
  • npm run typecheck passes
  • Docs updated if needed (n/a)
  • No Windows path regressions (n/a)
  • Targets next branch

This change was prepared with the help of an AI assistant (Claude Code) and checked by the commands above.

🤖 Generated with Claude Code

bun.lock pinned express-rate-limit@8.2.1, which depends on the exact
version ip-address@10.0.1. That version is affected by five published
advisories (GHSA-v2v4-37r5-5v8g, GHSA-mwp4-54f8-5fhr, GHSA-rpw4-54j3-4h4q,
GHSA-h3mg-xc3c-68pw, GHSA-j6r3-76f7-8jcv), fixed by 10.7.1.

Updates the transitive entries only: express-rate-limit 8.2.1 -> 8.7.0
(ip-address ^10.2.0) and ip-address 10.0.1 -> 10.7.3. package.json is
unchanged; the range from @modelcontextprotocol/sdk already allows it.

Refs mksglu#1225

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant