Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 17 additions & 17 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -100,48 +100,48 @@
"react-dom@^18": "18.3.1",
"ai@^6": "6.0.116",
"@ai-sdk/provider-utils@^4": "4.0.29",
"express@^4>body-parser": "1.20.3",
"express@^4>body-parser": "^1.20.6",
"@remix-run/dev@2.17.5>tar-fs": "2.1.4",
"tar": "7.5.19",
"tar": "7.5.21",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

fd -t f -a -g 'package.json' -g 'pnpm-lock.yaml' \
  -x rg -n -C 2 \
  '("?(tar|jws|vite|js-cookie|tmp)"?([@:])|/(tar|jws|vite|js-cookie|tmp)@)' {}

Repository: triggerdotdev/trigger.dev

Length of output: 265


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- relevant files ---'
fd -t f -a 'package.json|pnpm-lock.yaml|pnpm-workspace.yaml|packageManager|.npmrc' | head -80

printf '%s\n' '--- root package configuration ---'
if [ -f package.json ]; then
  sed -n '90,150p' package.json
  rg -n -C 2 '"(packageManager|pnpm|overrides|tar|jws|vite|js-cookie|tmp)"' package.json
fi

printf '%s\n' '--- toolchain and override declarations ---'
rg -n -C 3 'packageManager|pnpm@|overrides:|(^|[ /])(?:tar|jws|vite|js-cookie|tmp)(@|:)' \
  --glob 'package.json' --glob 'pnpm-workspace.yaml' --glob '.npmrc' --glob 'pnpm-lock.yaml' .

Repository: triggerdotdev/trigger.dev

Length of output: 31121


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- relevant files ---'
fd -t f -a 'package.json|pnpm-lock.yaml|pnpm-workspace.yaml|packageManager|.npmrc' | head -80

printf '%s\n' '--- root package configuration ---'
if [ -f package.json ]; then
  sed -n '90,150p' package.json
  rg -n -C 2 '"(packageManager|pnpm|overrides|tar|jws|vite|js-cookie|tmp)"' package.json
fi

printf '%s\n' '--- toolchain and override declarations ---'
rg -n -C 3 'packageManager|pnpm@|overrides:|(^|[ /])(?:tar|jws|vite|js-cookie|tmp)(@|:)' \
  --glob 'package.json' --glob 'pnpm-workspace.yaml' --glob '.npmrc' --glob 'pnpm-lock.yaml' \
  .

Repository: triggerdotdev/trigger.dev

Length of output: 31121


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import json
from pathlib import Path

targets = {"tar", "jws", "vite", "js-cookie", "tmp"}
root = Path(".")

print("--- workspace dependency declarations ---")
for path in sorted(root.rglob("package.json")):
    if any(part in {".git", "node_modules", "dist", "build"} for part in path.parts):
        continue
    try:
        data = json.loads(path.read_text())
    except Exception:
        continue
    for section in ("dependencies", "devDependencies", "optionalDependencies", "peerDependencies"):
        for name, spec in data.get(section, {}).items():
            if name in targets:
                print(f"{path}:{section}:{name}: {spec}")

print("--- root lockfile metadata and affected importer lines ---")
lock = Path("pnpm-lock.yaml").read_text().splitlines()
for i, line in enumerate(lock):
    if i < 65 or any(
        f"{name}:" in line for name in sorted(targets)
    ):
        if i < 65 or any(
            line.lstrip().startswith(f"{name}:") for name in sorted(targets)
        ):
            print(f"{i+1}:{line}")
PY

printf '%s\n' '--- affected lockfile dependency edges ---'
rg -n -C 2 \
  '^[[:space:]]+(tar|jws|vite|js-cookie|tmp):|^[[:space:]]+[^[:space:]].*:$' \
  pnpm-lock.yaml | rg -B 2 -A 2 \
  '(^|[[:space:]])(tar|jws|vite|js-cookie|tmp):'

Repository: triggerdotdev/trigger.dev

Length of output: 9058


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import json
from pathlib import Path

targets = {"tar", "jws", "vite", "js-cookie", "tmp"}

print("--- workspace dependency declarations ---")
for path in sorted(Path(".").rglob("package.json")):
    if any(part in {".git", "node_modules", "dist", "build"} for part in path.parts):
        continue
    try:
        data = json.loads(path.read_text())
    except Exception:
        continue
    for section in ("dependencies", "devDependencies", "optionalDependencies", "peerDependencies"):
        for name, spec in data.get(section, {}).items():
            if name in targets:
                print(f"{path}:{section}:{name}: {spec}")

print("--- root lockfile metadata and affected importer lines ---")
lines = Path("pnpm-lock.yaml").read_text().splitlines()
for i, line in enumerate(lines):
    if i < 65 or any(line.lstrip().startswith(f"{name}:") for name in targets):
        print(f"{i + 1}:{line}")
PY

printf '%s\n' '--- affected lockfile dependency edges ---'
rg -n -C 2 \
  '^[[:space:]]+(tar|jws|vite|js-cookie|tmp):|^[[:space:]]+[^[:space:]].*:$' \
  pnpm-lock.yaml |
  rg -B 2 -A 2 '(^|[[:space:]])(tar|jws|vite|js-cookie|tmp):'

Repository: triggerdotdev/trigger.dev

Length of output: 9058


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import re
from pathlib import Path

targets = {"tar", "jws", "vite", "js-cookie", "tmp"}
lines = Path("pnpm-lock.yaml").read_text().splitlines()

print("--- package snapshot parents for affected edges ---")
parent = None
for i, line in enumerate(lines, 1):
    m = re.match(r"^  (\S[^:]*):$", line)
    if m:
        parent = m.group(1)
    if re.match(r"^      (tar|jws|vite|js-cookie|tmp):", line):
        print(f"{i}: {parent} -> {line.strip()}")
        for context in lines[i-1:min(i+2, len(lines))]:
            print(f"    {context}")

print("--- importer sections containing direct affected dependencies ---")
in_importers = False
current = None
for i, line in enumerate(lines, 1):
    if line == "importers:":
        in_importers = True
        continue
    if in_importers and re.match(r"^[^ ]", line):
        break
    if in_importers:
        m = re.match(r"^  (\S[^:]*):$", line)
        if m:
            current = m.group(1)
        if re.match(r"^      (tar|vite|jws|js-cookie|tmp):", line):
            print(f"{i}: {current} -> {line.strip()}")
            for context in lines[i-1:min(i+3, len(lines))]:
                print(f"    {context}")
PY

Repository: triggerdotdev/trigger.dev

Length of output: 7106


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import json
import urllib.request

packages = [
    ("cacache", "17.1.4"),
    ("giget", "1.2.3"),
    ("`@kubernetes/client-node`", "1.0.0"),
    ("external-editor", "3.1.0"),
    ("testcontainers", "11.14.0"),
    ("tmp-promise", "3.0.3"),
    ("jsonwebtoken", "9.0.2"),
    ("js-beautify", "1.15.1"),
    ("react-use", "17.5.1"),
    ("`@vanilla-extract/integration`", "6.2.1"),
]

for name, version in packages:
    url = f"https://registry.npmjs.org/{name.replace('/', '%2f')}/{version}"
    try:
        with urllib.request.urlopen(url, timeout=10) as response:
            data = json.load(response)
        manifest = data.get("dependencies", {})
        peers = data.get("peerDependencies", {})
        affected = {
            key: value
            for key, value in {**manifest, **peers}.items()
            if key in {"tar", "jws", "vite", "js-cookie", "tmp"}
        }
        print(f"{name}@{version}: {json.dumps(affected, sort_keys=True)}")
    except Exception as exc:
        print(f"{name}@{version}: ERROR {exc}")
PY

Repository: triggerdotdev/trigger.dev

Length of output: 1793


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import json
import urllib.request

packages = [
    ("cacache", "17.1.4"),
    ("giget", "1.2.3"),
    ("`@kubernetes/client-node`", "1.0.0"),
    ("external-editor", "3.1.0"),
    ("testcontainers", "11.14.0"),
    ("tmp-promise", "3.0.3"),
    ("jsonwebtoken", "9.0.2"),
    ("js-beautify", "1.15.1"),
    ("react-use", "17.5.1"),
    ("`@vanilla-extract/integration`", "6.2.1"),
]

for name, version in packages:
    url = f"https://registry.npmjs.org/{name.replace('/', '%2f')}/{version}"
    try:
        with urllib.request.urlopen(url, timeout=10) as response:
            data = json.load(response)
        deps = {**data.get("dependencies", {}), **data.get("peerDependencies", {})}
        affected = {
            key: value for key, value in deps.items()
            if key in {"tar", "jws", "vite", "js-cookie", "tmp"}
        }
        print(f"{name}@{version}: {json.dumps(affected, sort_keys=True)}")
    except Exception as exc:
        print(f"{name}@{version}: ERROR {exc}")
PY

Repository: triggerdotdev/trigger.dev

Length of output: 1793


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import json
import subprocess
import urllib.parse

packages = [
    ("cacache", "17.1.4"),
    ("giget", "1.2.3"),
    ("`@kubernetes/client-node`", "1.0.0"),
    ("external-editor", "3.1.0"),
    ("testcontainers", "11.14.0"),
    ("tmp-promise", "3.0.3"),
    ("jsonwebtoken", "9.0.2"),
    ("js-beautify", "1.15.1"),
    ("react-use", "17.5.1"),
    ("`@vanilla-extract/integration`", "6.2.1"),
]

for name, version in packages:
    url = f"https://registry.npmjs.org/{urllib.parse.quote(name, safe='`@/`')}/{version}"
    try:
        raw = subprocess.check_output(
            ["curl", "-ksSfL", "--max-time", "15", url],
            text=True,
        )
        data = json.loads(raw)
        deps = {**data.get("dependencies", {}), **data.get("peerDependencies", {})}
        affected = {
            key: value for key, value in deps.items()
            if key in {"tar", "jws", "vite", "js-cookie", "tmp"}
        }
        print(f"{name}@{version}: {json.dumps(affected, sort_keys=True)}")
    except Exception as exc:
        print(f"{name}@{version}: ERROR {exc}")
PY

Repository: triggerdotdev/trigger.dev

Length of output: 578


Scope overrides by compatible dependency range.

The unscoped tar override replaces cacache@17.1.4’s ^6.1.11 and giget@1.2.3’s ^6.2.0 with 7.5.21. The tmp override replaces external-editor@3.1.0’s ^0.0.33 with 0.2.7. The js-cookie override replaces react-use@17.5.1’s ^2.2.1 with 3.0.8. These replacements cross incompatible package lines. Split the overrides by compatible major or scope them to compatible parent packages.

Source: MCP tools

"form-data@^2": "2.5.4",
"form-data@^3": "3.0.5",
"form-data@^4": "4.0.6",
"ws@>=7 <7.5.11": "7.5.11",
"ws@>=8 <8.21.0": "8.21.0",
"hono@>=4 <4.12.25": "4.12.25",
"undici@>=6 <6.27.0": "6.27.0",
"undici@>=7 <7.28.0": "7.28.0",
"js-yaml@>=3.0.0 <3.14.2": "3.14.2",
"js-yaml@>=4.0.0 <4.1.1": "4.1.1",
"hono@>=4 <4.12.34": "4.12.34",
"undici@>=6 <6.28.0": "6.28.0",
"undici@>=7 <7.29.0": "7.29.0",
"js-yaml@>=3.0.0 <3.15.1": "3.15.1",
"js-yaml@>=4.0.0 <4.3.1": "4.3.1",
"jws@<3.2.3": "3.2.3",
"qs@>=6.0.0 <6.15.2": "^6.15.2",
"lodash@>=4.17 <4.18.0": "^4.18.0",
"lodash-es@>=4.17 <4.18.0": "^4.18.0",
"dompurify@>=3 <3.4.0": "^3.4.1",
"vite@>=5.0.0 <6.4.2": "^6.4.2",
"dompurify@>=3 <3.4.13": "^3.4.13",
"vite@>=5.0.0 <6.4.3": "^6.4.3",
"rollup@>=4 <4.59.0": "^4.59.0",
"flatted@>=3 <3.4.2": "^3.4.2",
"picomatch@>=2 <2.3.2": "^2.3.2",
"picomatch@>=4 <4.0.4": "^4.0.4",
"minimatch@>=3 <3.1.3": "^3.1.3",
"protobufjs@>=7 <7.5.6": "^7.5.6",
"protobufjs@>=7 <7.6.5": "^7.6.5",
"fast-xml-parser@>=4 <4.5.5": "^4.5.5",
"fast-xml-parser@>=5 <5.7.0": "^5.7.0",
"path-to-regexp@>=0.1 <0.1.13": "^0.1.13",
"ajv@>=8 <8.18.0": "^8.18.0",
"socket.io-parser@>=4 <4.2.6": "^4.2.6",
"postcss@>=8 <8.5.10": "^8.5.10",
"socket.io-parser@>=4 <4.2.7": "^4.2.7",
"postcss@>=8 <8.5.23": "^8.5.23",
"yaml@>=2 <2.8.3": "^2.8.3",
"semver@>=5 <5.7.2": "^5.7.2",
"defu@>=6 <6.1.5": "^6.1.5",
"fast-uri@<3.1.2": "^3.1.2",
"fast-uri@>=3 <3.1.5": "^3.1.5",
"js-cookie@<3.0.8": "3.0.8",
"tmp@<0.2.7": "0.2.7",
"brace-expansion@<1.1.13": "1.1.13",
"brace-expansion@>=2 <2.0.3": "2.0.3",
"brace-expansion@>=5 <5.0.6": "5.0.6",
"brace-expansion@<1.1.18": "1.1.18",
"brace-expansion@>=2 <2.1.4": "2.1.4",
"brace-expansion@>=5 <5.0.9": "5.0.9",
Comment on lines +140 to +142

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Behavioural defaults changed by js-yaml 4.2 and brace-expansion 2.1 were only partially verifiable here

I confirmed the js-yaml claim: no YAML file in the repo contains underscore-separated numeric scalars (grep for : <digits>_<digit> across all *.yml/*.yaml outside node_modules returns nothing), and the 4.x consumers are @kubernetes/client-node, cosmiconfig, autoevals and remark-mdx-frontmatter, none of which parse user-authored YAML on a hot path. The brace-expansion expansion-size cap could not be verified from the repo (no installed node_modules to inspect the new default limit or how minimatch surfaces an exceeded cap), so that part of the claim rests on the author's testing.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

"mermaid@>=11 <11.16.1": "^11.16.1",
"@jsonhero/json-infer-types>ip-address": "^10.2.0",
"@jsonhero/json-infer-types>ip-address": "^10.3.1",
"@modelcontextprotocol/sdk@>=1.26.0>express-rate-limit": "^8.6.0"
},
"onlyBuiltDependencies": [
Expand Down
Loading
Loading