chore: upgrade nodemailer to ^10.0.2 to address GHSA-6vj9-mwq6-2f5v, GHSA-8vvx-rff5-p5rq - #1703
Open
claude[bot] wants to merge 2 commits into
Open
claude[bot] wants to merge 2 commits into
claude[bot] wants to merge 2 commits into
Conversation
…HSA-8vvx-rff5-p5rq nodemailer 10 ships its own type declarations, where SentMessageInfo.pending is optional. Default it to an empty array before concatenating. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Contributor
License Audit❌ Audit failed to produce results. Check the workflow logs for details. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes SOU-2390
Fixes SOU-2391
Summary
Upgrades the direct
@sourcebot/webdependencynodemailerfrom^9.0.1(locked9.1.1) to^10.0.2(locked10.0.13). No 9.x release contains the fixes, so a lockfile refresh is not enough.servernameacross transports, which could disclose SMTP credentials across tenants (fixed in 10.0.2).Upgrade notes
SentMessageInfo.pendingis optional. The fourresult.rejected.concat(result.pending)call sites (auth.ts,accountRequests.tsx2,invites.ts) now useresult.pending ?? []. Runtime behaviour doesn't change, because.filter(Boolean)already dropped anundefinedentry.Note: the conventional
cursor/cve/nodemailerbranch name is still held by a stale branch from merged PR #1642, so this PR usescursor/cve/nodemailer-2026-09.Verification
yarn why nodemailer: the only instance resolves tonodemailer@npm:10.0.13.yarn workspace @sourcebot/web tsc --noEmit: no errors besides the pre-existing@/public/*image/SVG module errors, which come from the local checkout not having a generatednext-env.d.tsand don't involve nodemailer.yarn workspace @sourcebot/web lint: clean.yarn workspace @sourcebot/web test: 1506 passed.yarn workspace @sourcebot/web build: succeeds.🤖 Generated with Claude Code
Note
Medium Risk
Touches SMTP paths used for login and membership email; the dependency bump fixes credential-leak and DoS CVEs but still warrants verifying outbound mail in staging.
Overview
Upgrades
@sourcebot/web's direct nodemailer dependency from^9.0.1to^10.0.2(lockfile resolves to 10.0.13), addressing security advisories that are only fixed in 10.x—not via a lockfile-only bump on 9.x.After send, failure detection in magic-link login (
auth.ts), join-request notifications, approval emails, and org invites now treatsSentMessageInfo.pendingas optional withresult.pending ?? [], matching nodemailer 10's bundled types without changing runtime behavior whenpendingis absent.Reviewed by Cursor Bugbot for commit 3a2081c. Bugbot is set up for automated code reviews on this repo. Configure here.