Skip to content

chore: upgrade ip-address to ^10.7.2 to address CVE-2026-101910, CVE-2026-101911, CVE-2026-101912, CVE-2026-101913 - #1695

Open
claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/ip-address
Open

claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/ip-address

Conversation

@claude

@claude claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2365
Fixes SOU-2366
Fixes SOU-2383
Fixes SOU-2384

Summary

Refreshes the yarn.lock entry for the transitive dependency ip-address from 10.4.0 to 10.7.2 (patched floor 10.7.1).

The existing ranges (socks requests ^10.1.1, express-rate-limit requests ^10.2.0) already admit the patched version, so this is a lockfile-only refresh via yarn up -R ip-address. No package.json changes or resolutions overrides.

Verification

  • yarn why ip-address: every instance resolves to ip-address@npm:10.7.2.
  • yarn workspace @sourcebot/backend test: 309 passed.
  • yarn workspace @sourcebot/web test: 1506 passed.

🤖 Generated with Claude Code

…2026-101913

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c9b2dae9-c886-4951-99ac-0102b3b378f1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@claude[bot] your pull request is missing a changelog!

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

@claude claude Bot changed the title chore: upgrade ip-address to ^10.7.2 to address CVE-2026-101910, CVE-2026-101913 chore: upgrade ip-address to ^10.7.2 to address CVE-2026-101910, CVE-2026-101911, CVE-2026-101912, CVE-2026-101913 Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants