Dependabot triage — 2026-08-14
Open alerts: 175 (direct: 119, transitive: 56; patch available for 171)
Summary (severity × scope)
| Severity |
Runtime |
Development |
Total |
| critical |
0 |
1 |
1 |
| high |
69 |
4 |
73 |
| medium |
79 |
4 |
83 |
| low |
16 |
2 |
18 |
| Total |
164 |
11 |
175 |
Prioritized fix plan
Special case: AGPL upstream fork
This repo is a fork of documenso/documenso. Resolve via upstream sync (merge upstream main), not local bumps. As of 2026-08-14 the fork's main is 84 commits behind and 211 commits ahead of upstream main (merge base 2026-04-23). Upstream has been actively bumping dependencies; merging upstream main should clear a large share of these alerts. After the sync, re-run triage on the remainder.
The sections below are for post-sync residue only — do not land local bumps that will conflict with the upstream merge.
(a) Critical/high runtime deps with patches — bump now
Exact bump targets (highest first-patched version across the package's alerts — clears all of them):
next (npm, direct, 63 alerts, worst: high) (declared: 16.2.4) → 16.2.11 — CVE-2026-44572, CVE-2026-44573, CVE-2026-44574, CVE-2026-44575…
hono (npm, direct, 16 alerts, worst: high) (declared: ^4.12.18) → 4.12.34 — CVE-2026-47673, CVE-2026-47674, CVE-2026-47675, CVE-2026-47676…
react-router (npm, direct, 13 alerts, worst: high) (declared: ^7.12.0) → 7.18.2 — CVE-2026-33244, CVE-2026-33245, CVE-2026-34077, CVE-2026-40181…
axios (npm, transitive, 10 alerts, worst: high) → 1.18.0 — CVE-2026-67314, GHSA-42h9-826w-cgv3, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548…
brace-expansion (npm, transitive, 4 alerts, worst: high) → 5.0.7 — CVE-2026-13149, CVE-2026-14257
postcss (npm, direct, 4 alerts, worst: high) (declared: ^8.5.6) → 8.5.23 — CVE-2026-41305, CVE-2026-45623, CVE-2026-69153, CVE-2026-73646
fast-uri (npm, transitive, 3 alerts, worst: high) → 3.1.5 — CVE-2026-13676, CVE-2026-16221, CVE-2026-18446
js-yaml (npm, transitive, 3 alerts, worst: high) → 4.3.1 — CVE-2026-53550, CVE-2026-59869, GHSA-5p4m-2wfm-xmqj
protobufjs (npm, transitive, 3 alerts, worst: high) → 7.6.5 — CVE-2026-48712, CVE-2026-54269, CVE-2026-59877
ws (npm, transitive, 3 alerts, worst: high) → 8.21.0 — CVE-2026-45736, CVE-2026-48779
@grpc/grpc-js (npm, transitive, 2 alerts, worst: high) → 1.14.4 — CVE-2026-48068, CVE-2026-48069
nanoid (npm, direct, 2 alerts, worst: high) (declared: ^5.1.6) → 5.1.16 — CVE-2026-67214
sharp (npm, direct, 2 alerts, worst: high) (declared: 0.34.5) → 0.35.0 — GHSA-f88m-g3jw-g9cj
@opentelemetry/propagator-jaeger (npm, transitive, 1 alert, worst: high) → 2.9.0 — CVE-2026-59892
engine.io (npm, transitive, 1 alert, worst: high) → 6.6.7 — CVE-2026-59725
form-data (npm, transitive, 1 alert, worst: high) → 4.0.6 — CVE-2026-12143
socket.io-parser (npm, transitive, 1 alert, worst: high) → 4.2.7 — CVE-2026-69185
tmp (npm, transitive, 1 alert, worst: high) → 0.2.6 — CVE-2026-44705
(b) Grouped minor/patch bumps — candidate single PR
Medium/low runtime items where the patched version stays within the current major. These can land together as one lockfile-refresh/bump PR.
mermaid (npm, direct, 5 alerts, worst: medium) (declared: ^11.12.2) → 11.16.1 — CVE-2026-50159, CVE-2026-71436, CVE-2026-71437, CVE-2026-71438…
@hono/node-server (npm, direct, 1 alert, worst: medium) (declared: ^1.19.11) → 1.19.15 — GHSA-frvp-7c67-39w9
@opentelemetry/core (npm, transitive, 1 alert, worst: medium) → 2.8.0 — CVE-2026-54285
joi (npm, transitive, 1 alert, worst: medium) → 18.2.1 — CVE-2026-48038
morgan (npm, transitive, 1 alert, worst: medium) → 1.11.0 — CVE-2026-5078
qs (npm, transitive, 1 alert, worst: medium) → 6.15.2 — CVE-2026-8723
ts-deepmerge (npm, transitive, 1 alert, worst: medium) → 8.0.0 — CVE-2026-12644
uuid (npm, transitive, 1 alert, worst: medium) → 11.1.1 — CVE-2026-41907
body-parser (npm, transitive, 1 alert, worst: low) → 1.20.6 — CVE-2026-12590
esbuild (npm, direct, 1 alert, worst: low) (declared: ^0.27.0) → 0.28.1 — GHSA-g7r4-m6w7-qqqr
(c) Majors needing migration work — flagged, not planned
First patched version is a major above the declared range. Needs migration effort; do not bundle with routine bumps.
nodemailer (npm, direct, 6 alerts, worst: high) (declared: ^8.0.5) → 9.0.1 — GHSA-268h-hp4c-crq3, GHSA-p6gq-j5cr-w38f, GHSA-r7g4-qg5f-qqm2, GHSA-wqvq-jvpq-h66f
turbo (npm, direct, 2 alerts, worst: medium) (declared: ^1.13.4) → 2.9.14 — CVE-2026-45772, CVE-2026-45773
(d) No patch available — watch list
No first_patched_version published for at least one alert. Monitor advisories; consider mitigation or removal if exposure is real.
image-size (npm, transitive, 2 alerts, worst: high) — CVE-2025-71329, CVE-2025-71330
dompurify (npm, transitive, 10 alerts, worst: medium) — CVE-2026-49458, CVE-2026-49459, CVE-2026-49978, CVE-2026-65898…
@ai-sdk/provider-utils (npm, transitive, 1 alert, worst: low) — CVE-2026-8769
(e) Dev-dependency noise — grouped cleanup
Development-scope only; no runtime exposure. Suitable for one grouped cleanup PR (or acceptance if toolchain upgrade is pending).
vitest (npm, direct, 1 alert, worst: critical) (declared: ^4.0.18) → 4.1.0 — CVE-2026-47429
vite (npm, direct, 2 alerts, worst: high) (declared: ^7.2.4) → 7.3.5 — CVE-2026-53571, CVE-2026-53632
adm-zip (npm, transitive, 1 alert, worst: high) → 0.6.0 — CVE-2026-39244
tar (npm, transitive, 2 alerts, worst: medium) → 7.5.18 — CVE-2026-53655, CVE-2026-59871
@babel/core (npm, direct, 1 alert, worst: low) (declared: ^7.28.5) → 7.29.6 — CVE-2026-49356
Report-only triage. Fix PRs are a separate approved wave — see plans/phase-2-cleanup-waves.md in psd-dev-standards.
Dependabot triage — 2026-08-14
Open alerts: 175 (direct: 119, transitive: 56; patch available for 171)
Summary (severity × scope)
Prioritized fix plan
Special case: AGPL upstream fork
This repo is a fork of documenso/documenso. Resolve via upstream sync (merge upstream main), not local bumps. As of 2026-08-14 the fork's
mainis 84 commits behind and 211 commits ahead of upstreammain(merge base 2026-04-23). Upstream has been actively bumping dependencies; merging upstream main should clear a large share of these alerts. After the sync, re-run triage on the remainder.The sections below are for post-sync residue only — do not land local bumps that will conflict with the upstream merge.
(a) Critical/high runtime deps with patches — bump now
Exact bump targets (highest first-patched version across the package's alerts — clears all of them):
next(npm, direct, 63 alerts, worst: high) (declared:16.2.4) → 16.2.11 — CVE-2026-44572, CVE-2026-44573, CVE-2026-44574, CVE-2026-44575…hono(npm, direct, 16 alerts, worst: high) (declared:^4.12.18) → 4.12.34 — CVE-2026-47673, CVE-2026-47674, CVE-2026-47675, CVE-2026-47676…react-router(npm, direct, 13 alerts, worst: high) (declared:^7.12.0) → 7.18.2 — CVE-2026-33244, CVE-2026-33245, CVE-2026-34077, CVE-2026-40181…axios(npm, transitive, 10 alerts, worst: high) → 1.18.0 — CVE-2026-67314, GHSA-42h9-826w-cgv3, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548…brace-expansion(npm, transitive, 4 alerts, worst: high) → 5.0.7 — CVE-2026-13149, CVE-2026-14257postcss(npm, direct, 4 alerts, worst: high) (declared:^8.5.6) → 8.5.23 — CVE-2026-41305, CVE-2026-45623, CVE-2026-69153, CVE-2026-73646fast-uri(npm, transitive, 3 alerts, worst: high) → 3.1.5 — CVE-2026-13676, CVE-2026-16221, CVE-2026-18446js-yaml(npm, transitive, 3 alerts, worst: high) → 4.3.1 — CVE-2026-53550, CVE-2026-59869, GHSA-5p4m-2wfm-xmqjprotobufjs(npm, transitive, 3 alerts, worst: high) → 7.6.5 — CVE-2026-48712, CVE-2026-54269, CVE-2026-59877ws(npm, transitive, 3 alerts, worst: high) → 8.21.0 — CVE-2026-45736, CVE-2026-48779@grpc/grpc-js(npm, transitive, 2 alerts, worst: high) → 1.14.4 — CVE-2026-48068, CVE-2026-48069nanoid(npm, direct, 2 alerts, worst: high) (declared:^5.1.6) → 5.1.16 — CVE-2026-67214sharp(npm, direct, 2 alerts, worst: high) (declared:0.34.5) → 0.35.0 — GHSA-f88m-g3jw-g9cj@opentelemetry/propagator-jaeger(npm, transitive, 1 alert, worst: high) → 2.9.0 — CVE-2026-59892engine.io(npm, transitive, 1 alert, worst: high) → 6.6.7 — CVE-2026-59725form-data(npm, transitive, 1 alert, worst: high) → 4.0.6 — CVE-2026-12143socket.io-parser(npm, transitive, 1 alert, worst: high) → 4.2.7 — CVE-2026-69185tmp(npm, transitive, 1 alert, worst: high) → 0.2.6 — CVE-2026-44705(b) Grouped minor/patch bumps — candidate single PR
Medium/low runtime items where the patched version stays within the current major. These can land together as one lockfile-refresh/bump PR.
mermaid(npm, direct, 5 alerts, worst: medium) (declared:^11.12.2) → 11.16.1 — CVE-2026-50159, CVE-2026-71436, CVE-2026-71437, CVE-2026-71438…@hono/node-server(npm, direct, 1 alert, worst: medium) (declared:^1.19.11) → 1.19.15 — GHSA-frvp-7c67-39w9@opentelemetry/core(npm, transitive, 1 alert, worst: medium) → 2.8.0 — CVE-2026-54285joi(npm, transitive, 1 alert, worst: medium) → 18.2.1 — CVE-2026-48038morgan(npm, transitive, 1 alert, worst: medium) → 1.11.0 — CVE-2026-5078qs(npm, transitive, 1 alert, worst: medium) → 6.15.2 — CVE-2026-8723ts-deepmerge(npm, transitive, 1 alert, worst: medium) → 8.0.0 — CVE-2026-12644uuid(npm, transitive, 1 alert, worst: medium) → 11.1.1 — CVE-2026-41907body-parser(npm, transitive, 1 alert, worst: low) → 1.20.6 — CVE-2026-12590esbuild(npm, direct, 1 alert, worst: low) (declared:^0.27.0) → 0.28.1 — GHSA-g7r4-m6w7-qqqr(c) Majors needing migration work — flagged, not planned
First patched version is a major above the declared range. Needs migration effort; do not bundle with routine bumps.
nodemailer(npm, direct, 6 alerts, worst: high) (declared:^8.0.5) → 9.0.1 — GHSA-268h-hp4c-crq3, GHSA-p6gq-j5cr-w38f, GHSA-r7g4-qg5f-qqm2, GHSA-wqvq-jvpq-h66fturbo(npm, direct, 2 alerts, worst: medium) (declared:^1.13.4) → 2.9.14 — CVE-2026-45772, CVE-2026-45773(d) No patch available — watch list
No
first_patched_versionpublished for at least one alert. Monitor advisories; consider mitigation or removal if exposure is real.image-size(npm, transitive, 2 alerts, worst: high) — CVE-2025-71329, CVE-2025-71330dompurify(npm, transitive, 10 alerts, worst: medium) — CVE-2026-49458, CVE-2026-49459, CVE-2026-49978, CVE-2026-65898…@ai-sdk/provider-utils(npm, transitive, 1 alert, worst: low) — CVE-2026-8769(e) Dev-dependency noise — grouped cleanup
Development-scope only; no runtime exposure. Suitable for one grouped cleanup PR (or acceptance if toolchain upgrade is pending).
vitest(npm, direct, 1 alert, worst: critical) (declared:^4.0.18) → 4.1.0 — CVE-2026-47429vite(npm, direct, 2 alerts, worst: high) (declared:^7.2.4) → 7.3.5 — CVE-2026-53571, CVE-2026-53632adm-zip(npm, transitive, 1 alert, worst: high) → 0.6.0 — CVE-2026-39244tar(npm, transitive, 2 alerts, worst: medium) → 7.5.18 — CVE-2026-53655, CVE-2026-59871@babel/core(npm, direct, 1 alert, worst: low) (declared:^7.28.5) → 7.29.6 — CVE-2026-49356Report-only triage. Fix PRs are a separate approved wave — see plans/phase-2-cleanup-waves.md in psd-dev-standards.