Repository navigation
chore(deps): bump the npm-deps group across 1 directory with 6 updates - #89
Conversation
|
@dependabot rebase |
Bumps the npm-deps group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@better-auth/oauth-provider](https://github.com/better-auth/better-auth/tree/HEAD/packages/oauth-provider) | `1.7.6` | `1.7.7` | | [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` | | [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.6` | `1.7.7` | | [hono](https://github.com/honojs/hono) | `4.13.9` | `4.13.12` | | [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.23.0` | `8.23.1` | | [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` | Updates `@better-auth/oauth-provider` from 1.7.6 to 1.7.7 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/oauth-provider/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/oauth-provider) Updates `@hono/node-server` from 2.1.1 to 2.1.3 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v2.1.1...v2.1.3) Updates `better-auth` from 1.7.6 to 1.7.7 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/better-auth) Updates `hono` from 4.13.9 to 4.13.12 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.13.9...v4.13.12) Updates `pg` from 8.23.0 to 8.23.1 - [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md) - [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.1/packages/pg) Updates `globals` from 17.12.0 to 17.13.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.12.0...v17.13.0) --- updated-dependencies: - dependency-name: "@better-auth/oauth-provider" dependency-version: 1.7.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-deps - dependency-name: "@hono/node-server" dependency-version: 2.1.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-deps - dependency-name: better-auth dependency-version: 1.7.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-deps - dependency-name: globals dependency-version: 17.13.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-deps - dependency-name: hono dependency-version: 4.13.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-deps - dependency-name: pg dependency-version: 8.23.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-deps ... Signed-off-by: dependabot[bot] <support@github.com>
522c237 to
00a5e0a
Compare
mroderick
left a comment
There was a problem hiding this comment.
Verdict: merge recommended — security-driven
This PR is the fix for critical advisory GHSA-965c-763c-88jm (CVSS 9.1, magic-link account takeover), and it applies to this deployment:
- Magic Link enabled (
src/auth.js) with the default plainstoreToken. ✔ affected condition - GitHub social provider enabled. ✔ affected condition
- Database-backed OAuth state (pg Pool,
account.skipStateCookieCheck: true, state validated against theverificationtable). ✔ affected condition
All three affected conditions hold, and production (auth.codebar.io, per docs/architecture.md) has no staging app. The fix (magic-link: / auth-state: purpose-prefix isolation plus a strict verification-record schema) was verified in the shipped 1.7.7 dist and the upstream patch — not the changelog prose.
The lockfile moves all @better-auth/* packages to 1.7.7 together, satisfying the advisory's "upgrade all participants" requirement; this app uses neither OAuth Proxy nor SAML, so the remaining upgrade clauses do not apply.
Confidence: High — validated locally (fresh worktree at the PR head, npm ci, full tap suite: 205/205 passing) plus green CI on the head (test/e2e/smoke). All runtime/cross-service contract rows verified at the line-trace or receiving-test level.
Cutover notes
Pre-upgrade magic links and pending GitHub sign-in states fail once after deploy with a friendly INVALID_TOKEN — restart them. No migrations, no config changes. Single-node Heroku app; brief old/new-dyno overlap may produce transient INVALID_TOKEN noise.
Per-dependency
| Package | From → To | Verdict | Basis |
|---|---|---|---|
| better-auth | 1.7.6 → 1.7.7 | Compatible (required) | Advisory fix verified in shipped dist; magic-link/state identifier changes line-traced; no customizations the advisory flags |
| @better-auth/oauth-provider | 1.7.6 → 1.7.7 | Compatible | Additive validateRedirectUri (opt-in, off here) + verifyOAuthQueryParams export; default redirect-URI validation unchanged (authorize.ts patch) |
| @hono/node-server | 2.1.1 → 2.1.3 | Compatible | serveStatic % security fix is a no-op here — the app's 6 static assets contain no % |
| hono | 4.13.9 → 4.13.12 | Compatible | All changed surfaces unused (hono/html-only); JWT/template parsing untouched |
| pg | 8.23.0 → 8.23.1 | Compatible | Bug fixes in unused edge paths; cert-validation fix moot (ssl rejectUnauthorized: false, never IP-connected) |
| globals | 17.12.0 → 17.13.0 | Compatible | Dev-only, data-only |
Contracts
Planner-side consumption verified from both sides: lib/omniauth/strategies/codebar.rb and AuthServicesController#member_from_github_id consume github_id from raw_info, email/name from userinfo (blank email fails the callback), JWT iss/aud against JWKS — none of the emission paths appear in this diff; the id_token/userinfo round-trips are asserted by test/integration/oauth-flow.test.js and jwt-payload.test.js in the passing suite.
Follow-up (not this PR)
static/auth-client.js currently loads the browser client from esm.sh/better-auth@latest — a version-drift hazard independent of dependency PRs. Draft PR #92 pins it to the server's version; merging #89 first means rebasing #92 with pin 1.7.7.
Bumps the npm-deps group with 6 updates in the / directory:
1.7.61.7.72.1.12.1.31.7.61.7.74.13.94.13.128.23.08.23.117.12.017.13.0Updates
@better-auth/oauth-providerfrom 1.7.6 to 1.7.7Release notes
Sourced from @better-auth/oauth-provider's releases.
Changelog
Sourced from @better-auth/oauth-provider's changelog.
Commits
db02f23chore: release v1.7.7 (#11413)683ac1dfeat(oauth-provider): add validateRedirectUri option for custom redirect vali...b26057efeat(oauth-provider): export verifyOAuthQueryParams for consent pages (#11402)c8aaffadocs: fix Wether and publically typos in comments (#11403)Updates
@hono/node-serverfrom 2.1.1 to 2.1.3Release notes
Sourced from @hono/node-server's releases.
Commits
720ac782.1.39821792Merge commit from fork35bca952.1.290a2600fix(listener): avoid mutating response headers when setting Content-Length (#...fe7467ctest(request): accept asynchronous body read errors (#403)64dc09edocs(readm): update the benchmark (#394)8f505aechore: add better benchmarks (#391)2469b1afix: type error in early hints and add typecheck to CI (#390)3f958daci: add autofix.ci (#392)Updates
better-authfrom 1.7.6 to 1.7.7Release notes
Sourced from better-auth's releases.
Changelog
Sourced from better-auth's changelog.
Commits
db02f23chore: release v1.7.7 (#11413)ac54bfdfix(auth): isolate verification records and encryption purposes (#11494)69defbcfix(organization): refresh active organization after email sign-in (#11375)55cb92efix(auth): honor social disableSignUp for ID token sign-in (#11491)4186e36fix(captcha): return JSON content type for errors (#11476)8620aa9fix(rate-limit): set JSON content type on 429 responses (#11469)Updates
honofrom 4.13.9 to 4.13.12Release notes
Sourced from hono's releases.
... (truncated)
Commits
6abd35b4.13.1295eb860chore(deps): upgrade vite-plus to 1.0.0 (#5464)afb2068fix(combine): return a Response from a short-circuiting middleware in some() ...e5bb206fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)c3053ccfix(etag): correctly match mixed-case header name in retainedHeader option (#...c437d75test(build): type-check the bundled declarations from a consumer project (#5486)be1f749fix(build): keep internal types private in bundled d.ts and avoid a self-refe...37ce0694.13.111e1207ctest(serve-static): fix the test (#5479)8b05c77Merge commit from forkUpdates
pgfrom 8.23.0 to 8.23.1Changelog
Sourced from pg's changelog.
Commits
0980cefPublish2759b2cfix(pg): run a named statement with an empty text more than once (#3781)7feb7dffix(pg): expose detail and hint on errors from the native client (#3780)9683053fix(pg): do not treat Sync as connection ending (#3772)4589038fix: validate server certificate against host when connecting to an IP addres...9808955cleanup: Fix typo in comment2b02f64fix: avoid mutating query config (#3720)0cef6afReject portal based queries in pipeline mode instead of misrouting rows (#3737)2991480Deprecate serializing invalidDates (#3731)c940d7cFail pipelined queries when the connection dies instead of hanging (#3736)Updates
globalsfrom 17.12.0 to 17.13.0Release notes
Sourced from globals's releases.
Commits
ce512bc17.13.0b007369Update globals (2026-10-01) (#354)16cb1feMeta tweaks