Skip to content

chore(deps): upgrade svix to silence GHSA-w5hq-g745-h8pq#942

Merged
gabrielmfern merged 2 commits into
resend:canaryfrom
ulrichstark:chore(deps)--upgrade-`svix`-to-silence-GHSA-w5hq-g745-h8pq
Apr 27, 2026
Merged

chore(deps): upgrade svix to silence GHSA-w5hq-g745-h8pq#942
gabrielmfern merged 2 commits into
resend:canaryfrom
ulrichstark:chore(deps)--upgrade-`svix`-to-silence-GHSA-w5hq-g745-h8pq

Conversation

@ulrichstark

@ulrichstark ulrichstark commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

This PR upgrades the dependency svix to version 1.92.2 that removes uuid from its dependencies.
The previously installed version of uuid triggers the security vulnerability GHSA-w5hq-g745-h8pq when running npm audit.

Edit: Maybe unpin both dependencies postal-mime and svix so consumers of resend get bug fixes and security patches of those and their subdependencies without your team needing to push an update and consumers needing to upgrade resend?

@ulrichstark ulrichstark requested a review from a team as a code owner April 23, 2026 11:55
@ulrichstark ulrichstark requested a review from mwoss April 23, 2026 11:55

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Shadow auto-approve: would require human review. This PR updates a production dependency (svix), which is classified as high-impact and requires human review to ensure no regressions were introduced.

@gabrielmfern gabrielmfern merged commit 9ca7487 into resend:canary Apr 27, 2026
7 checks passed
@ulrichstark ulrichstark deleted the chore(deps)--upgrade-`svix`-to-silence-GHSA-w5hq-g745-h8pq branch April 27, 2026 15:03
@ulrichstark

Copy link
Copy Markdown
Contributor Author

@gabrielmfern Thank you very much for merging! Could you please publish a new release to remove uuid from resend's dependencies and to make the security vulnerability reporting disappear?

image

Source: https://npmx.dev/package/resend

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants