chore(deps): override mysql2 and deepmerge-ts to patched versions - #102
Conversation
Both are transitive dependencies of prisma, bundled for its multi-database driver support regardless of which provider a project actually uses. This project only ever uses the postgresql provider, but the installed versions were still below the patched thresholds for their respective advisories.
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Sep 24, 2026 2:30a.m. | Review ↗ | |
| SQL | Sep 24, 2026 2:30a.m. | Review ↗ | |
| Secrets | Sep 24, 2026 2:30a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
PR Summary by QodoOverride vulnerable Prisma transitive dependencies
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedReview was skipped as selected files did not have any reviewable changes. ⛔ Files ignored due to path filters (1)
⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe pnpm workspace pins ChangesDependency Version Overrides
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~7 minutes Change: Other Merge Risk: ⚪ Minimal · up to The pinned versions are reflected in the lockfile, so this change is ready to merge after normal checks. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
Code Review by Qodo
1.
|
An open-ended >= range means a routine lockfile refresh could silently pull in an unreviewed future major release for either package. Also correct the accompanying comment: deepmerge-ts isn't dormant like mysql2 is, @prisma/config calls it directly while loading configuration regardless of database provider, so it's a real vulnerable dependency being patched here, not dead code.
There was a problem hiding this comment.
Pull Request Overview
The PR aims to address security vulnerabilities by overriding transitive dependencies for mysql2 and deepmerge-ts. While the intent is correct, the implementation is currently ineffective because the overrides field is placed in pnpm-workspace.yaml. In a pnpm environment, dependency overrides must be defined in the root package.json under the pnpm.overrides key. Until this configuration is moved, the project remains vulnerable as the package manager will ignore these pins.
Test suggestions
- Verify that the lockfile (pnpm-lock.yaml) correctly resolves mysql2 to exactly 3.24.4.
- Verify that the lockfile (pnpm-lock.yaml) correctly resolves deepmerge-ts to exactly 8.0.2.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the lockfile (pnpm-lock.yaml) correctly resolves mysql2 to exactly 3.24.4.
2. Verify that the lockfile (pnpm-lock.yaml) correctly resolves deepmerge-ts to exactly 8.0.2.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
|
@shirasakaren PTAL |
|
|
This was supposed to be Renovate's or Dependabot jobs, I don't know why they're not actively opening PR. Please help to check why they're not responding and actively patching the version. Please see it here #105 |




Summary by CodeRabbit