Skip to content

chore(deps): override mysql2 and deepmerge-ts to patched versions - #102

Merged
shirasakaren merged 3 commits into
mainfrom
chore/override-vulnerable-prisma-transitives
Sep 24, 2026
Merged

shirasakaren merged 3 commits into
mainfrom
chore/override-vulnerable-prisma-transitives

Conversation

@SyafaHadyan

@SyafaHadyan SyafaHadyan commented Sep 24, 2026 •

Copy link
Copy Markdown
Member
  • chore(deps): override mysql2 and deepmerge-ts to patched versions
  • fix(deps): pin the mysql2/deepmerge-ts overrides to exact versions

Summary by CodeRabbit

  • Chores
    • Made a routine update to project configuration. There are no changes to app features, workflows, or visible behavior, and no action is required. Existing functionality remains unchanged. These maintenance changes are not expected to affect how the app looks or works.

Both are transitive dependencies of prisma, bundled for its multi-database
driver support regardless of which provider a project actually uses. This
project only ever uses the postgresql provider, but the installed
versions were still below the patched thresholds for their respective
advisories.
@SyafaHadyan SyafaHadyan added the bug Something isn't working label Sep 24, 2026
@SyafaHadyan SyafaHadyan self-assigned this Sep 24, 2026
@deepsource-io

deepsource-io Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in a53c32c...3e97e32 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Sep 24, 2026 2:30a.m. Review ↗
SQL Sep 24, 2026 2:30a.m. Review ↗
Secrets Sep 24, 2026 2:30a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Override vulnerable Prisma transitive dependencies

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Forces Prisma’s mysql2 and deepmerge-ts transitives above patched advisory thresholds.
• Regenerates the lockfile with patched packages and updated peer dependency resolution.
Diagram

graph TD
  A["Workspace Overrides"] -->|resolves| B["pnpm Lockfile"] --> C["Prisma"] --> D["mysql2 3.24.4"]
  C --> E["deepmerge-ts 8.0.2"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Upgrade Prisma
  • ➕ Uses dependency versions validated and selected by Prisma upstream.
  • ➕ Eliminates project-maintained transitive dependency overrides.
  • ➖ A suitable Prisma release may not yet contain both patched dependencies.
  • ➖ A Prisma upgrade would expand the review and regression-testing scope.

Recommendation: The overrides are the best immediate remediation because they address installed vulnerable packages without changing the PostgreSQL runtime path or upgrading Prisma. Prefer removing them once Prisma natively resolves both dependencies above the advisory thresholds.

Files changed (2) +38 / -31

Other (2) +38 / -31
pnpm-lock.yamlResolve Prisma transitives to patched versions +32/-31

Resolve Prisma transitives to patched versions

• Records deepmerge-ts 8.0.2 and mysql2 3.24.4 after applying workspace overrides. Regeneration also updates mysql2’s dependency and @types/node peer graph, plus incidental peer snapshot keys.

pnpm-lock.yaml

pnpm-workspace.yamlEnforce patched Prisma transitive dependencies +6/-0

Enforce patched Prisma transitive dependencies

• Adds workspace overrides requiring mysql2 3.23.1 or newer and deepmerge-ts 8.0.0 or newer. Comments document that Prisma installs them despite the project’s PostgreSQL-only configuration.

pnpm-workspace.yaml

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 436398c6-6ca9-432e-9f16-5e0f44a6aefb

📥 Commits

Reviewing files that changed from the base of the PR and between 039877a and 3e97e32.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 812df236-4255-4b99-a468-222115349a97

📥 Commits

Reviewing files that changed from the base of the PR and between 3b10032 and 039877a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The pnpm workspace pins mysql2 to 3.24.4 and deepmerge-ts to 8.0.2. Updated comments distinguish their usage and explain the exact-version policy.

Changes

Dependency Version Overrides

Layer / File(s) Summary
Workspace dependency overrides
pnpm-workspace.yaml
The workspace pins mysql2 to 3.24.4 and deepmerge-ts to 8.0.2. Comments distinguish the packages’ usage and describe the exact-version policy.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~7 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 03987

The pinned versions are reflected in the lockfile, so this change is ready to merge after normal checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description only lists summary statements. It omits the required change explanation, testing details, and checklist. Use the repository template. Add a one- or two-sentence explanation of the change and reason, document the tests that were run, and complete the checklist items.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the dependency overrides for mysql2 and deepmerge-ts. It accurately summarizes the main change.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@ren-automation

ren-automation Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Checks for 3e97e32

Check Status Detail
✅ API lint, types, tests and build success
✅ build / Build, scan & push API image success
✅ build / Build, scan & push Web image success
✅ Codacy Static Code Analysis success
✅ codecov/patch success
✅ CodeQL success
✅ CodeQL success
✅ CodeRabbit success
✅ DeepSource: Docker success
✅ DeepSource: Secrets success
✅ DeepSource: SQL success
✅ Dependency review success
✅ Detect Changes / Detect affected workloads success
✅ Docker staging gate success
✅ E2E gate success
✅ Formatting and automation tests success
✅ GitGuardian Security Checks success
✅ gitleaks success
✅ Lighthouse CI budget success
✅ Lighthouse gate success
✅ Lint, typecheck, test & build success
⚪ OSSF Scorecard skipped
✅ Playwright (macos-latest, webkit) success
✅ Playwright (ubuntu-latest, chromium) success
✅ Playwright (ubuntu-latest, firefox) success
✅ Playwright (ubuntu-latest, mobile-chrome) success
✅ Playwright (ubuntu-latest, mobile-safari) success
✅ Playwright (ubuntu-latest, webkit) success
✅ Playwright (windows-latest, chromium) success
✅ pre-commit.ci - pr success
✅ Prose gate success
✅ Secret scan (gitleaks) success
✅ Security gate success
✅ security/snyk (MGM Laboratory) success
✅ semgrep-cloud-platform/scan success
✅ Signal submitted review success
✅ Socket Security: Project Report success
✅ Socket Security: Pull Request Alerts success
✅ SonarCloud Code Analysis success
✅ Trivy success
✅ Trivy filesystem scan success
⚪ Vale prose lint skipped
✅ Web lint, types and build success

ren-automation

@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@qodo-code-review

qodo-code-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Lock refreshes can force new majors ✓ Resolved 🐞 Bug ⚙ Maintainability
Description
The two bare overrides use open-ended >= ranges, replacing matching dependency edges throughout
the workspace without retaining Prisma's compatible major-version constraints. A routine lockfile
refresh can therefore select later breaking majors of either package and force them into present or
future consumers without a corresponding manifest change that explicitly reviews that upgrade.
Code

pnpm-workspace.yaml[R8-9]

+  mysql2: ">=3.23.1"
+  deepmerge-ts: ">=8.0.0"
Relevance

●● Moderate

The major-upgrade risk is plausible, but no close repository precedent establishes the team’s
preferred override range policy.

PR-#18

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The workspace declares pnpm 11.3.0 and the new override values are unrestricted above their security
thresholds, while the lock currently resolves only one specific snapshot of each dependency. pnpm's
documentation states that a regular root override rewrites matching dependency edges throughout the
dependency graph, confirming that these bare ranges are not limited to Prisma or to the current
major releases.

package.json[5-8]
pnpm-workspace.yaml[4-9]
pnpm-lock.yaml[3363-3365]
pnpm-lock.yaml[4649-4653]
🌐 pnpm documents that root overrides can replace any matching dependency in the dependency graph, with regular overrides rewriting matching edges unconditionally.

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The bare, open-ended overrides allow future major versions and apply across the workspace, so regenerating the lockfile can force an unreviewed breaking release into Prisma or another consumer.

## Fix Focus Areas
- pnpm-workspace.yaml[4-9]
- pnpm-lock.yaml[7-9]

## Recommended Fix
Replace the `>=` ranges with exact reviewed patched versions such as `mysql2: "3.24.4"` and `deepmerge-ts: "8.0.2"`, optionally scope each override to its Prisma parent, and regenerate the lockfile with the repository's pinned pnpm version.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Informational

2. The security note misstates config use ✓ Resolved 🐞 Bug ⚙ Maintainability
Description
The new comment says neither overridden package is exercised by PostgreSQL-only usage, but
deepmerge-ts is a database-independent dependency used by @prisma/config. Prisma config loading
calls its basic deepmerge export, so the note gives future maintainers an incorrect basis for
evaluating whether that security dependency can be removed or deprioritized.
Code

pnpm-workspace.yaml[R5-7]

+  # Prisma bundles these regardless of database provider; both are below
+  # patched versions for known advisories. Neither is exercised by this
+  # project's postgresql-only usage, but pin them past the fix anyway.
Relevance

●●● Strong

Recent precedent accepts corrections to inaccurate configuration comments, especially when they
affect operational understanding.

PR-#16
PR-#53

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The lockfile places deepmerge-ts directly under @prisma/config, while this repository invokes
Prisma config loading through its generate and migration scripts. Prisma's own dependency-update
analysis identifies the concrete call site as the deepmerge merger in loadConfigFromFile.ts,
disproving the comment's claim that PostgreSQL-only usage leaves this package unexercised.

pnpm-workspace.yaml[5-9]
pnpm-lock.yaml[7471-7475]
apps/api/package.json[9-14]
apps/api/package.json[25-29]
🌐 Prisma's update notes state that @prisma/config calls the basic deepmerge export on plain configuration objects in loadConfigFromFile.ts.

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The override comment incorrectly groups `deepmerge-ts` with unused database drivers even though Prisma uses it while loading configuration independently of the selected database provider.

## Fix Focus Areas
- pnpm-workspace.yaml[5-7]

## Recommended Fix
Rewrite the comment to distinguish `mysql2`, which is unused by the PostgreSQL application, from `deepmerge-ts`, which Prisma config loading actively uses and is overridden to address its advisory.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Web pages:
  +12 more
Review mode: ⚖️ Balanced: This dependency override changes workspace configuration and the resolved Prisma dependency graph, so compatibility and install/runtime behavior require a careful review despite the localized scope.

Grey Divider

Tip of the day
💡 Did you know, you can choose which labels appear on a finding, and whether they show icons or text

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread pnpm-workspace.yaml Outdated
Comment thread pnpm-workspace.yaml Outdated
An open-ended >= range means a routine lockfile refresh could silently
pull in an unreviewed future major release for either package. Also
correct the accompanying comment: deepmerge-ts isn't dormant like
mysql2 is, @prisma/config calls it directly while loading configuration
regardless of database provider, so it's a real vulnerable dependency
being patched here, not dead code.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The PR aims to address security vulnerabilities by overriding transitive dependencies for mysql2 and deepmerge-ts. While the intent is correct, the implementation is currently ineffective because the overrides field is placed in pnpm-workspace.yaml. In a pnpm environment, dependency overrides must be defined in the root package.json under the pnpm.overrides key. Until this configuration is moved, the project remains vulnerable as the package manager will ignore these pins.

Test suggestions

  • Verify that the lockfile (pnpm-lock.yaml) correctly resolves mysql2 to exactly 3.24.4.
  • Verify that the lockfile (pnpm-lock.yaml) correctly resolves deepmerge-ts to exactly 8.0.2.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the lockfile (pnpm-lock.yaml) correctly resolves mysql2 to exactly 3.24.4.
2. Verify that the lockfile (pnpm-lock.yaml) correctly resolves deepmerge-ts to exactly 8.0.2.

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread pnpm-workspace.yaml
@SyafaHadyan

Copy link
Copy Markdown
Member Author

@shirasakaren PTAL

@sonarqubecloud

Copy link
Copy Markdown

@shirasakaren shirasakaren left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@shirasakaren

Copy link
Copy Markdown
Contributor

This was supposed to be Renovate's or Dependabot jobs, I don't know why they're not actively opening PR. Please help to check why they're not responding and actively patching the version. Please see it here #105

@SyafaHadyan

@ren-automation

Copy link
Copy Markdown

LGTM review

LGTM

@shirasakaren
shirasakaren merged commit 1e23755 into main Sep 24, 2026
48 checks passed
@shirasakaren
shirasakaren deleted the chore/override-vulnerable-prisma-transitives branch September 24, 2026 02:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants