Skip to content

fix(sec): bump nanoid 3.x to 3.3.18 - #92573

Open
mrxmoex wants to merge 1 commit into
NousResearch:mainfrom
mrxmoex:fix/nanoid-3.3.18
Open

fix(sec): bump nanoid 3.x to 3.3.18#92573
mrxmoex wants to merge 1 commit into
NousResearch:mainfrom
mrxmoex:fix/nanoid-3.3.18

Conversation

@mrxmoex

@mrxmoex mrxmoex commented Aug 22, 2026

Copy link
Copy Markdown

Summary

Split from #92543 so the audit pin can land without a desktop runtime jump.

Related Issue

Split from #92543. Does not close #92543.

Type of Change

  • 🔒 Security fix

Test plan

  • npm audit root / web / ui-tui / website → nanoid 3.3.17 gone
  • Lockfiles contain nanoid-3.3.18.tgz and no nanoid-3.3.17.tgz
  • Integrity sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==

Risk

Low. Transitive pin (vite / sanitize-html / postcss). No app-code call to customAlphabet with attacker size. Override currently forces 3.3.17, so audit cannot climb without this.

@mrxmoex
mrxmoex requested a review from a team August 22, 2026 23:40
@alt-glitch alt-glitch added type/security Security vulnerability or hardening P3 Low — cosmetic, nice to have comp/tui Terminal UI (ui-tui/ + tui_gateway/) comp/dashboard Web dashboard / control panel UI (dashboard/, landing) duplicate This issue or pull request already exists labels Aug 22, 2026
@alt-glitch

Copy link
Copy Markdown
Collaborator

This was generated by AI during triage.

Duplicate of #89335 — it makes the same root and website nanoid 3.3.18 remediation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/dashboard Web dashboard / control panel UI (dashboard/, landing) comp/tui Terminal UI (ui-tui/ + tui_gateway/) duplicate This issue or pull request already exists P3 Low — cosmetic, nice to have type/security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants