fix(deps): update proxy-addr, shell-quote and wrangler to patched versions (#971)

npm audit fix in the root and in packages/mcp-server. proxy-addr 2.0.8 fixes
the IP spoofing through IPv4-mapped IPv6 trust subnets (GHSA-jqcg-44mw-7w3h),
shell-quote 1.12.0 fixes the command injection through a line terminator, and
wrangler 4.149.0 brings a miniflare that no longer bundles the vulnerable
sharp 0.35.4. No package is added; 56 lock entries for miniflare's sharp
binaries go away.
This commit is contained in:
Dayuan Jiang
2026-10-10 19:53:55 +09:00
committed by GitHub
parent 02eaa0bd22
commit a6e812d3a5
2 changed files with 63 additions and 1157 deletions
+56 -1154
View File
File diff suppressed because it is too large Load Diff
+7 -3
View File
@@ -2746,9 +2746,9 @@
}
},
"node_modules/proxy-addr": {
"version": "2.0.7",
"resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz",
"integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==",
"version": "2.0.8",
"resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.8.tgz",
"integrity": "sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==",
"license": "MIT",
"dependencies": {
"forwarded": "0.2.0",
@@ -2756,6 +2756,10 @@
},
"engines": {
"node": ">= 0.10"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/express"
}
},
"node_modules/qs": {