Resolve SSRF Vulnerabilities, Module Resolution Errors, and Studio Transport Corruption in base-builder-mcp - #22
Open
magqqgq wants to merge 1 commit into
Open
Resolve SSRF Vulnerabilities, Module Resolution Errors, and Studio Transport Corruption in base-builder-mcp#22magqqgq wants to merge 1 commit into
base-builder-mcp#22magqqgq wants to merge 1 commit into
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Sep 2, 2026 in 0s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
Details
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR (showing first 10 of 160 packages)
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| inquirer | 12.6.0 | 12.6.0 | package-lock.json | 2025-04-24T07:32:15Z |
| @inquirer/prompts | 7.5.0 | 7.5.0 | package-lock.json | 2025-04-24T07:32:13Z |
| @inquirer/select | 4.2.0 | 4.2.0 | package-lock.json | 2025-04-24T07:32:10Z |
| @inquirer/rawlist | 4.1.0 | 4.1.0 | package-lock.json | 2025-04-24T07:32:10Z |
| @inquirer/editor | 4.2.10 | 4.2.10 | package-lock.json | 2025-04-03T21:44:39Z |
| @inquirer/password | 4.0.12 | 4.0.12 | package-lock.json | 2025-04-03T21:44:39Z |
| @inquirer/confirm | 5.1.9 | 5.1.9 | package-lock.json | 2025-04-03T21:44:39Z |
| @inquirer/checkbox | 4.1.5 | 4.1.5 | package-lock.json | 2025-04-03T21:44:39Z |
| @inquirer/input | 4.1.9 | 4.1.9 | package-lock.json | 2025-04-03T21:44:39Z |
| @inquirer/number | 3.0.12 | 3.0.12 | package-lock.json | 2025-04-03T21:44:39Z |
Loading