Skip to content

chore(deps): bump nodemailer to 10.0.10 and patch vulnerable undici copies - #8393

Merged
waleedlatif1 merged 1 commit into
stagingfrom
chore/bump-nodemailer-undici
Sep 29, 2026
Merged

waleedlatif1 merged 1 commit into
stagingfrom
chore/bump-nodemailer-undici

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Supersedes chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates #8392 — Dependabot bumped package.json without bun.lock, so every CI job failed on --frozen-lockfile
  • nodemailer 9.1.1 → 10.0.10 (GHSA-6vj9-mwq6-2f5v); 10.0.11+ are still inside the repo's 7-day minimum release age
  • undici 7.29.0 → 7.29.1 (the September undici advisory batch)
  • Patched the transitive undici copies too: e2b override 2.45.0 → 2.50.0 (pins undici8 8.10.2) and node-gyp's nested undici 6.28.0 → 6.28.1
  • nodemailer 10 ships its own types: dropped @types/nodemailer, switched nodemailer.Transporter / nodemailer.SendMailOptions namespace types to named type imports, and removed the SES double-cast-allowed cast whose only reason was the @types package's nested AWS SDK
  • Kept bun.lock at lockfileVersion 1. Scoped overrides (undici@8, parent>child) would force v3, which Bun 1.3.x ignores

Not covered: @earendil-works/pi-coding-agent@0.80.10 exact-pins undici@8.5.0; patched undici needs pi ≥ 0.86.0, which is a separate Pi bump

Type of Change

  • Dependency update / security fix

Testing

  • bun install --frozen-lockfile passes on Bun 1.4.2 (CI) and 1.3.14
  • apps/sim type-check clean
  • lib/internal/smtp + lib/messaging/email tests: 52 passed (gmail tests exercise the real MailComposer)
  • Real SMTP round-trip through sendSmtpMessage against a local SMTP server (message id, subject, attachment), plus the SES v2 transport with a stubbed client and MailComposer raw build
  • bun run lint, block registry check, bun run check:audits (51 audits), docs-manifest:check

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@waleedlatif1
waleedlatif1 requested a review from a team as a code owner September 29, 2026 00:04
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Sep 29, 2026 12:06am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Bumps email library and patches transitive dependency.

The PR appears safe to merge; no actionable regression caused by these changes was established.

Summary

Updates Nodemailer and several undici dependency copies while adapting email type imports to Nodemailer’s bundled types.

  • Synchronizes the application and root dependency changes with bun.lock.
  • Removes the SES type cast associated with the former Nodemailer type package.

Reviews (1) · Last reviewed commit: "chore(deps): bump nodemailer to 10.0.10 ..."

@waleedlatif1
waleedlatif1 merged commit 90f3eed into staging Sep 29, 2026
32 checks passed
@waleedlatif1
waleedlatif1 deleted the chore/bump-nodemailer-undici branch September 29, 2026 00:10

This branch was successfully deployed

1 active deployment
Preview — 982eeed3 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant