#24326·mastra

security: clear Dependabot + Vanta findings (zero open)

Author: shreyas-mastraCreated Sep 17, 2026Updated Sep 17, 2026
Labelsstatus: needs triage

Summary

Track remediation to drive Dependabot alerts and Vanta findings for mastra-ai/mastra (GitHub + Aikido assets) to zero.

Inventory snapshot (2026-09-17):

  • Dependabot: 59 open alerts across 21 packages
  • Vanta: GitHub mastra-ai/mastra + mastra (Aikido) findings including Critical [email protected]

Approach

  • Direct-bump where we own the dependency
  • pnpm.overrides (and nested workspace / npm overrides) for transitive-only and dual-line packages
  • Document residual unfixable advisories (no patched release published)

Acceptance

  • PR open that maximizes clearing of Dependabot + Vanta findings toward zero
  • Do not merge until CI is green / reviewed