This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryPinned viem's ws to 8.21.0 and upgraded @blockrun/llm to 3.5.1 clearing high‑severity npm audit advisories.
Full changelog
Dependency security: a pinned viem transitive [email protected] (below the ≥8.21.0 patch) was flagging the whole ws → viem → @x402/evm → @blockrun/clawrouter → @blockrun/llm chain (5 high). An overrides entry forces viem's ws to 8.21.0 — clearing all of them (npm audit 15 → 11). The override ships in package.json, so every npx install gets the patched ws.
Remaining advisories are out of this repo's control: the Solana web3.js-v1 tree (no upstream fix for bigint-buffer; npm's only "fix" is a breaking downgrade), the intentional [email protected] pin (bumping re-introduces the Node <20.19 ESM break), and a dev-only esbuild.
Also fixed at the source in @blockrun/[email protected] (pnpm overrides for ws+form-data, dev-tool bump — 0 critical, runtime highs cleared). No source changes; 84 tests + build + live wallet smoke green.
Security Fixes
- Upgraded `viem`'s transitive dependency `ws` from 8.20.1 to 8.21.0 via package.json overrides, clearing high‑severity npm audit advisories (15 → 11).
- Updated `@blockrun/llm` to 3.5.1 which applies pnpm overrides for `ws` and `form-data`, resolving remaining runtime security issues.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About blockrunai/blockrun-mcp
Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.
Related context
Beta — feedback welcome: [email protected]