security: bump 14 vulnerable dependencies (critical and below) - #13
Andrew Elkins (andrewelkins) wants to merge 1 commit into
Conversation
Pins 14 vulnerable transitive dependencies to patched versions via the ecosystem override mechanism and regenerates yarn.lock once. - @babel/traverse -> >=7.23.2 (critical) - @xmldom/xmldom -> >=0.7.7 (critical) - cipher-base -> >=1.0.5 (critical) - elliptic -> >=6.5.7 (critical) - form-data -> >=3.0.4 (critical) - handlebars -> >=4.7.9 (critical) - loader-utils -> >=2.0.3 (critical) - minimist -> >=0.2.4 (critical) - pbkdf2 -> >=3.1.3 (critical) - sha.js -> >=2.4.12 (critical) - shell-quote -> >=1.8.4 (critical) - socket.io-parser -> >=4.0.5 (critical) - webpack -> >=5.76.0 (critical) - websocket-driver -> >=0.7.5 (critical) Batched into a single commit so the pins land together instead of as N PRs that each edit the same override block. Auto-drafted for security review.
|
Closing — this PR does not do what its description claims.
Worse, that same resolution captured
The remaining 12 pins resolved correctly and in-range. None of this was caught before opening because CI on this repo cannot run: The generating tool has been fixed on both counts — semver-correct caps for |
Security fix (draft for review)
Pins 14 vulnerable transitive dependencies in
yarn.lockviaresolutionsand regenerates the lockfile.@babel/traverse>= 7.23.2@xmldom/xmldom>= 0.7.7cipher-base>= 1.0.5elliptic>= 6.5.7form-data>= 3.0.4handlebars>= 4.7.9loader-utils>= 2.0.3minimist>= 0.2.4pbkdf2>= 3.1.3sha.js>= 2.4.12shell-quote>= 1.8.4socket.io-parser>= 4.0.5webpack>= 5.76.0websocket-driver>= 0.7.5Not fixed by this PR
No patched version exists yet for
babel-traverse— still vulnerable after merge.These are batched into one PR because each pin adds a key to the same override block in
package.json— as separate PRs they would conflict with each other on merge.