security: bump 13 vulnerable dependencies (critical and below) - #14
Andrew Elkins (andrewelkins) wants to merge 1 commit into
Conversation
Pins 13 vulnerable transitive dependencies to patched versions via the ecosystem override mechanism and regenerates yarn.lock once. - @babel/traverse -> >=7.23.2 (critical) - @xmldom/xmldom -> >=0.7.7 (critical) - cipher-base -> >=1.0.5 (critical) - elliptic -> >=6.5.7 (critical) - form-data -> >=3.0.4 (critical) - handlebars -> >=4.7.9 (critical) - loader-utils -> >=2.0.3 (critical) - minimist -> >=0.2.4 (critical) - pbkdf2 -> >=3.1.3 (critical) - sha.js -> >=2.4.12 (critical) - shell-quote -> >=1.8.4 (critical) - socket.io-parser -> >=4.0.5 (critical) - websocket-driver -> >=0.7.5 (critical) Batched into a single commit so the pins land together instead of as N PRs that each edit the same override block. Auto-drafted for security review.
|
Closing — same class of defect as #13, caught by a new guard rather than by review. The pins cleared their advisory floors, but two of them dragged unrelated consumers across a major boundary. Yarn
A floor-only check waves both through, because 0.2.4 >= 0.2.4 and 2.0.4 >= 2.0.3. The generating tool now also compares the resolved semver lines before and after regeneration and refuses the fix when any line disappears or appears. Neither was visible here because CI could not run — see #15, which unbreaks the runner. With that merged, Replacement PR follows with the 11 pins that verify clean. |
Security fix (draft for review)
Pins 13 vulnerable transitive dependencies in
yarn.lockviaresolutionsand regenerates the lockfile.@babel/traverse>= 7.23.2@xmldom/xmldom>= 0.7.7cipher-base>= 1.0.5elliptic>= 6.5.7form-data>= 3.0.4handlebars>= 4.7.9loader-utils>= 2.0.3minimist>= 0.2.4pbkdf2>= 3.1.3sha.js>= 2.4.12shell-quote>= 1.8.4socket.io-parser>= 4.0.5websocket-driver>= 0.7.5Not fixed by this PR
babel-traverse— no patched version exists yet.webpack— the override does not take on this lockfile (some descriptors keep the vulnerable version), so pinning it here would claim a fix that did not happen. Needs manual handling.These remain vulnerable after merge.
These are batched into one PR because each pin adds a key to the same override block in
package.json— as separate PRs they would conflict with each other on merge.Auto-drafted by the nightly security scan; needs human review before merge. Nothing but
package.jsonand the lockfile is touched, and no install scripts were run.