Skip to content

security: bump 13 vulnerable dependencies (critical and below) - #14

Closed
Andrew Elkins (andrewelkins) wants to merge 1 commit into
mainfrom
secfix/batch-13-deps
Closed

Andrew Elkins (andrewelkins) wants to merge 1 commit into
mainfrom
secfix/batch-13-deps

Conversation

@andrewelkins

Copy link
Copy Markdown

Security fix (draft for review)

Pins 13 vulnerable transitive dependencies in yarn.lock via resolutions and regenerates the lockfile.

Package Severity Patched Advisories
@babel/traverse critical >= 7.23.2 CVE-2023-45133
@xmldom/xmldom critical >= 0.7.7 CVE-2026-41675, CVE-2026-41674, CVE-2026-41672, CVE-2026-34601, CVE-2022-39353
cipher-base critical >= 1.0.5 CVE-2025-9287
elliptic critical >= 6.5.7 CVE-2025-14505, GHSA-vjh7-7g9h-fjfh, CVE-2024-48948, CVE-2024-48949, CVE-2024-42460 …
form-data critical >= 3.0.4 CVE-2026-12143, CVE-2025-7783
handlebars critical >= 4.7.9 GHSA-7rx3-28cr-v5wh, GHSA-442j-39wm-28r2, CVE-2026-33937, CVE-2026-33938, CVE-2026-33941 …
loader-utils critical >= 2.0.3 CVE-2022-37599, CVE-2022-37603, CVE-2022-37601
minimist critical >= 0.2.4 CVE-2021-44906
pbkdf2 critical >= 3.1.3 CVE-2025-6547, CVE-2025-6545
sha.js critical >= 2.4.12 CVE-2025-9288
shell-quote critical >= 1.8.4 CVE-2026-13311, CVE-2026-9277
socket.io-parser critical >= 4.0.5 CVE-2026-69185, CVE-2023-32695, CVE-2022-2421
websocket-driver critical >= 0.7.5 CVE-2026-54466

Not fixed by this PR

  • babel-traverse — no patched version exists yet.
  • webpack — the override does not take on this lockfile (some descriptors keep the vulnerable version), so pinning it here would claim a fix that did not happen. Needs manual handling.

These remain vulnerable after merge.

These are batched into one PR because each pin adds a key to the same override block in package.json — as separate PRs they would conflict with each other on merge.

Auto-drafted by the nightly security scan; needs human review before merge. Nothing but package.json and the lockfile is touched, and no install scripts were run.

Pins 13 vulnerable transitive dependencies to patched versions via the ecosystem override mechanism and regenerates yarn.lock once.

- @babel/traverse -> >=7.23.2 (critical)
- @xmldom/xmldom -> >=0.7.7 (critical)
- cipher-base -> >=1.0.5 (critical)
- elliptic -> >=6.5.7 (critical)
- form-data -> >=3.0.4 (critical)
- handlebars -> >=4.7.9 (critical)
- loader-utils -> >=2.0.3 (critical)
- minimist -> >=0.2.4 (critical)
- pbkdf2 -> >=3.1.3 (critical)
- sha.js -> >=2.4.12 (critical)
- shell-quote -> >=1.8.4 (critical)
- socket.io-parser -> >=4.0.5 (critical)
- websocket-driver -> >=0.7.5 (critical)

Batched into a single commit so the pins land together instead of as N PRs that each edit the same override block. Auto-drafted for security review.
@andrewelkins

Copy link
Copy Markdown
Author

Closing — same class of defect as #13, caught by a new guard rather than by review.

The pins cleared their advisory floors, but two of them dragged unrelated consumers across a major boundary. Yarn resolutions are global, and this lockfile legitimately carried two major lines of each package:

minimist — forced down a major. minimist@^1.1.1, ^1.2.0 and ^1.2.5 all resolved to 1.2.5 on main. Pinning the 0.x advisory floor collapsed every one of them to 0.2.4:

"minimist@>=0.2.4 <0.3.0", minimist@^0.2.1, minimist@^1.1.1, minimist@^1.2.0, minimist@^1.2.5:
  version "0.2.4"

loader-utils — forced up a major. main had 1.4.0 and 2.0.2 side by side; this branch collapses both to 2.0.4, breaking whatever needed the 1.x API.

A floor-only check waves both through, because 0.2.4 >= 0.2.4 and 2.0.4 >= 2.0.3. The generating tool now also compares the resolved semver lines before and after regeneration and refuses the fix when any line disappears or appears.

Neither was visible here because CI could not run — see #15, which unbreaks the runner. With that merged, Tests and Floating Dependencies actually execute and pass.

Replacement PR follows with the 11 pins that verify clean. webpack, minimist and loader-utils are excluded and reported as still-vulnerable rather than falsely claimed as fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant