Skip to content

security: bump 11 vulnerable dependencies (critical and below) - #16

Draft
Andrew Elkins (andrewelkins) wants to merge 1 commit into
mainfrom
secfix/batch-11-deps
Draft

Andrew Elkins (andrewelkins) wants to merge 1 commit into
mainfrom
secfix/batch-11-deps

Conversation

@andrewelkins

Copy link
Copy Markdown

Security fix (draft for review)

Pins 11 vulnerable transitive dependencies in yarn.lock via resolutions and regenerates the lockfile.

Package Severity Patched Advisories
@babel/traverse critical >= 7.23.2 CVE-2023-45133
@xmldom/xmldom critical >= 0.7.7 CVE-2026-41675, CVE-2026-41674, CVE-2026-41672, CVE-2026-34601, CVE-2022-39353
cipher-base critical >= 1.0.5 CVE-2025-9287
elliptic critical >= 6.5.7 CVE-2025-14505, GHSA-vjh7-7g9h-fjfh, CVE-2024-48948, CVE-2024-48949, CVE-2024-42460 …
form-data critical >= 3.0.4 CVE-2026-12143, CVE-2025-7783
handlebars critical >= 4.7.9 GHSA-7rx3-28cr-v5wh, GHSA-442j-39wm-28r2, CVE-2026-33937, CVE-2026-33938, CVE-2026-33941 …
pbkdf2 critical >= 3.1.3 CVE-2025-6547, CVE-2025-6545
sha.js critical >= 2.4.12 CVE-2025-9288
shell-quote critical >= 1.8.4 CVE-2026-13311, CVE-2026-9277
socket.io-parser critical >= 4.0.5 CVE-2026-69185, CVE-2023-32695, CVE-2022-2421
websocket-driver critical >= 0.7.5 CVE-2026-54466

Not fixed by this PR

  • babel-traverse — no patched version exists yet.
  • loader-utils, minimist, webpack — the override does not take on this lockfile (some descriptors keep the vulnerable version), so pinning it here would claim a fix that did not happen. Needs manual handling.

These remain vulnerable after merge.

These are batched into one PR because each pin adds a key to the same override block in package.json — as separate PRs they would conflict with each other on merge.

Auto-drafted by the nightly security scan; needs human review before merge. Nothing but package.json and the lockfile is touched, and no install scripts were run.

Pins 11 vulnerable transitive dependencies to patched versions via the ecosystem override mechanism and regenerates yarn.lock once.

- @babel/traverse -> >=7.23.2 (critical)
- @xmldom/xmldom -> >=0.7.7 (critical)
- cipher-base -> >=1.0.5 (critical)
- elliptic -> >=6.5.7 (critical)
- form-data -> >=3.0.4 (critical)
- handlebars -> >=4.7.9 (critical)
- pbkdf2 -> >=3.1.3 (critical)
- sha.js -> >=2.4.12 (critical)
- shell-quote -> >=1.8.4 (critical)
- socket.io-parser -> >=4.0.5 (critical)
- websocket-driver -> >=0.7.5 (critical)

Batched into a single commit so the pins land together instead of as N PRs that each edit the same override block. Auto-drafted for security review.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical and moderate dependency-resolution issues remain unresolved.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Pins 11 vulnerable transitive dependencies through Yarn resolutions and regenerates the lockfile.

Changes:

  • Adds security-focused dependency overrides.
  • Updates resolved packages and transitive dependencies.

Required fixes:

  • Critical: @xmldom/xmldom 0.7.13 remains vulnerable; move to a patched release line and verify compatibility.
  • Moderate: Pin socket.io-parser to a patched 4.0.x version compatible with socket.io 4.4.0.
  • Moderate: elliptic 6.6.1 remains affected by CVE-2025-14505; document the unresolved risk or replace the dependency path.
File summaries
File Description
yarn.lock Regenerates locked dependency versions.
package.json Adds 11 dependency security resolutions; several require correction.
Review details

Suppressed comments (3)

package.json:103

  • CVE-2026-12143 affects the 3.x line through 3.0.4 and is fixed in 3.0.5, so this lower bound still permits a known-vulnerable release. Raise the 3.x floor to 3.0.5 and regenerate the lockfile selector (the currently locked 3.0.5 can remain).
    "form-data": ">=3.0.4 <4.0.0",

package.json:107

  • CVE-2026-13311 affects shell-quote through 1.8.4 and is fixed in 1.8.5, so this range admits the vulnerable 1.8.4 release. Raise the floor to 1.8.5 and regenerate the lockfile selector; the currently locked 1.10.0 is already safe.
    "shell-quote": ">=1.8.4 <2.0.0",

package.json:108

  • CVE-2026-69185 affects Socket.IO parser versions from 4.0.0 through 4.2.6 and is fixed in 4.2.7, so this override permits vulnerable 4.0.5–4.2.6 releases. Set the floor to 4.2.7 and regenerate the lockfile selector; the currently locked 4.2.7 can remain.
    "socket.io-parser": ">=4.0.5 <5.0.0",
  • Files reviewed: 1/2 changed files
  • Comments generated: 3
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
},
"resolutions": {
"@babel/traverse": ">=7.23.2 <8.0.0",
"@xmldom/xmldom": ">=0.7.7 <0.8.0",
Comment thread package.json
"@babel/traverse": ">=7.23.2 <8.0.0",
"@xmldom/xmldom": ">=0.7.7 <0.8.0",
"cipher-base": ">=1.0.5 <2.0.0",
"elliptic": ">=6.5.7 <7.0.0",
Comment thread package.json
"pbkdf2": ">=3.1.3 <4.0.0",
"sha.js": ">=2.4.12 <3.0.0",
"shell-quote": ">=1.8.4 <2.0.0",
"socket.io-parser": ">=4.0.5 <5.0.0",
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants