security: bump 11 vulnerable dependencies (critical and below) - #16
Draft
Andrew Elkins (andrewelkins) wants to merge 1 commit into
Draft
Andrew Elkins (andrewelkins) wants to merge 1 commit into
Andrew Elkins (andrewelkins) wants to merge 1 commit into
Conversation
Pins 11 vulnerable transitive dependencies to patched versions via the ecosystem override mechanism and regenerates yarn.lock once. - @babel/traverse -> >=7.23.2 (critical) - @xmldom/xmldom -> >=0.7.7 (critical) - cipher-base -> >=1.0.5 (critical) - elliptic -> >=6.5.7 (critical) - form-data -> >=3.0.4 (critical) - handlebars -> >=4.7.9 (critical) - pbkdf2 -> >=3.1.3 (critical) - sha.js -> >=2.4.12 (critical) - shell-quote -> >=1.8.4 (critical) - socket.io-parser -> >=4.0.5 (critical) - websocket-driver -> >=0.7.5 (critical) Batched into a single commit so the pins land together instead of as N PRs that each edit the same override block. Auto-drafted for security review.
Copilot started reviewing on behalf of
Andrew Elkins (andrewelkins)
September 8, 2026 17:37
View session
There was a problem hiding this comment.
🟡 Changes recommended
Critical and moderate dependency-resolution issues remain unresolved.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Pins 11 vulnerable transitive dependencies through Yarn resolutions and regenerates the lockfile.
Changes:
- Adds security-focused dependency overrides.
- Updates resolved packages and transitive dependencies.
Required fixes:
- Critical:
@xmldom/xmldom0.7.13 remains vulnerable; move to a patched release line and verify compatibility. - Moderate: Pin
socket.io-parserto a patched 4.0.x version compatible withsocket.io4.4.0. - Moderate:
elliptic6.6.1 remains affected by CVE-2025-14505; document the unresolved risk or replace the dependency path.
File summaries
| File | Description |
|---|---|
yarn.lock |
Regenerates locked dependency versions. |
package.json |
Adds 11 dependency security resolutions; several require correction. |
Review details
Suppressed comments (3)
package.json:103
- CVE-2026-12143 affects the 3.x line through 3.0.4 and is fixed in 3.0.5, so this lower bound still permits a known-vulnerable release. Raise the 3.x floor to 3.0.5 and regenerate the lockfile selector (the currently locked 3.0.5 can remain).
"form-data": ">=3.0.4 <4.0.0",
package.json:107
- CVE-2026-13311 affects
shell-quotethrough 1.8.4 and is fixed in 1.8.5, so this range admits the vulnerable 1.8.4 release. Raise the floor to 1.8.5 and regenerate the lockfile selector; the currently locked 1.10.0 is already safe.
"shell-quote": ">=1.8.4 <2.0.0",
package.json:108
- CVE-2026-69185 affects Socket.IO parser versions from 4.0.0 through 4.2.6 and is fixed in 4.2.7, so this override permits vulnerable 4.0.5–4.2.6 releases. Set the floor to 4.2.7 and regenerate the lockfile selector; the currently locked 4.2.7 can remain.
"socket.io-parser": ">=4.0.5 <5.0.0",
- Files reviewed: 1/2 changed files
- Comments generated: 3
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| }, | ||
| "resolutions": { | ||
| "@babel/traverse": ">=7.23.2 <8.0.0", | ||
| "@xmldom/xmldom": ">=0.7.7 <0.8.0", |
| "@babel/traverse": ">=7.23.2 <8.0.0", | ||
| "@xmldom/xmldom": ">=0.7.7 <0.8.0", | ||
| "cipher-base": ">=1.0.5 <2.0.0", | ||
| "elliptic": ">=6.5.7 <7.0.0", |
| "pbkdf2": ">=3.1.3 <4.0.0", | ||
| "sha.js": ">=2.4.12 <3.0.0", | ||
| "shell-quote": ">=1.8.4 <2.0.0", | ||
| "socket.io-parser": ">=4.0.5 <5.0.0", |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security fix (draft for review)
Pins 11 vulnerable transitive dependencies in
yarn.lockviaresolutionsand regenerates the lockfile.@babel/traverse>= 7.23.2@xmldom/xmldom>= 0.7.7cipher-base>= 1.0.5elliptic>= 6.5.7form-data>= 3.0.4handlebars>= 4.7.9pbkdf2>= 3.1.3sha.js>= 2.4.12shell-quote>= 1.8.4socket.io-parser>= 4.0.5websocket-driver>= 0.7.5Not fixed by this PR
babel-traverse— no patched version exists yet.loader-utils,minimist,webpack— the override does not take on this lockfile (some descriptors keep the vulnerable version), so pinning it here would claim a fix that did not happen. Needs manual handling.These remain vulnerable after merge.
These are batched into one PR because each pin adds a key to the same override block in
package.json— as separate PRs they would conflict with each other on merge.Auto-drafted by the nightly security scan; needs human review before merge. Nothing but
package.jsonand the lockfile is touched, and no install scripts were run.