Skip to content

Track and triage npm audit / dependency vulnerabilities - #122

Merged
jesusmpc merged 3 commits into
mainfrom
dependency/GH-120-bump-vulnerable-de
Sep 7, 2026
Merged

jesusmpc merged 3 commits into
mainfrom
dependency/GH-120-bump-vulnerable-de

Conversation

@alexmontesg

Copy link
Copy Markdown
Contributor

Closes #120

Signed-off-by: Alejandro Montes <alejandromogarcia@ext.inditex.com>
@alexmontesg
alexmontesg force-pushed the dependency/GH-120-bump-vulnerable-de branch from fa00c27 to f5687dc Compare September 4, 2026 11:40
- override qs to ^6.16.0 (express/body-parser pin ~6.15.x, can't
  bump directly; qs 6.16 changelog is additive-only)
- override sequelize's nested uuid to ^11.1.1 (sequelize only uses
  v1/v4, unaffected by the v3/v5/v6 buffer advisory)
- bump prettier-eslint 16.3.0 -> 17.1.2 (unused in code/scripts,
  fixes nested @typescript-eslint/parser, typescript-estree, minimatch)
- bump sharp 0.34.3 -> 0.35.4 (direct usage only; verified no use of
  removed/renamed APIs: paletteBitDepth, sharpen opts, jp2k)

Left unfixed, no safe path available:
- image-size: latest release (2.0.2) still vulnerable upstream
- @imgly/background-removal-node: bundles pinned lodash/sharp,
  no newer release exists
- @ai-sdk/provider-utils/ui-utils, @mastra/core (low): buried in
  @mastra/core's legacy AI SDK v4 shim; fixing requires bumping the
  whole @mastra/* family, disproportionate blast radius for the
  severity
- @mastra/memory 1.28.2 bump reverted: requires newer @mastra/core
  exports (MAX_KNOWLEDGE_NODE_DESCRIPTION_LENGTH) not present in the
  pinned @mastra/core@1.36.0; broke at runtime on import

Verified with npm run lint, npm run build, and targeted runtime
smoke tests of sharp and @mastra/memory.
@imgly/background-removal-node pins vulnerable lodash (~4.17.21,
CWE-94/CWE-1321) and sharp (~0.32.4, libvips CVEs) with no newer
release available upstream.

- override lodash to ^4.18.1 under @imgly/background-removal-node
  (package only calls lodash.memoize, not the vulnerable
  template/unset/omit functions)
- add a blanket top-level sharp override to ^0.35.4 instead of
  scoping it under @imgly/background-removal-node; a path-scoped
  override left the nested copy stuck on 0.32.6 (invalid per
  npm ls), likely because sharp is also a root-level dependency

Verified: npm ls shows a single deduped sharp@0.35.4 and
lodash@4.18.1 across the tree, exercised @imgly's internal sharp
decode + lodash.memoize calls directly, and confirmed npm run lint
/ npm run build still pass.
@sonarqubecloud

sonarqubecloud Bot commented Sep 4, 2026

Copy link
Copy Markdown

@alexmontesg
alexmontesg marked this pull request as ready for review September 4, 2026 12:14
@alexmontesg alexmontesg self-assigned this Sep 4, 2026
@alexmontesg
alexmontesg requested a review from jesusmpc September 4, 2026 12:14
@jesusmpc
jesusmpc merged commit ac7b33e into main Sep 7, 2026
11 checks passed
@jesusmpc
jesusmpc deployed to azure-develop September 7, 2026 06:06 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
azure-develop — b5a569c4 Deployed Sep 7, 2026 by jesusmpc via Deploy to Container Apps #489
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Track and triage npm audit / dependency vulnerabilities

2 participants