Repository navigation
Track and triage npm audit / dependency vulnerabilities - #122
Merged
Merged
Conversation
Signed-off-by: Alejandro Montes <alejandromogarcia@ext.inditex.com>
alexmontesg
force-pushed
the
dependency/GH-120-bump-vulnerable-de
branch
from
September 4, 2026 11:40
fa00c27 to
f5687dc
Compare
- override qs to ^6.16.0 (express/body-parser pin ~6.15.x, can't bump directly; qs 6.16 changelog is additive-only) - override sequelize's nested uuid to ^11.1.1 (sequelize only uses v1/v4, unaffected by the v3/v5/v6 buffer advisory) - bump prettier-eslint 16.3.0 -> 17.1.2 (unused in code/scripts, fixes nested @typescript-eslint/parser, typescript-estree, minimatch) - bump sharp 0.34.3 -> 0.35.4 (direct usage only; verified no use of removed/renamed APIs: paletteBitDepth, sharpen opts, jp2k) Left unfixed, no safe path available: - image-size: latest release (2.0.2) still vulnerable upstream - @imgly/background-removal-node: bundles pinned lodash/sharp, no newer release exists - @ai-sdk/provider-utils/ui-utils, @mastra/core (low): buried in @mastra/core's legacy AI SDK v4 shim; fixing requires bumping the whole @mastra/* family, disproportionate blast radius for the severity - @mastra/memory 1.28.2 bump reverted: requires newer @mastra/core exports (MAX_KNOWLEDGE_NODE_DESCRIPTION_LENGTH) not present in the pinned @mastra/core@1.36.0; broke at runtime on import Verified with npm run lint, npm run build, and targeted runtime smoke tests of sharp and @mastra/memory.
@imgly/background-removal-node pins vulnerable lodash (~4.17.21, CWE-94/CWE-1321) and sharp (~0.32.4, libvips CVEs) with no newer release available upstream. - override lodash to ^4.18.1 under @imgly/background-removal-node (package only calls lodash.memoize, not the vulnerable template/unset/omit functions) - add a blanket top-level sharp override to ^0.35.4 instead of scoping it under @imgly/background-removal-node; a path-scoped override left the nested copy stuck on 0.32.6 (invalid per npm ls), likely because sharp is also a root-level dependency Verified: npm ls shows a single deduped sharp@0.35.4 and lodash@4.18.1 across the tree, exercised @imgly's internal sharp decode + lodash.memoize calls directly, and confirmed npm run lint / npm run build still pass.
|
jesusmpc
approved these changes
Sep 7, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Closes #120