Skip to content

fix(deps): updated vulnerable npm packages to patched versions - #37

Merged
karlspace merged 2 commits into
mainfrom
fix/security-deps-2026-10
Oct 10, 2026
Merged

karlspace merged 2 commits into
mainfrom
fix/security-deps-2026-10

Conversation

@karlspace

Copy link
Copy Markdown
Contributor

Summary

Fixes all 50 open Dependabot alerts (2 critical, 28 high, 19 medium, 1 low). Every fix stays inside the package's current major. The change is lockfile-only plus four raised floors in package.json, with no overrides. It also adds a PR validation workflow, because until now pull requests were never built or tested (see Testing).

Type of Change

  • Bug fix (security dependency updates)
  • Configuration change (new PR CI workflow)
  • New feature
  • Documentation update

Changes

Commit 1: chore(ci), new .github/workflows/nodejs-pr.yml

  • Calls the org reusable automation-templates/.../nodejs-build.yml@main on PRs to main, the same pattern as EXT-n8n-httpThrottled.
  • Runs npm ci, npm run type-check, npm run test:run, npm run build and npm audit --audit-level=high, on Node from .nvmrc.
  • No deploy, publish or artifact upload.
  • If you don't want this, drop the commit. The PR would then be untested by CI.

Commit 2: fix(deps)

Package Before After Alerts / advisories
protobufjs (runtime, direct) 8.0.0 8.8.0 #22 GHSA-xq3m-2v4x-88gg (critical), #26 #28 #29 #30 #31 #32 #33 #34 #40 #41 #43
@protobufjs/utf8 (runtime) 1.1.0 removed (protobufjs 8.8 no longer depends on it) #27 GHSA-q6x5-8v7m-xcrf
i18next-http-backend (runtime, direct) 3.0.2 3.0.6 #23 GHSA-q89c-q3h5-w34g
vite (dev, direct) 7.3.1 7.3.6 #19 #20 #21 #38 #39
vitest + @vitest/mocker (dev, direct) 4.0.18 4.1.11 #36 GHSA-5xrq-8626-4rwp (critical), #61 #63
workbox-build (via vite-plugin-pwa ^7.4.0) 7.4.0 7.4.1 moves to rollup 4 / plugin-terser 1, drops lodash
rollup 2.79.2 + 4.57.1 4.63.6 #5 #6 GHSA-mw96-cpmx-2vgc
serialize-javascript 6.0.2 7.1.2 #11 GHSA-5c6j-r48x-rmvq, #35 GHSA-qj8w-gfj5-8c6v
lodash 4.17.23 removed #17 #18
picomatch 2.3.1 + 4.0.3 4.0.7 #14 #15
fast-uri 3.1.0 3.1.8 #44 #45 #51 #53 #54 #56 #57 #64
postcss 8.5.6 8.5.28 #24 #46 #47 #50
minimatch 10.1.1 + 5.1.6 10.2.6 + 5.1.9 #9 #10
brace-expansion 2.0.2 2.1.7 #42
nanoid 3.3.11 3.3.19 #58
browserslist 4.28.1 4.29.3 #60
baseline-browser-mapping 2.9.19 2.11.27 #62
@babel/plugin-transform-modules-systemjs 7.28.5 7.29.8 #25
@babel/core 7.28.6 7.29.7 #37
ajv 8.17.1 8.20.0 GHSA-2g4f-4pwh-qvx6 (auto-dismissed #2; same lockfile change)
source-map-js 1.2.1 1.2.2 GHSA-68fv-2mgg-jv7q (high, npm audit, no Dependabot alert yet)

Notes:

  • 7-day release cooldown. Resolved with npm ... --package-lock-only --ignore-scripts --before=2026-10-02, so nothing published in the last week entered the tree (supply-chain hygiene). Every first-patched version predates the cutoff; the newest is fast-uri 3.1.7 from 2026-09-02.
  • Transitive majors are upstream-declared, not overrides.
    • @rollup/plugin-terser 0.4 to 1.0, @rollup/plugin-node-resolve 15 to 16 and serialize-javascript 6 to 7 come from workbox-build 7.4.1.
    • es-module-lexer 1 to 2 and std-env 3 to 4 come from vitest 4.1.
  • @types/node is no longer in the tree. It was only pulled in by protobufjs 8.0.0. src/ uses no Node APIs, and CI type-check verifies this.
  • New optional @napi-rs/lzma-linux-x64-gnu. It is declared by rollup itself since 4.63.0, with the reason documented in rollup's package.json (rollup#6461).

Not fixed:

  • GHSA-xvq9-wjp8-hwqf (low) in i18next-http-backend < 4.0.2 has no 3.x patch, and there is no Dependabot alert for it yet.
  • It is not reachable here: loadPath is ${BASE_URL}locales/{{lng}}/{{ns}}.json, a template with a leading path, which upstream lists as unaffected.
  • Moving to 4.x (drops cross-fetch, needs a host fetch) can be a separate PR.

Testing

  • CI on this PR: the new PR Validation workflow runs type-check, vitest, production build and the audit. CodeQL and GitGuardian also run.
  • Nothing was installed or built locally; only the lockfile was resolved.
  • Re-checked every open alert's vulnerable range against all instances in the new lockfile: 50/50 resolved.
  • npm audit --package-lock-only reports only the low-severity i18next-http-backend advisory above.
  • Not done: a Docker build (docker compose up) and a manual browser check of the PWA.

Supersedes

Dependabot security PRs #30 (fast-uri), #31 (nanoid), #32 (browserslist), #33 (vitest/@vitest/mocker) and #34 (baseline-browser-mapping). They will be closed once this PR is green. The grouped version-update PRs #35 and #36 and the GitHub Actions PRs are not security fixes and stay open.

Checklist

  • Self-reviewed the code
  • No secrets committed
  • Updated documentation if needed (n/a)

Pull requests were never built or tested: deploy-pages.yml and
release.yml only run on push to main, so Dependabot and manual PRs
showed just CodeQL and GitGuardian before merge.

* New nodejs-pr.yml calls the org reusable nodejs-build.yml (same
  pattern as EXT-n8n-httpThrottled) on PRs to main
* Runs npm ci, type-check, vitest run, production build and an npm
  audit gated at high severity, on the Node version from .nvmrc
* No deploy, publish or artifact upload; contents read-only, plus
  pull-requests write that the reusable workflow declares
Resolved all 50 open Dependabot alerts (2 critical, 28 high,
19 medium, 1 low) with updates inside each package's current major.
No overrides or resolutions were needed.

Direct dependencies (package.json floors raised):
* protobufjs 8.0.0 -> 8.8.0 (runtime): GHSA-xq3m-2v4x-88gg (critical),
  GHSA-685m-2w69-288q, GHSA-jvwf-75h9-cwgg, GHSA-75px-5xx7-5xc7,
  GHSA-66ff-xgx4-vchm, GHSA-wcpc-wj8m-hjx6, GHSA-fx83-v9x8-x52w,
  GHSA-2pr8-phx7-x9h3, GHSA-jggg-4jg4-v7c6, GHSA-f38q-mgvj-vph7,
  GHSA-j3f2-48v5-ccww, GHSA-q6x5-8v7m-xcrf; 8.8.0 no longer pulls
  @protobufjs/utf8 1.1.0 (same GHSA) or @types/node
* i18next-http-backend 3.0.2 -> 3.0.6 (runtime): GHSA-q89c-q3h5-w34g
* vite 7.3.1 -> 7.3.6: GHSA-p9ff-h696-f583, GHSA-v2wj-q39q-566r,
  GHSA-4w7w-66w2-5vf9, GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3
* vitest and @vitest/mocker 4.0.18 -> 4.1.11:
  GHSA-5xrq-8626-4rwp (critical), GHSA-82fw-gwwq-j7x9

Transitive build tooling (lockfile only):
* workbox-build 7.4.0 -> 7.4.1 (inside vite-plugin-pwa's ^7.4.0)
  moves to rollup 4 and @rollup/plugin-terser 1 and drops lodash:
  - rollup 2.79.2 and 4.57.1 -> 4.63.6: GHSA-mw96-cpmx-2vgc
  - serialize-javascript 6.0.2 -> 7.1.2: GHSA-5c6j-r48x-rmvq,
    GHSA-qj8w-gfj5-8c6v
  - lodash 4.17.23 removed: GHSA-r5fr-rjxr-66jc, GHSA-f23m-r3pf-42rh
  - picomatch 2.3.1 removed, 4.0.3 -> 4.0.7: GHSA-3v7f-55p6-f55p
* fast-uri 3.1.0 -> 3.1.8: GHSA-4c8g-83qw-93j6, GHSA-v2hh-gcrm-f6hx,
  GHSA-7p8r-x3mc-p8w7, GHSA-v39h-62p7-jpjc, GHSA-q3j6-qgpj-74h6,
  GHSA-f65p-4m7j-42xc, GHSA-jqff-g426-hqxp, GHSA-qw65-cvwx-89v3
* postcss 8.5.6 -> 8.5.28: GHSA-qx2v-qp2m-jg93, GHSA-6g55-p6wh-862q,
  GHSA-r28c-9q8g-f849, GHSA-fxqj-rqcc-2cmp
* minimatch 10.1.1 -> 10.2.6 and 5.1.6 -> 5.1.9: GHSA-7r86-cg39-jmmj
* brace-expansion 2.0.2 -> 2.1.7: GHSA-3jxr-9vmj-r5cp
* nanoid 3.3.11 -> 3.3.19: GHSA-xwg4-73v4-xw9w
* browserslist 4.28.1 -> 4.29.3: GHSA-73wf-gq98-2v4g
* baseline-browser-mapping 2.9.19 -> 2.11.27: GHSA-w5vr-8v7q-w6rv
* @babel/plugin-transform-modules-systemjs 7.28.5 -> 7.29.8:
  GHSA-fv7c-fp4j-7gwp
* @babel/core 7.28.6 -> 7.29.7: GHSA-4x5r-pxfx-6jf8

Same lockfile change, no open Dependabot alert:
* ajv 8.17.1 -> 8.20.0: GHSA-2g4f-4pwh-qvx6 (medium)
* source-map-js 1.2.1 -> 1.2.2: GHSA-68fv-2mgg-jv7q (high)

Resolved with npm --before=2026-10-02, a 7-day release cooldown, so
no version published in the last week entered the tree; every
patched version above predates that cutoff.

Not fixed: GHSA-xvq9-wjp8-hwqf (low, i18next-http-backend < 4.0.2)
has no 3.x patch and is not reachable here - loadPath starts with
BASE_URL, a template upstream lists as unaffected.
@karlspace karlspace added dependencies Dependabot: dependencies npm Dependabot: npm labels Oct 9, 2026
@karlspace
karlspace merged commit b71e6cc into main Oct 10, 2026
6 checks passed
@karlspace
karlspace deleted the fix/security-deps-2026-10 branch October 10, 2026 09:55
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 0.1.3 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependabot: dependencies npm Dependabot: npm released

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant