Repository navigation
fix(deps): updated vulnerable npm packages to patched versions - #37
Merged
Merged
Conversation
Pull requests were never built or tested: deploy-pages.yml and release.yml only run on push to main, so Dependabot and manual PRs showed just CodeQL and GitGuardian before merge. * New nodejs-pr.yml calls the org reusable nodejs-build.yml (same pattern as EXT-n8n-httpThrottled) on PRs to main * Runs npm ci, type-check, vitest run, production build and an npm audit gated at high severity, on the Node version from .nvmrc * No deploy, publish or artifact upload; contents read-only, plus pull-requests write that the reusable workflow declares
Resolved all 50 open Dependabot alerts (2 critical, 28 high, 19 medium, 1 low) with updates inside each package's current major. No overrides or resolutions were needed. Direct dependencies (package.json floors raised): * protobufjs 8.0.0 -> 8.8.0 (runtime): GHSA-xq3m-2v4x-88gg (critical), GHSA-685m-2w69-288q, GHSA-jvwf-75h9-cwgg, GHSA-75px-5xx7-5xc7, GHSA-66ff-xgx4-vchm, GHSA-wcpc-wj8m-hjx6, GHSA-fx83-v9x8-x52w, GHSA-2pr8-phx7-x9h3, GHSA-jggg-4jg4-v7c6, GHSA-f38q-mgvj-vph7, GHSA-j3f2-48v5-ccww, GHSA-q6x5-8v7m-xcrf; 8.8.0 no longer pulls @protobufjs/utf8 1.1.0 (same GHSA) or @types/node * i18next-http-backend 3.0.2 -> 3.0.6 (runtime): GHSA-q89c-q3h5-w34g * vite 7.3.1 -> 7.3.6: GHSA-p9ff-h696-f583, GHSA-v2wj-q39q-566r, GHSA-4w7w-66w2-5vf9, GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3 * vitest and @vitest/mocker 4.0.18 -> 4.1.11: GHSA-5xrq-8626-4rwp (critical), GHSA-82fw-gwwq-j7x9 Transitive build tooling (lockfile only): * workbox-build 7.4.0 -> 7.4.1 (inside vite-plugin-pwa's ^7.4.0) moves to rollup 4 and @rollup/plugin-terser 1 and drops lodash: - rollup 2.79.2 and 4.57.1 -> 4.63.6: GHSA-mw96-cpmx-2vgc - serialize-javascript 6.0.2 -> 7.1.2: GHSA-5c6j-r48x-rmvq, GHSA-qj8w-gfj5-8c6v - lodash 4.17.23 removed: GHSA-r5fr-rjxr-66jc, GHSA-f23m-r3pf-42rh - picomatch 2.3.1 removed, 4.0.3 -> 4.0.7: GHSA-3v7f-55p6-f55p * fast-uri 3.1.0 -> 3.1.8: GHSA-4c8g-83qw-93j6, GHSA-v2hh-gcrm-f6hx, GHSA-7p8r-x3mc-p8w7, GHSA-v39h-62p7-jpjc, GHSA-q3j6-qgpj-74h6, GHSA-f65p-4m7j-42xc, GHSA-jqff-g426-hqxp, GHSA-qw65-cvwx-89v3 * postcss 8.5.6 -> 8.5.28: GHSA-qx2v-qp2m-jg93, GHSA-6g55-p6wh-862q, GHSA-r28c-9q8g-f849, GHSA-fxqj-rqcc-2cmp * minimatch 10.1.1 -> 10.2.6 and 5.1.6 -> 5.1.9: GHSA-7r86-cg39-jmmj * brace-expansion 2.0.2 -> 2.1.7: GHSA-3jxr-9vmj-r5cp * nanoid 3.3.11 -> 3.3.19: GHSA-xwg4-73v4-xw9w * browserslist 4.28.1 -> 4.29.3: GHSA-73wf-gq98-2v4g * baseline-browser-mapping 2.9.19 -> 2.11.27: GHSA-w5vr-8v7q-w6rv * @babel/plugin-transform-modules-systemjs 7.28.5 -> 7.29.8: GHSA-fv7c-fp4j-7gwp * @babel/core 7.28.6 -> 7.29.7: GHSA-4x5r-pxfx-6jf8 Same lockfile change, no open Dependabot alert: * ajv 8.17.1 -> 8.20.0: GHSA-2g4f-4pwh-qvx6 (medium) * source-map-js 1.2.1 -> 1.2.2: GHSA-68fv-2mgg-jv7q (high) Resolved with npm --before=2026-10-02, a 7-day release cooldown, so no version published in the last week entered the tree; every patched version above predates that cutoff. Not fixed: GHSA-xvq9-wjp8-hwqf (low, i18next-http-backend < 4.0.2) has no 3.x patch and is not reachable here - loadPath starts with BASE_URL, a template upstream lists as unaffected.
This was referenced Oct 9, 2026
|
🎉 This PR is included in version 0.1.3 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes all 50 open Dependabot alerts (2 critical, 28 high, 19 medium, 1 low). Every fix stays inside the package's current major. The change is lockfile-only plus four raised floors in
package.json, with nooverrides. It also adds a PR validation workflow, because until now pull requests were never built or tested (see Testing).Type of Change
Changes
Commit 1:
chore(ci), new.github/workflows/nodejs-pr.ymlautomation-templates/.../nodejs-build.yml@mainon PRs tomain, the same pattern asEXT-n8n-httpThrottled.npm ci,npm run type-check,npm run test:run,npm run buildandnpm audit --audit-level=high, on Node from.nvmrc.Commit 2:
fix(deps)^7.4.0)npm audit, no Dependabot alert yet)Notes:
npm ... --package-lock-only --ignore-scripts --before=2026-10-02, so nothing published in the last week entered the tree (supply-chain hygiene). Every first-patched version predates the cutoff; the newest is fast-uri 3.1.7 from 2026-09-02.@rollup/plugin-terser0.4 to 1.0,@rollup/plugin-node-resolve15 to 16 andserialize-javascript6 to 7 come fromworkbox-build7.4.1.es-module-lexer1 to 2 andstd-env3 to 4 come from vitest 4.1.@types/nodeis no longer in the tree. It was only pulled in by protobufjs 8.0.0.src/uses no Node APIs, and CI type-check verifies this.@napi-rs/lzma-linux-x64-gnu. It is declared by rollup itself since 4.63.0, with the reason documented in rollup'spackage.json(rollup#6461).Not fixed:
i18next-http-backend< 4.0.2 has no 3.x patch, and there is no Dependabot alert for it yet.loadPathis${BASE_URL}locales/{{lng}}/{{ns}}.json, a template with a leading path, which upstream lists as unaffected.cross-fetch, needs a hostfetch) can be a separate PR.Testing
npm audit --package-lock-onlyreports only the low-severity i18next-http-backend advisory above.docker compose up) and a manual browser check of the PWA.Supersedes
Dependabot security PRs #30 (fast-uri), #31 (nanoid), #32 (browserslist), #33 (vitest/@vitest/mocker) and #34 (baseline-browser-mapping). They will be closed once this PR is green. The grouped version-update PRs #35 and #36 and the GitHub Actions PRs are not security fixes and stay open.
Checklist