Skip to content

[BUG] v12.2.0 shipped a stale bundled lockfile after in-range security fixes were already published #10062

Description

@stein2nd

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

This is not just a request to bump a dependency for a CVE

  • This is not solely a request to bump a dependency for a CVE

The declared ranges already allow the fixed releases. This report is that v12.2.0 was published after those releases (and after the advisories) without refreshing the bundled lockfile, and that the open v12.2.1 release still does not. Consumers cannot apply overrides to bundleDependencies. The fix is the same lockfile refresh as #9871, done in npm's own release process.

Current Behavior

npm@12.2.0 (latest, published 2026-09-30) still bundles these versions:

Package Bundled in 12.2.0 First release that clears the current advisories Parent range already declared
brace-expansion 5.0.9 5.0.12 (2026-09-14) minimatch@10.2.5 → ^5.0.5
ip-address 10.5.0 10.7.1 (2026-09-15); 10.7.3 is current socks@2.8.9 → ^10.1.1
undici 6.28.0 6.28.1 (2026-09-04); 6.29.0 is current node-gyp@13.0.0 → ^6.25.0

The advisories were published on 2026-09-28 and 2026-09-29, before the 12.2.0 release. npm audit fix reports each copy as a bundled dependency of npm@12.2.0 and leaves it unchanged. overrides do not replace bundleDependencies (same constraint as #9867 and #9869).

As of 2026-10-02, the latest branch lockfile still resolves brace-expansion@5.0.9, ip-address@10.5.0, and undici@6.28.0. The open release PR #10060 (v12.2.1) does not include these updates.

#9871 refreshed this lockfile in August and landed the versions that are vulnerable again. #9867 and #9869 are closed and do not track the September advisories.

Expected Behavior

Refresh the bundled lockfile and publish a patch. No dependency range change is required.

Please bundle at least:

  • brace-expansion@5.0.12
  • ip-address@10.7.3 (10.7.1 or newer clears <=10.7.0)
  • undici@6.29.0 (6.28.1 or newer clears <=6.28.0)

That is the same kind of lockfile refresh as #9871. Downstream projects cannot patch these copies themselves.

Steps To Reproduce

  1. npm install npm@12.2.0
  2. npm audit
  3. npm audit fix reports the three packages as bundled dependencies of npm@12.2.0 and does not change them.

Advisories currently reported:

Environment

  • npm: 12.2.0
  • Node.js: v26.10.0
  • OS Name: macOS 27.0.1 (arm64)
  • System Model Name: Mac
  • npm config:
; "user" config from ~/.npmrc
allow-scripts = ["spawn-sync"]

; "project" config from the local project .npmrc
allow-git = "all"

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions