Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
The declared ranges already allow the fixed releases. This report is that v12.2.0 was published after those releases (and after the advisories) without refreshing the bundled lockfile, and that the open v12.2.1 release still does not. Consumers cannot apply overrides to bundleDependencies. The fix is the same lockfile refresh as #9871, done in npm's own release process.
Current Behavior
npm@12.2.0 (latest, published 2026-09-30) still bundles these versions:
| Package |
Bundled in 12.2.0 |
First release that clears the current advisories |
Parent range already declared |
brace-expansion |
5.0.9 |
5.0.12 (2026-09-14) |
minimatch@10.2.5 → ^5.0.5 |
ip-address |
10.5.0 |
10.7.1 (2026-09-15); 10.7.3 is current |
socks@2.8.9 → ^10.1.1 |
undici |
6.28.0 |
6.28.1 (2026-09-04); 6.29.0 is current |
node-gyp@13.0.0 → ^6.25.0 |
The advisories were published on 2026-09-28 and 2026-09-29, before the 12.2.0 release. npm audit fix reports each copy as a bundled dependency of npm@12.2.0 and leaves it unchanged. overrides do not replace bundleDependencies (same constraint as #9867 and #9869).
As of 2026-10-02, the latest branch lockfile still resolves brace-expansion@5.0.9, ip-address@10.5.0, and undici@6.28.0. The open release PR #10060 (v12.2.1) does not include these updates.
#9871 refreshed this lockfile in August and landed the versions that are vulnerable again. #9867 and #9869 are closed and do not track the September advisories.
Expected Behavior
Refresh the bundled lockfile and publish a patch. No dependency range change is required.
Please bundle at least:
brace-expansion@5.0.12
ip-address@10.7.3 (10.7.1 or newer clears <=10.7.0)
undici@6.29.0 (6.28.1 or newer clears <=6.28.0)
That is the same kind of lockfile refresh as #9871. Downstream projects cannot patch these copies themselves.
Steps To Reproduce
npm install npm@12.2.0
npm audit
npm audit fix reports the three packages as bundled dependencies of npm@12.2.0 and does not change them.
Advisories currently reported:
Environment
- npm: 12.2.0
- Node.js: v26.10.0
- OS Name: macOS 27.0.1 (arm64)
- System Model Name: Mac
- npm config:
; "user" config from ~/.npmrc
allow-scripts = ["spawn-sync"]
; "project" config from the local project .npmrc
allow-git = "all"
Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
The declared ranges already allow the fixed releases. This report is that
v12.2.0was published after those releases (and after the advisories) without refreshing the bundled lockfile, and that the openv12.2.1release still does not. Consumers cannot applyoverridestobundleDependencies. The fix is the same lockfile refresh as #9871, done in npm's own release process.Current Behavior
npm@12.2.0(latest, published 2026-09-30) still bundles these versions:brace-expansionminimatch@10.2.5→^5.0.5ip-addresssocks@2.8.9→^10.1.1undicinode-gyp@13.0.0→^6.25.0The advisories were published on 2026-09-28 and 2026-09-29, before the 12.2.0 release.
npm audit fixreports each copy as a bundled dependency ofnpm@12.2.0and leaves it unchanged.overridesdo not replacebundleDependencies(same constraint as #9867 and #9869).As of 2026-10-02, the
latestbranch lockfile still resolvesbrace-expansion@5.0.9,ip-address@10.5.0, andundici@6.28.0. The open release PR #10060 (v12.2.1) does not include these updates.#9871 refreshed this lockfile in August and landed the versions that are vulnerable again. #9867 and #9869 are closed and do not track the September advisories.
Expected Behavior
Refresh the bundled lockfile and publish a patch. No dependency range change is required.
Please bundle at least:
brace-expansion@5.0.12ip-address@10.7.3(10.7.1or newer clears<=10.7.0)undici@6.29.0(6.28.1or newer clears<=6.28.0)That is the same kind of lockfile refresh as #9871. Downstream projects cannot patch these copies themselves.
Steps To Reproduce
npm install npm@12.2.0npm auditnpm audit fixreports the three packages as bundled dependencies ofnpm@12.2.0and does not change them.Advisories currently reported:
brace-expansion: GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7pip-address: GHSA-rpw4-54j3-4h4q, GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pwundici: GHSA-3wwx-pv8p-q78v, GHSA-r53p-7pc4-xj5r, GHSA-rfgv-xxqx-mfg5Environment