Skip to content

deps: update vulnerable transitive dependencies - #10080

Open
keyurgovrani wants to merge 3 commits into
npm:latestfrom
keyurgovrani:deps/vulnerable-transitive-latest
Open

keyurgovrani wants to merge 3 commits into
npm:latestfrom
keyurgovrani:deps/vulnerable-transitive-latest

Conversation

@keyurgovrani

Copy link
Copy Markdown

Summary

  • updates bundled brace-expansion from 5.0.9 to 5.0.12
  • updates bundled ip-address from 10.5.0 to 10.7.3
  • updates bundled undici from 6.28.0 to 6.29.0
  • refreshes the nested development copies of brace-expansion to 1.1.21. tap bundles its own 1.1.11, which a lockfile update cannot reach.

Each package lands in its own deps: <pkg>@<version> commit.

Advisories fixed

Package Advisory Severity First fixed
undici GHSA-rfgv-xxqx-mfg5 (CVE-2026-19534) high 6.28.1
undici GHSA-3wwx-pv8p-q78v (CVE-2026-85024) medium 6.28.1
undici GHSA-r53p-7pc4-xj5r (CVE-2026-18540) low 6.28.1
brace-expansion GHSA-6j4f-fj2g-mc7p (CVE-2026-102276) high 5.0.10 / 1.1.19
brace-expansion GHSA-qhr7-859c-m2p7 (CVE-2026-102278) high 5.0.11 / 1.1.20
brace-expansion GHSA-q2hr-2g5m-vwhr (CVE-2026-102277) medium 5.0.12 / 1.1.21
ip-address GHSA-rpw4-54j3-4h4q (CVE-2026-101913) medium 10.5.1
ip-address GHSA-2vr4-cq9g-pvrc (CVE-2026-101910) medium 10.5.1
ip-address GHSA-h3mg-xc3c-68pw (CVE-2026-101911) medium 10.7.1
ip-address GHSA-j6r3-76f7-8jcv (CVE-2026-101912) medium 10.7.1

The production audit now reports only http-cache-semantics (GHSA-ch52-4w7c-c8xp, CVE-2026-93748), which has no fixed release yet.

Node.js 24 ships npm 11, so images built on node:lts still report these advisories. #10076 backports the same three commits to release/v11.

Testing

  • node . update <pkg> --ignore-scripts, one package per commit, then node . run dependencies --ignore-scripts
  • node scripts/resetdeps.js && node scripts/git-dirty.js prints git clean
  • the vendored files are byte-identical to the published tarballs, and each lockfile integrity matches the registry
  • node . ls brace-expansion ip-address undici --all --omit=dev
  • node . audit --omit=dev --json
  • TMPDIR=$PWD/.tmp node . test --ignore-scripts on Node 24.21.0 (macOS). The same 16 files fail on latest with and without these commits, from temp-path assumptions on this machine. CI on Linux is the real gate.

🤖 Generated with Claude Code

keyurgovrani and others added 3 commits October 5, 2026 17:27
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@nkolev92

nkolev92 commented Oct 5, 2026

Copy link
Copy Markdown

@jeffkl PTAL

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants