From 2d3c29832f49070a4c159f3cd2a73d41aa4582df Mon Sep 17 00:00:00 2001 From: orbivort <273379167+orbivort@users.noreply.github.com> Date: Wed, 30 Sep 2026 11:46:47 +0800 Subject: [PATCH] chore: upgrade dependencies --- CHANGELOG.md | 69 +++++++++++++++++++++++ packages/backend/package.json | 6 +- pnpm-lock.yaml | 101 ++++++++++++++-------------------- pnpm-workspace.yaml | 31 ++++++++++- 4 files changed, 141 insertions(+), 66 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 48ba747..9c3c828 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,73 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 --- +## [Unreleased] + +### Security + +- Remediate **22** dependency vulnerabilities (**6 high**, **13 moderate**, **3 low**): + - `nodemailer` 9.1.1 → 10.0.12 — fixes a quadratic-time `addressparser` free-text + fallback that allows remote denial of service + ([GHSA-v53p-9fqp-m79j](https://github.com/advisories/GHSA-v53p-9fqp-m79j)), a + process-global DNS cache that reuses the TLS `servername` across transports and so + enables cross-tenant SMTP credential disclosure + ([GHSA-6vj9-mwq6-2f5v](https://github.com/advisories/GHSA-6vj9-mwq6-2f5v)), nested + structured recipient arrays that bypass the parser depth limit and exhaust the stack + ([GHSA-8vvx-rff5-p5rq](https://github.com/advisories/GHSA-8vvx-rff5-p5rq)), and a + quoted local-part that can produce a malformed envelope recipient through RFC 5322 + comment parsing + ([GHSA-g57g-f23g-4646](https://github.com/advisories/GHSA-g57g-f23g-4646)) + - `multer` 2.3.0 → 2.4.0 — fixes a denial of service via orphaned disk writes on + aborted uploads + ([GHSA-3pph-fpjx-jg34](https://github.com/advisories/GHSA-3pph-fpjx-jg34)) + - `undici` 8.10.0 → 8.10.2 — fixes three high-severity issues: a denial of service via + an unrequested WebSocket subprotocol + ([GHSA-rfgv-xxqx-mfg5](https://github.com/advisories/GHSA-rfgv-xxqx-mfg5)), a TLS + certificate validation bypass via dropped connect options in `BalancedPool` + ([GHSA-w293-vg96-wgc3](https://github.com/advisories/GHSA-w293-vg96-wgc3)), and + cross-origin cache poisoning via missing origin isolation in interceptors + ([GHSA-vp8m-p9jh-q5pm](https://github.com/advisories/GHSA-vp8m-p9jh-q5pm)); five + moderate issues: denial of service via an unhandled error in WebSocket + `permessage-deflate` decompression + ([GHSA-3wwx-pv8p-q78v](https://github.com/advisories/GHSA-3wwx-pv8p-q78v)), via an + orphaned `RetryHandler` response body + ([GHSA-pmjh-fq2x-6v4x](https://github.com/advisories/GHSA-pmjh-fq2x-6v4x)), and via + unbounded decompression of compressed responses + ([GHSA-3xpg-4rpp-hhhm](https://github.com/advisories/GHSA-3xpg-4rpp-hhhm)), + cross-user cookie disclosure via `Set-Cookie` caching in shared caches + ([GHSA-2jfj-6hjv-fm6j](https://github.com/advisories/GHSA-2jfj-6hjv-fm6j)), and + denial of service via an unclean `WebSocketStream` close + ([GHSA-rx4f-c7p8-82vq](https://github.com/advisories/GHSA-rx4f-c7p8-82vq)); and three + low-severity issues: downstream response splitting via the retry interceptor + ([GHSA-r53p-7pc4-xj5r](https://github.com/advisories/GHSA-r53p-7pc4-xj5r)), response + truncation via oversized chunked responses in the dump interceptor + ([GHSA-2gqq-gqf2-x968](https://github.com/advisories/GHSA-2gqq-gqf2-x968)), and + caching/replay of unsafe HTTP method responses + ([GHSA-8436-99hf-9mmv](https://github.com/advisories/GHSA-8436-99hf-9mmv)). It is + pulled by `jsdom` (the vitest DOM environment), which declares `^8.9.0`, and is pinned + by a pnpm override + - `brace-expansion` 5.0.9 → 5.0.12 — fixes two stack-exhaustion denial-of-service issues + via uncontrolled recursion + ([GHSA-qhr7-859c-m2p7](https://github.com/advisories/GHSA-qhr7-859c-m2p7), + [GHSA-6j4f-fj2g-mc7p](https://github.com/advisories/GHSA-6j4f-fj2g-mc7p)) and a + quadratic-time CPU denial of service in the `{a},b}` rewrite + ([GHSA-q2hr-2g5m-vwhr](https://github.com/advisories/GHSA-q2hr-2g5m-vwhr)). It is + pulled by `minimatch` through the eslint and `rimraf > glob` toolchains and is pinned + by a pnpm override + - `fast-uri` 3.1.7 → 3.1.8 — fixes inconsistent host-case normalization via + percent-encoded octets + ([GHSA-hrr3-gc8f-f4qj](https://github.com/advisories/GHSA-hrr3-gc8f-f4qj)). It is + pulled by `ajv` through the Prisma CLI and stylelint toolchains and is pinned by a pnpm + override + - `ip-address` 10.7.0 → 10.7.2 — fixes an allow-list bypass where `isInSubnet()` / + `isHostInSubnet()` compare addresses of different families as if they shared an + address space + ([GHSA-j6r3-76f7-8jcv](https://github.com/advisories/GHSA-j6r3-76f7-8jcv)) and an + unbounded parse diagnostic that can stall or crash the process + ([GHSA-h3mg-xc3c-68pw](https://github.com/advisories/GHSA-h3mg-xc3c-68pw)). It is + pulled by `express-rate-limit`, which declares `^10.2.0`, and is pinned by a pnpm + override + ## [1.1.0] - 2026-09-15 ### Added @@ -217,6 +284,8 @@ Key achievements of this release: --- +[Unreleased]: https://github.com/orbivort/peoplevate/compare/v1.1.0...HEAD + [1.0.0]: https://github.com/orbivort/peoplevate/releases/tag/v1.0.0 [1.0.1]: https://github.com/orbivort/peoplevate/compare/v1.0.0...v1.0.1 [1.0.2]: https://github.com/orbivort/peoplevate/compare/v1.0.1...v1.0.2 diff --git a/packages/backend/package.json b/packages/backend/package.json index 694e48b..e421b78 100644 --- a/packages/backend/package.json +++ b/packages/backend/package.json @@ -57,9 +57,9 @@ "express-rate-limit": "^8.7.0", "helmet": "^8.3.0", "jsonwebtoken": "^9.0.3", - "multer": "^2.3.0", + "multer": "^2.4.0", "node-cron": "^4.6.0", - "nodemailer": "^9.1.1", + "nodemailer": "^10.0.9", "pg": "catalog:", "uuid": "^14.0.2", "winston": "^3.19.0", @@ -75,7 +75,7 @@ "@types/jsonwebtoken": "^9.0.10", "@types/multer": "^2.2.0", "@types/node": "catalog:", - "@types/nodemailer": "^8.0.1", + "@types/nodemailer": "^8.0.2", "@types/supertest": "^7.2.1", "@vitest/coverage-v8": "catalog:", "cross-env": "catalog:", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 2fb3c80..83fd8e2 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -45,10 +45,13 @@ overrides: nanoid: 3.3.18 deepmerge-ts: 8.0.2 mysql2: 3.24.3 - fast-uri: 3.1.7 + fast-uri: 3.1.8 qs: 6.16.0 js-yaml: 4.3.2 colord: 2.10.0 + undici: 8.10.2 + brace-expansion: 5.0.12 + ip-address: 10.7.2 importers: @@ -100,14 +103,14 @@ importers: specifier: ^9.0.3 version: 9.0.3 multer: - specifier: ^2.3.0 - version: 2.3.0 + specifier: ^2.4.0 + version: 2.4.0 node-cron: specifier: ^4.6.0 version: 4.6.0 nodemailer: - specifier: ^9.1.1 - version: 9.1.1 + specifier: ^10.0.9 + version: 10.0.12 pg: specifier: 'catalog:' version: 8.23.0 @@ -149,8 +152,8 @@ importers: specifier: 'catalog:' version: 24.13.3 '@types/nodemailer': - specifier: ^8.0.1 - version: 8.0.1 + specifier: ^8.0.2 + version: 8.0.2 '@types/supertest': specifier: ^7.2.1 version: 7.2.1 @@ -1794,8 +1797,8 @@ packages: '@types/node@26.5.1': resolution: {integrity: sha512-CzNm2FezW4VR/LjG6yUdiEgLE/rAQ9Slj5gCu/C2VrdcW7I0ahNZ8DRbHT7zOZ6r3ONgd/bsQIeSaoDGrd1C6g==} - '@types/nodemailer@8.0.1': - resolution: {integrity: sha512-PxpaInm8V1JQDd4j0ds5HfvWQk8JupS1C0Picb96QJsrrRDjBH+DlK7L4ZdNSqNULhiZRQHc40nLVShaGxXAMw==} + '@types/nodemailer@8.0.2': + resolution: {integrity: sha512-c7M5ox8p0nEOfbJ2E9Qcmt8/QCu/VzsiAhzBiZbvky2PhKZDHpKB3sQHBM5MEZNkCfBOaS6S9//AGPRTNB7IaA==} '@types/pg@8.23.1': resolution: {integrity: sha512-fKVHpikPdg4GKks3JuLEhvwSyvwzF23hnabPy6DD8ljVbC7+6J5dQzdv4arV6jqq57djnMgs1HKBxX4P8aBI3A==} @@ -2086,15 +2089,15 @@ packages: better-result@2.10.0: resolution: {integrity: sha512-oQhh0y1qo2/ZKdAAEvHZAqKKiHOFU5k/bW96fE2ScgQOVkJRiHwB+nOS1SgFsYqRlxMDWvefXi9Q3px7QvgNDw==} - bidi-js@1.0.3: - resolution: {integrity: sha512-RKshQI1R3YQ+n9YJz2QQ147P66ELpa1FQEg20Dk8oW9t2KgLbpDLLp9aGZ7y8WHSshDknG0bknqGw5/tyCs5tw==} + bidi-js@1.1.0: + resolution: {integrity: sha512-fX1Onk0tdVPC7obPWB5EbJ1z7NVhLq4m2xZLq2YXBkxzMXIGRpNMU88n0EPgWseKl12J7zXs7qrDxPK4sRs2fg==} body-parser@2.3.0: resolution: {integrity: sha512-2cGmJupaNgg+QUwVLAucDuWuoMZ6EX9iHDRswZ5lsNYEmwPaRknMPCLZz07yTzVq/83p4o/wzbDZbBrTvGGTIw==} engines: {node: '>=18'} - brace-expansion@5.0.9: - resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==} + brace-expansion@5.0.12: + resolution: {integrity: sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==} engines: {node: 20 || >=22} braces@3.0.3: @@ -2109,9 +2112,6 @@ packages: buffer-equal-constant-time@1.0.1: resolution: {integrity: sha512-zRpUiDwd/xk6ADqPMATG8vc9VPrkck7T07OIx0gnjmJAnHnTVXNQG3vfvWNuiZIkwu9KrKdA1iJKfsfTVxE6NA==} - buffer-from@1.1.2: - resolution: {integrity: sha512-E+XQCRwSbaaiChtv6k6Dwgc+bx+Bs6vuKJHHl5kox/BaKbhiXzqQOwK4cO22yElGp2OCmjwVhT3HmxgyPGnJfQ==} - busboy@1.6.0: resolution: {integrity: sha512-8SFQbg/0hQ9xy3UNTB0YEnsNBbWfhf7RtnzpL7TkBiTBRfrQ9Fxcnz7VJsleJpyp6rVLvXiuORqjlHi5q+PYuA==} engines: {node: '>=10.16.0'} @@ -2217,10 +2217,6 @@ packages: component-emitter@1.3.1: resolution: {integrity: sha512-T0+barUSQRTUQASh8bx02dl+DhF54GtIDY13Y3m9oWTklKbb3Wv974meRpeZ3lp1JpLVECWWNHC4vaG2XHXouQ==} - concat-stream@2.0.0: - resolution: {integrity: sha512-MWufYdFw53ccGjCA+Ol7XJYpAlW6/prSMzuPOTRnJGcGzuhLn4Scrz7qf6o8bROZ514ltazcIFJZevcfbo0x7A==} - engines: {'0': node >= 6.0} - concurrently@10.0.5: resolution: {integrity: sha512-JaP/CoftUrCcAFW/g//RbgEGwlelnEae6cfBLgH6ZdO6s8jPkn6p9SB9u6pdVxYXoiSnFqseOlHfrEfF82TVOg==} engines: {node: '>=22'} @@ -2636,8 +2632,8 @@ packages: fast-string-width@3.0.2: resolution: {integrity: sha512-gX8LrtNEI5hq8DVUfRQMbr5lpaS4nMIWV+7XEbXk2b8kiQIizgnlr12B4dA3ZEx3308ze0O4Q1R+cHts8kyUJg==} - fast-uri@3.1.7: - resolution: {integrity: sha512-dOvZVzjdZdz7phd9v6jCbwxrBW3fK6n8Rc0CtdmM4bumzMnxywBYhuph6J819RRw/ku+rLbelwfMunktuzVVHg==} + fast-uri@3.1.8: + resolution: {integrity: sha512-GZMtZUTNRpOVIECoXwLNZS5xUGE+mVNbTB8h/7Rwh2TFWcBQiPzTgyZi05BF9UMZKkLJv8XBRJTlU7zg8+ZfMg==} fast-wrap-ansi@0.2.2: resolution: {integrity: sha512-7F2Fl+TjRSenLqlU3UjSH0iyqopqoZIu7eZVpEirP2g1GtWa2G/ecEmBdgz31+Mxr+ELclgg6sokpSFIQiZ02Q==} @@ -2913,8 +2909,8 @@ packages: resolution: {integrity: sha512-5Hh7Y1wQbvY5ooGgPbDaL5iYLAPzMTUrjMulskHLH6wnv/A+1q5rgEaiuqEjB+oxGXIVZs1FF+R/KPN3ZSQYYg==} engines: {node: '>=12'} - ip-address@10.7.0: - resolution: {integrity: sha512-BGFsyJd5mpXp3rK6jIdADLNgpJUK1jnjzvYF8lK+VyDab9JAmqN0YOKDdP17HlgKb2+ehPgDc8EtnRLbGCAMhA==} + ip-address@10.7.2: + resolution: {integrity: sha512-7H/2gFSIitxc0hG3nOI1glS8QLo/EHBFFLk8vEUjXY/xu0AdL8jZ9U1IzO2PUm0d2D/ofQcAifb0g6OBkt8U7w==} engines: {node: '>= 12'} ipaddr.js@1.9.1: @@ -3356,8 +3352,8 @@ packages: typescript: optional: true - multer@2.3.0: - resolution: {integrity: sha512-cjNbm3sttszgZeGfJR124D+jFEfkXCVAsoPBmFn9X7UxmDSFHWqE2CoEj0vrmSpuAFnqWR1Szcm9QTsiHr60Xw==} + multer@2.4.0: + resolution: {integrity: sha512-7dqa0ZcFfzbefdTuIkzOSMvZWC0J7FLqBOjJUZvDCXShIURWKxAyTT1wHhnE5q19c7jOJf43IYYKjBmZVZmvhg==} engines: {node: '>= 10.16.0'} mute-stream@3.0.0: @@ -3402,9 +3398,9 @@ packages: resolution: {integrity: sha512-D9UOmYG3UH1V+ENW56t5QXBwJw1YEY18ruVeus89Rw+SyIgjPkCO84bRzO3uNIYosJbNwiabWVn48o3uJLjxFQ==} engines: {node: '>=18'} - nodemailer@9.1.1: - resolution: {integrity: sha512-izw9mVKFix6YSnC9eLgV6g1opl9DUlRio9ZNcq+Wu9Ujn2UwF+8Nl0B8nz22kEC+CTZCvinkxwJ0DeFbb6NwcQ==} - engines: {node: '>=6.0.0'} + nodemailer@10.0.12: + resolution: {integrity: sha512-PQ46oNbNMuH/Sno7B5IWIU9etytwrO0xdTFvWXpIQFRXhBAXtzD48243AS+BCbQQTPD8y3fqUrgLn0tSo77gvg==} + engines: {node: '>=20.0.0'} normalize-path@3.0.0: resolution: {integrity: sha512-6eZs5Ls3WtCisHWp9S2GUy8dqkpGi4BVSz3GaqiE6ezub0512ESztXUwUB6C6IKbQkY2Pnb/mD4WYojCRwcwLA==} @@ -4134,9 +4130,6 @@ packages: resolution: {integrity: sha512-faYHw0anBbc/kWF3zFTEnxSFOAGUX9GFbOBthvDdLsIlEoWOFOtS0zgCiQYwIskL9iGXZL3kAXD8OoZ4GmMATA==} engines: {node: '>= 18'} - typedarray@0.0.6: - resolution: {integrity: sha512-/aCDEGatGvZ2BIk+HmLf4ifCJFwvKFNb9/JeZPMulfgFracn9QFcAf5GO8B/mweUjSoblS5In0cWhqpfs/5PQA==} - typescript-eslint@8.70.0: resolution: {integrity: sha512-P/W5cz70/cQAuKfY3xwQMWWTV7BvJ0mAQmi+9mBcsVPaBUpd6Ohpa+fECv9rBFrQcig86jAiNBFNWUqnTjr4pw==} engines: {node: ^18.18.0 || ^20.9.0 || >=21.1.0} @@ -4155,8 +4148,8 @@ packages: undici-types@8.9.0: resolution: {integrity: sha512-KTDyRTYX8sWmKXAikPHHSyc63CRPETMctyjKFupcC6OBLXT3xsN0e9aF7m+mIXutFWpUXuedtowG7iLOzp0kQg==} - undici@8.10.0: - resolution: {integrity: sha512-HvltHd7avK13QIw/oLe4qoOLyoVSoafqJ2jYOrtMRBkbYT31eiBQ8O0ehRKZiEZCMEyLFQNIADpgCWC5fALvYQ==} + undici@8.10.2: + resolution: {integrity: sha512-/y4/bH9YNU5hi9NIrpOuvGXFcxrj3CMrV+/AYpowAYTpHn8gX/XPFjNy766FPoYY0miQhdW977JFWKGNhBdwyQ==} engines: {node: '>=22.19.0'} unicorn-magic@0.4.0: @@ -4425,7 +4418,7 @@ snapshots: '@asamuzakjp/dom-selector@8.3.2': dependencies: - bidi-js: 1.0.3 + bidi-js: 1.1.0 css-tree: 3.2.1 is-potential-custom-element-name: 1.0.1 lru-cache: 11.5.2 @@ -5746,9 +5739,9 @@ snapshots: dependencies: undici-types: 8.9.0 - '@types/nodemailer@8.0.1': + '@types/nodemailer@8.0.2': dependencies: - '@types/node': 24.13.3 + '@types/node': 26.5.1 '@types/pg@8.23.1': dependencies: @@ -6062,7 +6055,7 @@ snapshots: ajv@8.20.0: dependencies: fast-deep-equal: 3.1.3 - fast-uri: 3.1.7 + fast-uri: 3.1.8 json-schema-traverse: 1.0.0 require-from-string: 2.0.2 @@ -6123,7 +6116,7 @@ snapshots: better-result@2.10.0: {} - bidi-js@1.0.3: + bidi-js@1.1.0: dependencies: require-from-string: 2.0.2 @@ -6141,7 +6134,7 @@ snapshots: transitivePeerDependencies: - supports-color - brace-expansion@5.0.9: + brace-expansion@5.0.12: dependencies: balanced-match: 4.0.4 @@ -6159,8 +6152,6 @@ snapshots: buffer-equal-constant-time@1.0.1: {} - buffer-from@1.1.2: {} - busboy@1.6.0: dependencies: streamsearch: 1.1.0 @@ -6270,13 +6261,6 @@ snapshots: component-emitter@1.3.1: {} - concat-stream@2.0.0: - dependencies: - buffer-from: 1.1.2 - inherits: 2.0.4 - readable-stream: 3.6.2 - typedarray: 0.0.6 - concurrently@10.0.5: dependencies: chalk: 5.6.2 @@ -6644,7 +6628,7 @@ snapshots: dependencies: debug: 4.4.3(supports-color@10.2.2) express: 5.2.1(supports-color@10.2.2) - ip-address: 10.7.0 + ip-address: 10.7.2 transitivePeerDependencies: - supports-color @@ -6715,7 +6699,7 @@ snapshots: dependencies: fast-string-truncated-width: 3.0.3 - fast-uri@3.1.7: {} + fast-uri@3.1.8: {} fast-wrap-ansi@0.2.2: dependencies: @@ -6988,7 +6972,7 @@ snapshots: internmap@2.0.3: {} - ip-address@10.7.0: {} + ip-address@10.7.2: {} ipaddr.js@1.9.1: {} @@ -7058,7 +7042,7 @@ snapshots: saxes: 6.0.0 symbol-tree: 3.2.4 tough-cookie: 6.0.2 - undici: 8.10.0 + undici: 8.10.2 w3c-xmlserializer: 5.0.0 webidl-conversions: 8.0.1 whatwg-mimetype: 5.0.0 @@ -7320,7 +7304,7 @@ snapshots: minimatch@10.2.6: dependencies: - brace-expansion: 5.0.9 + brace-expansion: 5.0.12 minipass@7.1.3: {} @@ -7383,11 +7367,10 @@ snapshots: - '@types/node' optional: true - multer@2.3.0: + multer@2.4.0: dependencies: append-field: 1.0.0 busboy: 1.6.0 - concat-stream: 2.0.0 type-is: 1.6.18 mute-stream@3.0.0: {} @@ -7421,7 +7404,7 @@ snapshots: node-releases@2.0.53: {} - nodemailer@9.1.1: {} + nodemailer@10.0.12: {} normalize-path@3.0.0: {} @@ -8108,8 +8091,6 @@ snapshots: media-typer: 1.1.1 mime-types: 3.0.2 - typedarray@0.0.6: {} - typescript-eslint@8.70.0(eslint@10.10.0(jiti@2.7.0)(supports-color@10.2.2))(supports-color@10.2.2)(typescript@6.0.3): dependencies: '@typescript-eslint/eslint-plugin': 8.70.0(@typescript-eslint/parser@8.70.0(eslint@10.10.0(jiti@2.7.0)(supports-color@10.2.2))(supports-color@10.2.2)(typescript@6.0.3))(eslint@10.10.0(jiti@2.7.0)(supports-color@10.2.2))(supports-color@10.2.2)(typescript@6.0.3) @@ -8127,7 +8108,7 @@ snapshots: undici-types@8.9.0: {} - undici@8.10.0: {} + undici@8.10.2: {} unicorn-magic@0.4.0: {} diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index d4d792c..919c79e 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -48,9 +48,11 @@ overrides: # @prisma/dev > @prisma/streams-local and by stylelint via table) to a patched # version to fix GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf # and GHSA-jqff-g426-hqxp (SSRF / host-confusion via URI normalization, all - # patched in >=3.1.6). 3.1.7 is the newest release in the 3.x range that ajv - # declares (^3.0.1), so a 4.x override would break the declared contract. - fast-uri: 3.1.7 + # patched in >=3.1.6) and GHSA-hrr3-gc8f-f4qj (inconsistent host-case + # normalization via percent-encoded octets, patched >=3.1.8). 3.1.8 is the + # newest release in the 3.x range that ajv declares (^3.0.1), so a 4.x override + # would break the declared contract. + fast-uri: 3.1.8 # Force `qs` (pulled by express, body-parser and supertest's superagent) to a # patched version to fix GHSA-x5fp-wj9c-mxmx (array-limit bypass via # bracket-key comma parsing, patched >=6.15.4) and GHSA-4mjr-xmp4-gh2g @@ -66,6 +68,29 @@ overrides: # GHSA-2wm5-q62r-hmrv (slow rejection of oversized malformed color strings, # patched >=2.9.4). stylelint declares `^2.9.3`, so 2.10.0 stays in range. colord: 2.10.0 + # Force `undici` (pulled by jsdom, which backs the vitest browser-like test + # environment) to a patched version to fix GHSA-rfgv-xxqx-mfg5 (DoS via an + # unrequested WebSocket subprotocol), GHSA-w293-vg96-wgc3 (TLS certificate + # validation bypass via dropped connect options in BalancedPool), + # GHSA-vp8m-p9jh-q5pm (cross-origin cache poisoning via missing origin + # isolation in interceptors), GHSA-3wwx-pv8p-q78v, GHSA-pmjh-fq2x-6v4x, + # GHSA-3xpg-4rpp-hhhm, GHSA-2jfj-6hjv-fm6j, GHSA-rx4f-c7p8-82vq, + # GHSA-r53p-7pc4-xj5r, GHSA-2gqq-gqf2-x968 and GHSA-8436-99hf-9mmv (all + # patched >=8.10.2). jsdom declares `^8.9.0`, so 8.10.2 (the minimal patched + # release) stays in range. + undici: 8.10.2 + # Force `brace-expansion` (pulled by minimatch, which is used by the eslint and + # rimraf > glob toolchains) to a patched version to fix GHSA-qhr7-859c-m2p7 and + # GHSA-6j4f-fj2g-mc7p (stack exhaustion via uncontrolled recursion) and + # GHSA-q2hr-2g5m-vwhr (quadratic-time CPU DoS on the `{a},b}` rewrite), all + # patched >=5.0.12. minimatch declares `^5.0.8`, so 5.0.12 stays in range. + brace-expansion: 5.0.12 + # Force `ip-address` (pulled by express-rate-limit) to a patched version to fix + # GHSA-j6r3-76f7-8jcv (isInSubnet() compares mixed address families and can + # admit an address outside its range) and GHSA-h3mg-xc3c-68pw (unbounded parse + # diagnostic string stalls the process), both patched >=10.7.1. + # express-rate-limit declares `^10.2.0`, so 10.7.2 stays in range. + ip-address: 10.7.2 # Shared dependency versions across all packages catalog: