Skip to content

fix: update 21 vulnerable dependencies - #85

Merged
rdietrick merged 1 commit into
mainfrom
vuln-fix/2026-09-09-81
Sep 29, 2026
Merged

rdietrick merged 1 commit into
mainfrom
vuln-fix/2026-09-09-81

Conversation

@rdietrick

Copy link
Copy Markdown
Collaborator

Vulnerability Fix

This PR was generated by the Copilot SDK agent (auto).

Changes Applied

  • protobufjs: 7.2.6 → 7.5.6 [package.json, package-lock.json]
  • picomatch: 3.0.1 → 3.0.2 [package.json, package-lock.json]
  • linkify-it: 5.0.0 → 5.0.2 [package.json, package-lock.json]
  • undici: 7.25.0 → 7.29.0 [package.json, package-lock.json]
  • ws: 8.18.2 → 8.21.1 [package.json, package-lock.json]
  • fast-uri: 3.0.1 → 3.1.5 [package.json, package-lock.json]
  • axios: 1.15.2 → 1.18.0 [package.json, package-lock.json]
  • websocket-driver: 0.7.4 → 0.7.5 [package.json, package-lock.json]
  • form-data: 4.0.5 → 4.0.6 [package.json, package-lock.json]
  • sigstore: 3.1.0 → 4.1.1 [package.json, package-lock.json]
  • browserslist: 4.24.4, 4.28.2 → 4.28.7 [package.json, package-lock.json]
  • fast-xml-parser: 4.5.6, 5.5.8 → 5.7.0, 5.10.1 [package.json, package-lock.json]
  • markdown-it: 14.1.0 → 14.3.0 [package.json, package-lock.json]
  • diff: 4.0.2 → 4.0.4 [package.json, package-lock.json]
  • ajv: 6.12.6 → 6.14.0 [package.json, package-lock.json]
  • fast-xml-builder: 1.1.5 → 1.1.7, 1.3.0 [package.json, package-lock.json]
  • tar: 7.5.11, 7.5.13 → 7.5.19, 7.5.22 [package.json, package-lock.json]
  • @sigstore/core: 2.0.0 → 3.2.1 [package.json, package-lock.json]
  • @babel/core: 7.24.9, 7.26.10, 7.29.0 → 7.29.6, 7.29.7 [package.json, package-lock.json]
  • @protobufjs/utf8: 1.1.0 → 1.1.2 [package.json, package-lock.json]
  • postcss-selector-parser: 7.1.1 → 7.1.4 [package.json, package-lock.json]

Skipped

  • serialize-javascript: only copy is node_modules/@salesforce/cli/node_modules/serialize-javascript@6.0.2, shipped inside the @salesforce/cli@2.150.6 tarball (extraneous); npm overrides cannot rewrite it and @salesforce/cli is already at its latest release
  • js-yaml: override to 4.3.0 applied to all reachable copies, but node_modules/@salesforce/cli/node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml@3.15.0 ships inside the @salesforce/cli tarball (extraneous) and cannot be overridden
  • brace-expansion: reachable copies now 5.0.9, but node_modules/@salesforce/cli/node_modules/npm/node_modules/brace-expansion@5.0.7 is inBundle within @salesforce/cli's vendored npm and cannot be overridden
  • uuid: all remaining copies (@salesforce/cli/node_modules/uuid@8.0.0, .../gaxios/node_modules/uuid@9.0.1, .../istanbul-lib-processinfo/node_modules/uuid@8.3.2) ship inside the @salesforce/cli tarball (extraneous) and cannot be overridden
  • ip-address: reachable copy updated to 10.3.1, but node_modules/@salesforce/cli/node_modules/npm/node_modules/ip-address@10.2.0 is inBundle within @salesforce/cli's vendored npm and cannot be overridden

Vulnerabilities Addressed

Package Fix Version CVE/ID
serialize-javascript 7.0.5 GHSA-5c6j-r48x-rmvq
serialize-javascript 7.0.5 GHSA-qj8w-gfj5-8c6v
js-yaml 4.3.0 GHSA-5p4m-2wfm-xmqj
js-yaml 4.3.0 GHSA-52cp-r559-cp3m
js-yaml 4.3.0 GHSA-mh29-5h37-fv8m
js-yaml 4.3.0 GHSA-h67p-54hq-rp68
protobufjs 7.5.6 GHSA-xq3m-2v4x-88gg
protobufjs 7.5.6 GHSA-66ff-xgx4-vchm
protobufjs 7.5.6 GHSA-75px-5xx7-5xc7
protobufjs 7.5.6 GHSA-q6x5-8v7m-xcrf
picomatch 3.0.2 GHSA-3v7f-55p6-f55p
picomatch 3.0.2 GHSA-c2c7-rcm5-vvqj
linkify-it 5.0.2 GHSA-v245-v573-v5vm
linkify-it 5.0.2 GHSA-22p9-wv53-3rq4
undici 7.29.0 GHSA-vmh5-mc38-953g
undici 7.29.0 GHSA-pr7r-676h-xcf6
undici 7.29.0 GHSA-35p6-xmwp-9g52
undici 7.29.0 GHSA-g8m3-5g58-fq7m
undici 7.29.0 GHSA-p88m-4jfj-68fv
undici 7.29.0 GHSA-8xcm-r25x-g524
undici 7.29.0 GHSA-jr45-8vmc-qm54
undici 7.29.0 GHSA-m8rv-5g2x-5cg5
undici 7.29.0 GHSA-v3r7-h72x-cjcm
undici 7.29.0 GHSA-4cwx-7wf7-3272
ws 8.21.0 GHSA-96hv-2xvq-fx4p
fast-uri 3.1.6 GHSA-v2hh-gcrm-f6hx
fast-uri 3.1.6 GHSA-4c8g-83qw-93j6
fast-uri 3.1.6 GHSA-v39h-62p7-jpjc
fast-uri 3.1.6 GHSA-7p8r-x3mc-p8w7
fast-uri 3.1.6 GHSA-f65p-4m7j-42xc
fast-uri 3.1.6 GHSA-jqff-g426-hqxp
axios 1.18.0 GHSA-654m-c8p4-x5fp
axios 1.18.0 GHSA-p92q-9vqr-4j8v
axios 1.18.0 GHSA-j5f8-grm9-p9fc
axios 1.18.0 GHSA-pjwm-pj3p-43mv
axios 1.18.0 GHSA-35jp-ww65-95wh
axios 1.18.0 GHSA-gcfj-64vw-6mp9
axios 1.18.0 GHSA-f4gw-2p7v-4548
brace-expansion 5.0.9 GHSA-mh99-v99m-4gvg
brace-expansion 5.0.9 GHSA-rgw5-rvv9-x895
brace-expansion 5.0.9 GHSA-f886-m6hf-6m8v
brace-expansion 5.0.9 GHSA-3jxr-9vmj-r5cp
brace-expansion 5.0.9 GHSA-jxxr-4gwj-5jf2
uuid 11.1.1 GHSA-w5hq-g745-h8pq
websocket-driver 0.7.5 GHSA-xv26-6w52-cph6
form-data 4.0.6 GHSA-hmw2-7cc7-3qxx
ip-address 10.3.1 GHSA-mwp4-54f8-5fhr
sigstore 4.1.1 GHSA-52v5-jr5w-gjxr
browserslist 4.28.7 GHSA-73wf-gq98-2v4g
fast-xml-parser 5.7.0 GHSA-gh4j-gqv2-49f6
markdown-it 14.2.0 GHSA-38c4-r59v-3vqw
markdown-it 14.2.0 GHSA-6v5v-wf23-fmfq
diff 4.0.4 GHSA-73rr-hh4g-fpgx
ajv 6.14.0 GHSA-2g4f-4pwh-qvx6
fast-xml-builder 1.1.7 GHSA-5wm8-gmm8-39j9
fast-xml-builder 1.1.7 GHSA-45c6-75p6-83cc
tar 7.5.18 GHSA-vmf3-w455-68vh
tar 7.5.18 GHSA-w8wr-v893-vjvp
@sigstore/core 3.2.1 GHSA-jfc7-64v2-mr8c
@babel/core 7.29.6 GHSA-4x5r-pxfx-6jf8
@protobufjs/utf8 1.1.1 GHSA-q6x5-8v7m-xcrf
postcss-selector-parser 7.1.3 GHSA-w9m9-85wc-3x92

Generated by sec-vuln-fixer using Copilot SDK (auto)

Requested by @rdietrick

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 9, 2026 17:28
@rdietrick rdietrick added sec-vuln-fixer Created by sec-vuln-fixer security Security-related change severity:high High severity vulnerability labels Sep 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several new overrides are unscoped pins that can downgrade already-updated dependencies (per the current lockfile), so they should be range-scoped to only affect vulnerable versions.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review tier: Lite
Findings: 1 Medium severity

New issues introduced by this change (1)
Severity Finding
Medium severity package.json — The ws override currently pins 8.21.0, but package-lock.json already resolves ws@&ZeroWidthSpace;8.21.1…
What changed in this PR

This PR aims to mitigate reported npm dependency vulnerabilities by adding/updating overrides in package.json so transitive dependencies resolve to patched versions.

Changes:

  • Expanded package.json overrides to pin/force patched versions for multiple vulnerable transitive dependencies.
  • Added targeted override entries for packages called out by vulnerability tooling (e.g., undici, ws, tar, @babel/core).
File Description
package.json Adds many npm overrides entries intended to force vulnerable transitive dependencies to patched versions.
Suppressed comments (5)

package.json:57

  • The fast-xml-builder override pins 1.1.7, but package-lock.json already contains fast-xml-builder@1.3.0 under @salesforce/cli. A global pin would force a downgrade; use a range-scoped override so only vulnerable versions are replaced.
    "fast-xml-builder": "1.1.7",

package.json:58

  • The tar override pins 7.5.18, but package-lock.json already resolves newer versions (tar@7.5.22 and an in-bundle tar@7.5.19). Pinning can unintentionally downgrade; scope the override to only apply to versions below the fixed version.
    "tar": "7.5.18",

package.json:60

  • The @babel/core override pins 7.29.6, but package-lock.json already includes @babel/core@7.29.7 (under @salesforce/cli). A global pin would downgrade that copy; prefer a range-scoped override to only bump vulnerable versions.
    "@babel/core": "7.29.6",

package.json:62

  • Several overrides here pin versions lower than what is already present in package-lock.json (e.g., @protobufjs/utf8 is 1.1.2 and postcss-selector-parser is 7.1.4 in the lockfile). Unscoped pins can cause regressions by downgrading; scope these overrides to only affect vulnerable ranges.
    "@protobufjs/utf8": "1.1.1",
    "postcss-selector-parser": "7.1.3"

package.json:54

  • The markdown-it override pins 14.2.0, but package-lock.json already resolves markdown-it@14.3.0 under @salesforce/cli. A global pin can force a downgrade; scope the override to only apply to versions below the fixed version.
    "markdown-it": "14.2.0",

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
"picomatch@3": "3.0.2",
"linkify-it": "5.0.2",
"undici@7": "7.29.0",
"ws": "8.21.0",
@rdietrick
rdietrick merged commit 0a62e80 into main Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

sec-vuln-fixer Created by sec-vuln-fixer security Security-related change severity:high High severity vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants