Skip to content

πŸ”’οΈ(deps) upgrade dependencies with known vulnerabilities - #100

Merged
juliendemoutiez merged 1 commit into
mainfrom
security/deps-audit
Sep 15, 2026
Merged

juliendemoutiez merged 1 commit into
mainfrom
security/deps-audit

Conversation

@juliendemoutiez

@juliendemoutiez juliendemoutiez commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Description of change

Upgrade dependencies with known vulnerabilities, in one PR instead of the ~30 overlapping Snyk/Renovate PRs (which conflict on the same lockfiles).

Server

  • bcrypt 5 β†’ 6: drops @mapbox/node-pre-gyp and its vulnerable tar (critical). API unchanged; existing $2b$ hashes still verify (checked against a hash produced by bcrypt 5.1.1).
  • nodemailer 6 β†’ 10: only breaking change is Node β‰₯ 20 (we run 22). We only use createTransport.
  • sharp 0.33 β†’ 0.35: libvips CVEs on image processing (attachments, avatars, backgrounds). None of the 0.34/0.35 breaking changes touch our calls (metadata, rotate, resize, toBuffer).
  • npm audit fix (in-range): express, socket.io, ws, lodash, validator, sails, sails-hook-sockets, @aws-sdk/client-s3…

Client

  • npm audit fix (in-range): axios, js-cookie, lodash, nanoid, react-router-dom 6.30.6…
  • js-yaml forced to ^4.3.2 under @mdxeditor/editor via overrides (mdxeditor 3.x pins 4.1.1). Avoids the risky mdxeditor 3 β†’ 4 major bump proposed by Snyk.

Remaining, not fixed on purpose

  • react-router (moderate): fix only in v7. Not exploitable here: no navigation to user-controlled paths, no SSR.
  • socket.io-client 2.5 / parseuri (moderate): only parses our own socket URL; v4 needs a sails.io compatibility check.
  • uuid (moderate): only affects v3/v5/v6 with a buf argument; we only use v4.
  • body-parser / qs via sails (moderate): no fix available in sails 1.x.
  • react-scripts, @cucumber/cucumber, mocha chains: build/test tooling, not shipped.

Pull-Request Checklist

  • Code is up-to-date with the main branch
  • npm run lint passes with this change
  • npm run test passes with this change
  • This pull request links relevant issues as Fixes #0000: N/A, supersedes bot PRs listed above
  • There are new or updated unit tests validating the change: N/A, dependency upgrades
  • Documentation has been updated to reflect this change (CHANGELOG)
  • The new commits follow conventions outlined in the conventional commit spec

Summary by CodeRabbit

  • Security
    • Updated server-side security-sensitive dependencies, including bcrypt, nodemailer, and sharp.
    • Added an override for js-yaml to address a client-side dependency vulnerability.
    • Documented known vulnerabilities affecting server and client dependencies in the unreleased changelog.

@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
βš™οΈ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 732124b3-c87f-4be8-9fa4-097d2232b639

πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between 7858be2 and 87e823e.

β›” Files ignored due to path filters (3)
  • client/package-lock.json is excluded by !**/package-lock.json
  • package-lock.json is excluded by !**/package-lock.json
  • server/package-lock.json is excluded by !**/package-lock.json
πŸ“’ Files selected for processing (3)
  • CHANGELOG.md
  • client/package.json
  • server/package.json

πŸ“ Walkthrough

Walkthrough

The pull request upgrades three server dependencies, adds a client override for js-yaml, and documents the dependency changes under the unreleased security section.

Changes

Dependency security updates

Layer / File(s) Summary
Dependency versions and release notes
server/package.json, client/package.json, CHANGELOG.md
bcrypt, nodemailer, and sharp version ranges are updated. The client pins js-yaml for @mdxeditor/editor. The changelog records server and client dependency updates addressing known vulnerabilities.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

✨ Finishing Touches πŸ’‘ 1
πŸ› οΈ Fix failing CI checks πŸ’‘
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❀️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant