Repository navigation
fix(deps): take proxy-addr 2.0.8 for CVE-2026-90711 (#514) - #515
Merged
Merged
Conversation
The nightly image scan found CVE-2026-90711 (critical) in proxy-addr 2.0.7, which express 4.22.2 pulls in. 2.0.8 fixes it and is in express's range, so this is a lockfile-only update. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Lock-only change, verified end to end. Nothing blocking.
What I checked:
package-lock.json:2233— the registry confirmsproxy-addr@2.0.8exists and itsdist.integritymatches the committed hash exactly (sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==), so this is not a fabricated or stale entry.- 2.0.8 is inside the range express declares (
package-lock.json:1654,"proxy-addr": "~2.0.7", express resolved at 4.22.2), so nooverridesentry is needed and the existingoverrides: { "qs": "^6.16.0" }inpackage.json:35stays as-is. - No new packages. 2.0.8's dependencies are identical to 2.0.7's (
forwarded@0.2.0,ipaddr.js@1.9.1), both already pinned at those versions in the lock. The addedfundingblock matches the published package metadata. - No hand-edit drift: regenerating the lock from this
package.jsonin a scratch directory withnpm install --package-lock-onlyyields a file byte-identical to the committed one. - All six checks in the summary pass, and
npm auditno longer reportsproxy-addr.
Non-blocking notes
npm auditstill reports two moderate advisories —ip-address <=10.7.0(four GHSAs, reachable from jsdom) andmulter 2.2.0 - 2.3.0(orphaned disk writes on aborted uploads, and Iris's upload path is multer). Both predate this PR and are correctly out of scope here. Flagging only because the PR body says "the scan check on this PR rebuilds the image and should come back clean": there is no audit or scan step in.github/workflows/ci.yml, so whatever that scan is, it is external to this repo and I cannot confirm its threshold. If it fails on moderate, it will not come back clean after this merge, and the multer one deserves its own issue.
Accessibility impact: none — a transitive HTTP-layer dependency patch that cannot reach HTML generation or the axe-core lint.
bbertucc
added a commit
that referenced
this pull request
Oct 6, 2026
…ories (#516) npm audit reported two moderate advisories after #515: - multer 2.3.0: DoS through orphaned disk writes on aborted uploads. Iris's upload path uses multer. - ip-address 10.5.0 (via express-rate-limit): SSRF classifier gaps. Both fixes are in the existing ranges, so this is a lockfile-only update. multer 2.4.0 no longer needs concat-stream, so six packages leave the lockfile. npm audit now reports 0 vulnerabilities. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Iris Maintainer Agent here.
Closes #514. The owner asked for this fix directly, so the issue has no
maintainerlabel.The nightly scan found one critical advisory, CVE-2026-90711, in
proxy-addr2.0.7. Express 4.22.2 pulls that package in. Version 2.0.8 fixes it and is within Express's range, so onlypackage-lock.jsonchanges:proxy-addrversion, resolved URL and integrity hash.fundingfield from the package's metadata.There are no new packages.
npm testandbash test/e2e.shpass. The scan check on this PR rebuilds the image and should come back clean.🤖 Generated with Claude Code