Skip to content

fix(deps): take proxy-addr 2.0.8 for CVE-2026-90711 (#514) - #515

Merged
bbertucc merged 1 commit into
mainfrom
fix/proxy-addr-514
Oct 6, 2026
Merged

bbertucc merged 1 commit into
mainfrom
fix/proxy-addr-514

Conversation

@bbertucc

@bbertucc bbertucc commented Oct 6, 2026

Copy link
Copy Markdown
Member

Iris Maintainer Agent here.

Closes #514. The owner asked for this fix directly, so the issue has no maintainer label.

The nightly scan found one critical advisory, CVE-2026-90711, in proxy-addr 2.0.7. Express 4.22.2 pulls that package in. Version 2.0.8 fixes it and is within Express's range, so only package-lock.json changes:

  • The proxy-addr version, resolved URL and integrity hash.
  • A funding field from the package's metadata.

There are no new packages. npm test and bash test/e2e.sh pass. The scan check on this PR rebuilds the image and should come back clean.

🤖 Generated with Claude Code

The nightly image scan found CVE-2026-90711 (critical) in proxy-addr
2.0.7, which express 4.22.2 pulls in. 2.0.8 fixes it and is in express's
range, so this is a lockfile-only update.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lock-only change, verified end to end. Nothing blocking.

What I checked:

  • package-lock.json:2233 — the registry confirms proxy-addr@2.0.8 exists and its dist.integrity matches the committed hash exactly (sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==), so this is not a fabricated or stale entry.
  • 2.0.8 is inside the range express declares (package-lock.json:1654, "proxy-addr": "~2.0.7", express resolved at 4.22.2), so no overrides entry is needed and the existing overrides: { "qs": "^6.16.0" } in package.json:35 stays as-is.
  • No new packages. 2.0.8's dependencies are identical to 2.0.7's (forwarded@0.2.0, ipaddr.js@1.9.1), both already pinned at those versions in the lock. The added funding block matches the published package metadata.
  • No hand-edit drift: regenerating the lock from this package.json in a scratch directory with npm install --package-lock-only yields a file byte-identical to the committed one.
  • All six checks in the summary pass, and npm audit no longer reports proxy-addr.

Non-blocking notes

  • npm audit still reports two moderate advisories — ip-address <=10.7.0 (four GHSAs, reachable from jsdom) and multer 2.2.0 - 2.3.0 (orphaned disk writes on aborted uploads, and Iris's upload path is multer). Both predate this PR and are correctly out of scope here. Flagging only because the PR body says "the scan check on this PR rebuilds the image and should come back clean": there is no audit or scan step in .github/workflows/ci.yml, so whatever that scan is, it is external to this repo and I cannot confirm its threshold. If it fails on moderate, it will not come back clean after this merge, and the multer one deserves its own issue.

Accessibility impact: none — a transitive HTTP-layer dependency patch that cannot reach HTML generation or the axe-core lint.

@bbertucc
bbertucc merged commit 06565fe into main Oct 6, 2026
7 checks passed
@bbertucc
bbertucc deleted the fix/proxy-addr-514 branch October 6, 2026 14:06
bbertucc added a commit that referenced this pull request Oct 6, 2026
…ories (#516)

npm audit reported two moderate advisories after #515:
- multer 2.3.0: DoS through orphaned disk writes on aborted uploads.
  Iris's upload path uses multer.
- ip-address 10.5.0 (via express-rate-limit): SSRF classifier gaps.

Both fixes are in the existing ranges, so this is a lockfile-only update.
multer 2.4.0 no longer needs concat-stream, so six packages leave the
lockfile. npm audit now reports 0 vulnerabilities.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Nightly security scan failed on main

1 participant