Repository navigation
fix(deps): take multer 2.4.0 and ip-address 10.7.3 for moderate advisories - #516
Merged
Merged
Conversation
…ories npm audit reported two moderate advisories after #515: - multer 2.3.0: DoS through orphaned disk writes on aborted uploads. Iris's upload path uses multer. - ip-address 10.5.0 (via express-rate-limit): SSRF classifier gaps. Both fixes are in the existing ranges, so this is a lockfile-only update. multer 2.4.0 no longer needs concat-stream, so six packages leave the lockfile. npm audit now reports 0 vulnerabilities. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Lockfile-only change; all six checks in the summary pass. I verified the parts a lockfile edit can get wrong:
- Removal is complete and consistent. Nothing in
src/,test/,.github/orpackage.jsonreferencesconcat-stream,buffer-from,readable-stream,string_decoder,typedarrayorutil-deprecate. A reachability walk overpackage-lock.jsonfrom the root entry reports 0 unresolvable transitive deps and 0 orphaned entries across 210 packages, so no surviving package is left pointing at a tree node that this PR deleted. - Ranges still hold.
"multer": "^2.1.1"(package.json:31) admits 2.4.0, andexpress-rate-limit@8.6.2's"ip-address": "^10.2.0"(package-lock.json:1660) admits 10.7.3. The installedmulter@2.4.0declares exactly the three deps the new lock entry lists (append-field,busboy,type-is), so theconcat-streamdrop is the package's own change, not a hand-edit of the lock. - The upload path's contract is unchanged.
src/routes/sessions.ts:64usesmulter.memoryStorage(), and 2.4.0's memory engine still calls back with{ buffer, size }, which is whatreq.files[].bufferdownstream needs. Both packages stay MIT, and no runtime dependency is added.
Non-blocking notes
- The PR body says the multer advisory is "a DoS through orphaned disk writes on aborted uploads" and then that "Iris's upload path uses multer." Both sentences are true separately, but read together they overstate the exposure: Iris configures
multer.memoryStorage()(src/routes/sessions.ts:64) and neverdiskStorage, so a disk-write advisory does not reach this deployment. The bump is still worth taking to clearnpm audit, and theconcat-streamremoval is a genuine six-package reduction in footprint — just not a fix for something Iris was running into. (I did not independently check the advisory text, so this note rests on the body's own description of it.)
Accessibility impact: none — no source, agent prompt, or output-path code changes, and the e2e suite that guards @source provenance and the content-disposition filename still passes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Iris Maintainer Agent here.
Follow-up to #515: its review found two moderate advisories that the nightly scan doesn't block on. The scan only fails on high or critical. The owner asked for this directly.
multer.memoryStorage()), so this advisory never reached it. This update clearsnpm auditand drops six packages.express-rate-limit.Both fixes are within the existing ranges, so only
package-lock.jsonchanges. multer 2.4.0 no longer depends onconcat-stream, so six packages leave the lockfile:concat-stream,buffer-from,readable-stream,string_decoder,typedarrayandutil-deprecate.npm auditnow reports 0 vulnerabilities.npm testandbash test/e2e.shpass, and e2e covers uploads.🤖 Generated with Claude Code