Repository navigation
fix: raise eight stale pnpm override floors to clear 27 advisories - #43
Merged
Merged
Conversation
The overrides block encodes a MINIMUM version per package. Upstreams have each shipped incremental follow-up fixes since these floors were written, so half of them had gone stale and resolved to versions that are vulnerable again. pnpm audit reported 29 advisories across five packages. Floors raised (resolved version in parentheses): - axios >=1.18.0 -> >=1.20.0 (1.20.0) clears 12 advisories - undici@6 >=6.28.0 -> >=6.28.1 (6.29.0) - undici@7 >=7.29.0 -> >=7.29.1 (7.30.0) picks up ~10 CVEs - js-yaml@4 >=4.3.1 -> >=4.3.2 (4.3.2) - ip-address >=10.4.0 -> >=10.5.1 (10.7.2) - brace-expansion@1 >=1.1.16 -> >=1.1.21 (1.1.21) - brace-expansion@2 >=2.1.2 -> >=2.1.7 (2.1.7) - brace-expansion@5 >=5.0.7 -> >=5.0.12 (5.0.12) This is alert hygiene, not remediation of exploitable exposure. Every one of these is a dev/build-time transitive dependency, and files is ["dist"], so no consumer of the published package is affected by any of them. Each was checked for reachability and none is reachable on a code path this repo executes: the ip-address bug is in a classifier and its only consumer (socks) never calls one; the undici bug is in the WebSocket deflate inflater and nothing here opens a WebSocket; js-yaml runs during lint but only parses our own config, and there is no .eslintrc.y*ml. Floors resolve to the newest match, so this lands minors (6.29.0, 7.30.0, 10.7.2, 1.20.0) rather than bare patches. Each was diff-reviewed as additive/fix-only. Two behavior changes exist but are unreachable here: js-yaml 4.3.2 adds a 100-item merge-sequence cap, and ip-address 10.6.0 tightened classifier semantics. Re-locked with `pnpm install`, deliberately NOT `pnpm update`: @n8n/node-cli and n8n-workflow are declared "*", so a broad update floats the toolchain (0.34.0 -> 0.50.3, ~1982 lockfile lines). Changing an override instead re-resolves only the affected subtree. @n8n/node-cli remains 0.34.0. pnpm audit now reports only the two vitest advisories, which need a major bump and are handled separately. Build, lint and tests are green.
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pnpm auditwas reporting 29 advisories (10 high, 15 moderate, 4 low) across five packages. Thepnpm.overridesblock encodes a minimum version per package, and upstreams have each shipped incremental follow-up fixes since these floors were written — so half the floors had gone stale and were resolving to versions that are vulnerable again.This raises eight floors and clears 27 of 29. The remaining two are
vitest/@vitest/mocker, which need a major bump and are handled in a separate PR.axios>=1.18.0>=1.20.0undici@6>=6.28.0>=6.28.1undici@7>=7.29.0>=7.29.1js-yaml@4>=4.3.1>=4.3.2ip-address>=10.4.0>=10.5.1brace-expansion@1>=1.1.16>=1.1.21brace-expansion@2>=2.1.2>=2.1.7brace-expansion@5>=5.0.7>=5.0.12This is alert hygiene, not an incident
Stating this explicitly so nobody later reads these as exploited exposure. Every one is a dev/build-time transitive dependency, and
files: ["dist"]means only compiled node code is published — no consumer of@nodrel-dev/n8n-nodes-fedexis affected by any of them. Each was checked for reachability and none is reachable on a code path this repo executes:isPrivate). Its only consumer,socks, calls justAddress4/Address6/fromByteArrayand never a classifier. Effectively zero.release-itonly does HTTPS REST; nothing here opens a WebSocket. Ceiling if reachable: a crashed release script.@eslint/eslintrc, but only parses our own config, and there is no.eslintrc.y*mlin the repo. Ceiling: burned CI minutes.release-it,google-auth-library), never handling untrusted input.Notes for review
isLinkLocalis nowfe80::/10).pnpm install, deliberately notpnpm update.@n8n/node-cliandn8n-workfloware declared"*", so a broad update floats the whole toolchain — measured at 0.34.0 → 0.50.3 and ~1982 lockfile lines. Changing an override re-resolves only the affected subtree (94 lines here).@n8n/node-cliremains 0.34.0 — worth confirming in the diff.Test plan
pnpm audit→ 29 advisories reduced to 2 (vitest only, handled separately)pnpm test→ 6 files, 16 tests passedpnpm build→ exit 0pnpm lint→ exit 0 (strict vian8n.strict: true)@n8n/node-clistill pinned at 0.34.0 in the lockfileNo source files changed — the node's runtime behavior is untouched.