Skip to content

fix: raise eight stale pnpm override floors to clear 27 advisories - #43

Merged
noctisreus merged 1 commit into
mainfrom
fix/raise-stale-override-floors
Sep 30, 2026
Merged

noctisreus merged 1 commit into
mainfrom
fix/raise-stale-override-floors

Conversation

@noctisreus

Copy link
Copy Markdown
Collaborator

Summary

pnpm audit was reporting 29 advisories (10 high, 15 moderate, 4 low) across five packages. The pnpm.overrides block encodes a minimum version per package, and upstreams have each shipped incremental follow-up fixes since these floors were written — so half the floors had gone stale and were resolving to versions that are vulnerable again.

This raises eight floors and clears 27 of 29. The remaining two are vitest/@vitest/mocker, which need a major bump and are handled in a separate PR.

Override From To Resolves to
axios >=1.18.0 >=1.20.0 1.20.0 — clears 12 advisories
undici@6 >=6.28.0 >=6.28.1 6.29.0
undici@7 >=7.29.0 >=7.29.1 7.30.0 — picks up ~10 CVEs
js-yaml@4 >=4.3.1 >=4.3.2 4.3.2
ip-address >=10.4.0 >=10.5.1 10.7.2
brace-expansion@1 >=1.1.16 >=1.1.21 1.1.21
brace-expansion@2 >=2.1.2 >=2.1.7 2.1.7
brace-expansion@5 >=5.0.7 >=5.0.12 5.0.12

This is alert hygiene, not an incident

Stating this explicitly so nobody later reads these as exploited exposure. Every one is a dev/build-time transitive dependency, and files: ["dist"] means only compiled node code is published — no consumer of @nodrel-dev/n8n-nodes-fedex is affected by any of them. Each was checked for reachability and none is reachable on a code path this repo executes:

  • ip-address — the bug is in a classifier (isPrivate). Its only consumer, socks, calls just Address4/Address6/fromByteArray and never a classifier. Effectively zero.
  • undici — the bug is in the WebSocket permessage-deflate inflater. release-it only does HTTPS REST; nothing here opens a WebSocket. Ceiling if reachable: a crashed release script.
  • js-yaml — does execute on every lint/build via @eslint/eslintrc, but only parses our own config, and there is no .eslintrc.y*ml in the repo. Ceiling: burned CI minutes.
  • brace-expansion — glob-expansion DoS; patterns come from our config, never attacker input.
  • axios — dev tooling only (release-it, google-auth-library), never handling untrusted input.

Notes for review

  • Floors resolve to the newest match, so this lands minors (6.29.0, 7.30.0, 10.7.2, 1.20.0) rather than bare patches. Each was diff-reviewed as additive/fix-only.
  • Two real behavior changes exist, both unreachable here: js-yaml 4.3.2 adds a 100-item merge-sequence cap, and ip-address 10.6.0 tightened classifier semantics (isLinkLocal is now fe80::/10).
  • Re-locked with pnpm install, deliberately not pnpm update. @n8n/node-cli and n8n-workflow are declared "*", so a broad update floats the whole toolchain — measured at 0.34.0 → 0.50.3 and ~1982 lockfile lines. Changing an override re-resolves only the affected subtree (94 lines here). @n8n/node-cli remains 0.34.0 — worth confirming in the diff.

Test plan

  • pnpm audit → 29 advisories reduced to 2 (vitest only, handled separately)
  • pnpm test → 6 files, 16 tests passed
  • pnpm build → exit 0
  • pnpm lint → exit 0 (strict via n8n.strict: true)
  • @n8n/node-cli still pinned at 0.34.0 in the lockfile
  • CI green on this PR

No source files changed — the node's runtime behavior is untouched.

The overrides block encodes a MINIMUM version per package. Upstreams have
each shipped incremental follow-up fixes since these floors were written, so
half of them had gone stale and resolved to versions that are vulnerable
again. pnpm audit reported 29 advisories across five packages.

Floors raised (resolved version in parentheses):

- axios            >=1.18.0 -> >=1.20.0   (1.20.0)  clears 12 advisories
- undici@6         >=6.28.0 -> >=6.28.1   (6.29.0)
- undici@7         >=7.29.0 -> >=7.29.1   (7.30.0)  picks up ~10 CVEs
- js-yaml@4        >=4.3.1  -> >=4.3.2    (4.3.2)
- ip-address       >=10.4.0 -> >=10.5.1   (10.7.2)
- brace-expansion@1 >=1.1.16 -> >=1.1.21  (1.1.21)
- brace-expansion@2 >=2.1.2  -> >=2.1.7   (2.1.7)
- brace-expansion@5 >=5.0.7  -> >=5.0.12  (5.0.12)

This is alert hygiene, not remediation of exploitable exposure. Every one of
these is a dev/build-time transitive dependency, and files is ["dist"], so no
consumer of the published package is affected by any of them. Each was checked
for reachability and none is reachable on a code path this repo executes: the
ip-address bug is in a classifier and its only consumer (socks) never calls
one; the undici bug is in the WebSocket deflate inflater and nothing here
opens a WebSocket; js-yaml runs during lint but only parses our own config,
and there is no .eslintrc.y*ml.

Floors resolve to the newest match, so this lands minors (6.29.0, 7.30.0,
10.7.2, 1.20.0) rather than bare patches. Each was diff-reviewed as
additive/fix-only. Two behavior changes exist but are unreachable here:
js-yaml 4.3.2 adds a 100-item merge-sequence cap, and ip-address 10.6.0
tightened classifier semantics.

Re-locked with `pnpm install`, deliberately NOT `pnpm update`: @n8n/node-cli
and n8n-workflow are declared "*", so a broad update floats the toolchain
(0.34.0 -> 0.50.3, ~1982 lockfile lines). Changing an override instead
re-resolves only the affected subtree. @n8n/node-cli remains 0.34.0.

pnpm audit now reports only the two vitest advisories, which need a major
bump and are handled separately. Build, lint and tests are green.
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@noctisreus
noctisreus merged commit 7b54b0d into main Sep 30, 2026
7 checks passed
@noctisreus
noctisreus deleted the fix/raise-stale-override-floors branch September 30, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant