Repository navigation
fix: dependency security vulnerabilities (DELO-6676) - #251
Conversation
Bump transitive @grpc/grpc-js 1.14.4 -> 1.14.5 (Improper Certificate Validation, GHSA-m9gg-hp2v-232j) via lockfile refresh. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lukaszczerpak-cloudinary
left a comment
There was a problem hiding this comment.
The grpc fix looks right: the lockfile now has a single @grpc/grpc-js entry at 1.14.5, which meets the advisory minimum. A few comments inline.
| { | ||
| "name": "web-speed-test-server", | ||
| "version": "1.3.15", | ||
| "version": "1.3.16", |
There was a problem hiding this comment.
Please drop this manual bump. release-please owns the version, and .release-please-manifest.json is still at 1.3.15. After merge, /version (routes/wpt.js) and the telemetry service version (instrumentation.js) would report 1.3.16 with no matching release or tag, and release-please will later rewrite this from the manifest. This already happened after #246: it bumped to 1.3.16 by hand, and release-please's next release (cefa60f) reset it to 1.3.13, so the deployed version went backwards. The fix: title already triggers a patch release.
There was a problem hiding this comment.
Dropped in 6b34357. package.json is back at 1.3.15, so release-please does the bump from the fix: title.
| version "1.14.4" | ||
| resolved "https://registry.yarnpkg.com/@grpc/grpc-js/-/grpc-js-1.14.4.tgz#e73ff57d97802f063999545f43ebb2b1eca65d9d" | ||
| integrity sha512-k9Dj3DV/itK9D06Y8f190Qgop7/Ui+D0njFV3LHMPwPT75DpXLQohE9Wmz0QElrJnzsjB7KPWiKJbOl7IPDArQ== | ||
| version "1.14.5" |
There was a problem hiding this comment.
This fix exists only in the lockfile. The range ^1.14.3 still allows the vulnerable 1.14.3 and 1.14.4, so a later lockfile edit or merge-conflict resolution could quietly bring back 1.14.4 (GHSA-m9gg-hp2v-232j). Could you add a resolutions entry for @grpc/grpc-js (e.g. ^1.14.5), the same way protobufjs, qs and proxy-addr are already pinned?
There was a problem hiding this comment.
Added "@grpc/grpc-js": "^1.14.5" to resolutions in 6b34357. The lock entry is now "@grpc/grpc-js@^1.14.3", "@grpc/grpc-js@^1.14.5" → 1.14.5, so a re-lock can't fall back to 1.14.4.
| version "22.20.3" | ||
| resolved "https://registry.yarnpkg.com/@types/node/-/node-22.20.3.tgz#f77d48b4cb336b4e6dc44850ddb6da69caade396" | ||
| integrity sha512-DZmzkmwHzXrLPAXPyKNDzlIwMMUZCVacoD25ywdy5YTKGbOx/2ld+Q38Im2zJ0vBuZP5Prd3VZutKZyXwkOS8A== | ||
| version "26.6.4" |
There was a problem hiding this comment.
The lockfile refresh also moved @types/node from 22.20.3 to 26.6.4 (and undici-types from 6.21 to 8.9). CI runs Node 20.16 and .mise.local.toml uses 22.13, so editor and type checks would now accept Node 26 APIs that don't exist at runtime. It's also unrelated to the security fix. Could you keep this at 22.x, or mention the jump in the PR description if it's intentional?
There was a problem hiding this comment.
Not intentional, reverted in 6b34357. I rebuilt yarn.lock from master and re-ran yarn install, so the only lockfile change vs master is the grpc-js entry. @types/node stays at 22.20.3 / undici-types 6.21.0, and the other incidental bumps are gone too.
- Add `@grpc/grpc-js: ^1.14.5` to resolutions so the parent range (^1.14.3) can't re-admit the vulnerable 1.14.3/1.14.4 (GHSA-m9gg-hp2v-232j). - Revert package.json version to 1.3.15; release-please owns it. - Rebuild yarn.lock from master so only the grpc-js entry changes, keeping @types/node at 22.20.3 and dropping unrelated transitive bumps. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
Vulnerabilities resolved
@grpc/grpc-jsis transitive via@opentelemetry/sdk-node→@opentelemetry/otlp-grpc-exporter-base@0.222.0, which declares^1.14.3.Dependencies updated
Left deliberately untouched (breaking or out of scope for a security-only PR):
express4→5,chai4→6,chai-http4→5,config3→5,dotenv16→18,got14→16,rollbar2→3,sinon19→22,sinon-chai3→4,mocha11→12, andcloudinary2.10.1→2.11.0 (exact-pinned with apatch-packagepatch).Resolutions
@grpc/grpc-js: ^1.14.5: the parent range^1.14.3(via@opentelemetry/otlp-grpc-exporter-base) still admits vulnerable 1.14.3/1.14.4. Existingprotobufjs,qs,proxy-addrpins kept.Lockfile
@grpc/grpc-jsentry changes vs master (1.14.4 → 1.14.5). No other transitive bumps.Package version
Test results
yarn install --frozen-lockfileclean;patch-packageapplied the cloudinary patch.npm test— 13 passing, no hard crashes or module-resolution errors.node --require ./instrumentation.js./version→ 200, Prometheus:6060/metrics→ 200 withhttp_server_*metrics.npm ls @grpc/grpc-js --all→ single copy at 1.14.5.Test plan
npm testpassesnode --require ./instrumentation.js start.js(Prometheus exporter on :6060)🤖 Generated with Claude Code