Skip to content

fix: dependency security vulnerabilities (DELO-6676) - #251

Merged
ikrascloudinary merged 2 commits into
masterfrom
DELO-6676/security-fixes
Oct 7, 2026
Merged

ikrascloudinary merged 2 commits into
masterfrom
DELO-6676/security-fixes

Conversation

@ikrascloudinary

@ikrascloudinary ikrascloudinary commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Vulnerabilities resolved

  • @grpc/grpc-js: 1.14.4 → 1.14.5 (minimum required: 1.13.6 / 1.14.5, from DELO-6676 — Improper Certificate Validation, GHSA-m9gg-hp2v-232j)

@grpc/grpc-js is transitive via @opentelemetry/sdk-node → @opentelemetry/otlp-grpc-exporter-base@0.222.0, which declares ^1.14.3.

Dependencies updated

  • None — every direct dependency is already at its latest non-breaking version.

Left deliberately untouched (breaking or out of scope for a security-only PR): express 4→5, chai 4→6, chai-http 4→5, config 3→5, dotenv 16→18, got 14→16, rollbar 2→3, sinon 19→22, sinon-chai 3→4, mocha 11→12, and cloudinary 2.10.1→2.11.0 (exact-pinned with a patch-package patch).

Resolutions

  • Added @grpc/grpc-js: ^1.14.5: the parent range ^1.14.3 (via @opentelemetry/otlp-grpc-exporter-base) still admits vulnerable 1.14.3/1.14.4. Existing protobufjs, qs, proxy-addr pins kept.

Lockfile

  • Only the @grpc/grpc-js entry changes vs master (1.14.4 → 1.14.5). No other transitive bumps.

Package version

  • Unchanged; release-please handles it.

Test results

  • yarn install --frozen-lockfile clean; patch-package applied the cloudinary patch.
  • npm test — 13 passing, no hard crashes or module-resolution errors.
  • OpenTelemetry boot smoke-tested OK: node --require ./instrumentation.js.
  • Full server boot: /version → 200, Prometheus :6060/metrics → 200 with http_server_* metrics.
  • npm ls @grpc/grpc-js --all → single copy at 1.14.5.

Test plan

  • npm test passes
  • App boots cleanly: node --require ./instrumentation.js start.js (Prometheus exporter on :6060)

🤖 Generated with Claude Code

Bump transitive @grpc/grpc-js 1.14.4 -> 1.14.5 (Improper Certificate
Validation, GHSA-m9gg-hp2v-232j) via lockfile refresh.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@lukaszczerpak-cloudinary lukaszczerpak-cloudinary left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The grpc fix looks right: the lockfile now has a single @grpc/grpc-js entry at 1.14.5, which meets the advisory minimum. A few comments inline.

Comment thread package.json Outdated
{
"name": "web-speed-test-server",
"version": "1.3.15",
"version": "1.3.16",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please drop this manual bump. release-please owns the version, and .release-please-manifest.json is still at 1.3.15. After merge, /version (routes/wpt.js) and the telemetry service version (instrumentation.js) would report 1.3.16 with no matching release or tag, and release-please will later rewrite this from the manifest. This already happened after #246: it bumped to 1.3.16 by hand, and release-please's next release (cefa60f) reset it to 1.3.13, so the deployed version went backwards. The fix: title already triggers a patch release.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dropped in 6b34357. package.json is back at 1.3.15, so release-please does the bump from the fix: title.

Comment thread yarn.lock
version "1.14.4"
resolved "https://registry.yarnpkg.com/@grpc/grpc-js/-/grpc-js-1.14.4.tgz#e73ff57d97802f063999545f43ebb2b1eca65d9d"
integrity sha512-k9Dj3DV/itK9D06Y8f190Qgop7/Ui+D0njFV3LHMPwPT75DpXLQohE9Wmz0QElrJnzsjB7KPWiKJbOl7IPDArQ==
version "1.14.5"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fix exists only in the lockfile. The range ^1.14.3 still allows the vulnerable 1.14.3 and 1.14.4, so a later lockfile edit or merge-conflict resolution could quietly bring back 1.14.4 (GHSA-m9gg-hp2v-232j). Could you add a resolutions entry for @grpc/grpc-js (e.g. ^1.14.5), the same way protobufjs, qs and proxy-addr are already pinned?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added "@grpc/grpc-js": "^1.14.5" to resolutions in 6b34357. The lock entry is now "@grpc/grpc-js@^1.14.3", "@grpc/grpc-js@^1.14.5" → 1.14.5, so a re-lock can't fall back to 1.14.4.

Comment thread yarn.lock Outdated
version "22.20.3"
resolved "https://registry.yarnpkg.com/@types/node/-/node-22.20.3.tgz#f77d48b4cb336b4e6dc44850ddb6da69caade396"
integrity sha512-DZmzkmwHzXrLPAXPyKNDzlIwMMUZCVacoD25ywdy5YTKGbOx/2ld+Q38Im2zJ0vBuZP5Prd3VZutKZyXwkOS8A==
version "26.6.4"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The lockfile refresh also moved @types/node from 22.20.3 to 26.6.4 (and undici-types from 6.21 to 8.9). CI runs Node 20.16 and .mise.local.toml uses 22.13, so editor and type checks would now accept Node 26 APIs that don't exist at runtime. It's also unrelated to the security fix. Could you keep this at 22.x, or mention the jump in the PR description if it's intentional?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not intentional, reverted in 6b34357. I rebuilt yarn.lock from master and re-ran yarn install, so the only lockfile change vs master is the grpc-js entry. @types/node stays at 22.20.3 / undici-types 6.21.0, and the other incidental bumps are gone too.

- Add `@grpc/grpc-js: ^1.14.5` to resolutions so the parent range
  (^1.14.3) can't re-admit the vulnerable 1.14.3/1.14.4 (GHSA-m9gg-hp2v-232j).
- Revert package.json version to 1.3.15; release-please owns it.
- Rebuild yarn.lock from master so only the grpc-js entry changes,
  keeping @types/node at 22.20.3 and dropping unrelated transitive bumps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ikrascloudinary
ikrascloudinary merged commit 70af89e into master Oct 7, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants