Repository navigation
Fix 41 Dependabot security alerts: axios, DOMPurify, simple-git and dev tools - #2162
Merged
Merged
Conversation
Bump axios to 1.20.0 and the dompurify override to 3.4.16. Both are compiled into the plugin's admin and player bundles. Raise or add overrides so the lockfile resolves to patched versions of source-map-js, fast-uri, ip-address, markdown-it, moment, brace-expansion (1.x and 5.x), compression, proxy-addr and http-cache-semantics. These are build and test tooling and are not shipped. package-lock.json is regenerated with Node 22.14.0 and npm 10.9.2.
… showdown - postcss-selector-parser ^7.1.6 for every copy, replacing the two range-scoped keys, and the css-minimizer-webpack-plugin pin 7.1.3 -> 7.1.6. - lighthouse > @sentry/node ^10.0.0: moves @opentelemetry/core to 2.8.0 and drops the old @opentelemetry/instrumentation-* packages. Lighthouse loads Sentry only when crash reporting is switched on. - @wordpress/blocks 15.7.0 -> 15.27.0 (dev dependency): 15.22.0 dropped showdown, which has no fixed release. Compiled output is byte-identical to the previous commit (318 of 318 files).
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Shipped runtime upgrades and broad transitive overrides still require the documented manual QA.
Review effort: Balanced
Findings: None
What changed in this PR
Updates runtime and development dependencies to resolve 37 Dependabot alerts.
Changes:
- Upgrades axios and DOMPurify runtime dependencies.
- Removes Showdown through an
@wordpress/blocksupgrade. - Adds security overrides for vulnerable transitive tooling dependencies.
| File | Description |
|---|---|
package.json |
Updates dependencies and security overrides. |
package-lock.json |
Locks the resulting dependency graph. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🔍 WordPress Plugin Check Report
📊 Report
|
| 📍 Line | 🔖 Check | 💬 Message |
|---|---|---|
0 |
mismatched_plugin_name | Plugin name "GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more" is different from the name declared in plugin header "GoDAM". |
0 |
trademarked_term | The plugin name includes a restricted term. Your chosen plugin name - "GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more" - contains the restricted term "wordpress" which cannot be used at all in your plugin name. |
📁 assets/build/css/main.css (1 warning)
| 📍 Line | 🔖 Check | 💬 Message |
|---|---|---|
0 |
EnqueuedStylesScope | This style is being loaded in all contexts. |
📁 assets/src/libs/analytics.min.js (5 warnings)
| 📍 Line | 🔖 Check | 💬 Message |
|---|---|---|
0 |
EnqueuedScriptsScope | This script is being loaded in all frontend contexts. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880 (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880/2026/10/08/hello-world/ (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880/sample-page/ (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880/demo-attachment-post/ (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead. |
📁 assets/build/js/main.min.js (5 warnings)
| 📍 Line | 🔖 Check | 💬 Message |
|---|---|---|
0 |
EnqueuedScriptsScope | This script is being loaded in all frontend contexts. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880 (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880/2026/10/08/hello-world/ (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880/sample-page/ (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead. |
0 |
NonBlockingScripts.NoStrategy | This script on http://localhost:8880/demo-attachment-post/ (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead. |
🤖 Generated by WordPress Plugin Check Action • Learn more about Plugin Check
Advisory published 2026-10-06; shell-quote 1.8.4 to 1.10.x is affected and the override pinned 1.9.0. Development-only (npm-run-all, launch-editor). Compiled output is byte-identical (318 of 318 files); unit tests pass.
It only backed the "wp-env" npm script: the repo has no .wp-env.json, no docs or workflows use it, and PHP CI runs through setup-php. Removing it drops simple-git and @simple-git/argv-parser (alerts #374 to #377, 2 of them critical; the fix, simple-git 4, breaks wp-env) and the extract-zip 1.7.0 copy. @wordpress/scripts lists @wordpress/env as an optional peer, so its lockfile entry was removed by hand and npm pruned the 83 packages only it used. No other version changes. Compiled output is byte-identical (318 of 318 files); 496 unit tests pass.
develop's committed POT no longer matched a fresh build after the 2.3.1 merge and the media library guided tour (#2154): 59 new strings and shifted references, so the "POT matches a fresh build" check failed on every PR to develop. Regenerated with npm ci, npm run build:prod and both make-pot passes (--slug=godam so the worktree folder name does not leak into the header). The header matches develop's; re-running reproduces the file.
KMchaudhary
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Fixes 41 of the 44 open Dependabot alerts (3 critical, 14 high, 22 moderate, 2 low), plus a new critical shell-quote advisory before Dependabot raises it here. Two of the bumps ship in the plugin's JavaScript and need a manual check: axios 1.18.0 to 1.20.0 and DOMPurify 3.4.13 to 3.4.16. Everything else is build or test tooling, and its compiled output is unchanged.
Dependabot reads
main, so these alerts close when this reachesmainwith the next release.Alerts addressed (41 of 44 open)
1.18.0to1.20.03.4.13to3.4.161.2.2(Node-side only, via jsdom; not in any bundle)^2.0.8^3.1.8^1.8.2^4.3.0(Dependabot lists no fix, but 4.3.0 is outside<= 4.2.0)^10.7.1(10.3.1 to 10.7.3)^14.3.12.31.01.1.21(14 copies) and5.0.12^7.1.6for every copy, replacing the two range-scoped keys; thecss-minimizer-webpack-pluginpin goes 7.1.3 to 7.1.6@sentry/node10 instead of 9; the old instrumentation packages drop out@wordpress/blocks15.7.0 to 15.27.0; 15.22.0 dropped showdown, which has no fixed release@wordpress/envdev dependency (and itswp-envnpm script), the only thing that pulled simple-git in. The fix itself, simple-git 4, breaks wp-env1.9.0to1.11.0; Dependabot will flag 1.9.0 on its next scan ofmainNot fixable in this PR (3 alerts)
@wordpress/scriptsAll 3 are development-only tools that never ship in the plugin.
Why removing
@wordpress/envis safe@wordpress/envspins up a throwaway Docker WordPress. Here it only backed a one-line"wp-env": "wp-env"npm script: the repo has no.wp-env.json, nothing in the README, docs or.github/workflowsuses it, and PHP CI runs throughsetup-php. Anyone who wants it can still runnpx @wordpress/env start.@wordpress/scriptslists it as an optional peer, so its lockfile entry was removed by hand and npm pruned the 83 packages only it used; nothing was added and no other version moved.Verification
All on Node 22.14.0 / npm 10.9.2 (the repo's
.nvmrc).npm cinpm run build:prodnpm run test:unitnpm audit, distinct advisoriesCompiled output: 25 of 318 files change, and every one is explained by axios or DOMPurify:
blocks/godam-player/index.js,js/godam-player-frontend.min.js,js/media-library.min.js,js/godam-gallery.min.js. Integrations: the 4 LifterLMS bundles andjs/gf-godam-recorder-editor.min.js. Admin pages:pages/godam.min.js,pages/video-editor.min.js,pages/analytics.min.js.pages/analytics.min.jsandpages/tools.min.js. The source imports axios only on the Tools and Analytics admin pages, for plainaxios.getandaxios.postcalls.LICENSE.txtfiles change the DOMPurify version and gain oneregenerator-runtimeline, because DOMPurify 3.4.16's own build now embeds a small Babel helper. That helper is also why each DOMPurify bundle grows by 993 bytes..asset.phpfiles change only their'version'hash.A scratch build with only axios and DOMPurify bumped is byte-identical to this branch's build (318 of 318 files), so none of the other bumps changes shipped output.
DOMPurify 3.4.13 to 3.4.16 source changes: a new guard against mutation XSS through literal text, a clobber-safe
removeAttributeNode, andpointer-eventsandvector-effectadded to the allowed SVG attributes.Also in this PR:
languages/godam.potregenerateddevelop's committed POT stopped matching a fresh build after the 2.3.1 merge and the media library guided tour (#2154): 59 new strings and shifted references. That made the "Check the committed POT matches a fresh build" check fail on every PR todevelop, this one included. Regenerated withnpm ci,npm run build:prodand bothmake-potpasses (--slug=godam, so the folder name cannot leak into the header). The header matchesdevelop's, and a re-run reproduces the file. A POT is a translators' template only; it does not change runtime behaviour.Manual QA results (done on godam-dev.local, 7 Oct)
Same site and data, two builds: before =
developat this PR's base (d1326fc, axios 1.18.0, DOMPurify 3.4.13) and after = this PR (122c46d, axios 1.20.0, DOMPurify 3.4.16). Each run drove real Chrome through the steps below; every check gave identical results before and after, and no page threw a JavaScript error in either run./wp/v2/media/<id>)<b>+<img onerror>+<script>keeps<b>, stripsonerrorand<script>, nothing executes-90<img onerror=...>becomes90<img src="x"><b>b</b>target=_blank rel=noopener, and the embed codeSide-effect tests (8 Oct, same two builds, each run against a database snapshot restored afterwards; identical results):
migration_status: success; the test embed stays as is because that video is not fetched on Centralonerrorand<script>removed, and nothing executesWhat the DOMPurify bump changes for GoDAM: both advisories (GHSA-p98j-92pf-mc4p, GHSA-6688-9rhm-gjv2) affect only DOMPurify's
IN_PLACEmode. Running the advisory's own payload, 3.4.13 leaves a liveonerrorand 3.4.16 refuses the input; GoDAM never usesIN_PLACE(0 uses) and passes strings, where both versions return the same safe output. So the bump closes the alerts without changing what GoDAM renders, which is what the table shows.Not covered: LifterLMS (not installed on godam-dev.local), the Retranscode and Video Migration start actions (they spend transcoding bandwidth; their GETs were tested), and
js/godam-gallery.min.js(still built, but nothing in the plugin loads it any more; the shortcode, block and Elementor widget all use gallery v2).Manual QA steps
Shipped changes (please check on a test site with this build):
<script>oronerror=in layer HTML is still stripped (DOMPurify).Development-only bumps (no runtime impact, nothing to check): source-map-js, proxy-addr, fast-uri, compression, http-cache-semantics, ip-address, markdown-it, moment, brace-expansion, postcss-selector-parser, @sentry/node, @wordpress/blocks, shell-quote, and the removal of @wordpress/env.