Skip to content

Fix 41 Dependabot security alerts: axios, DOMPurify, simple-git and dev tools - #2162

Merged
KMchaudhary merged 5 commits into
developfrom
fix/dependabot-alerts-oct6
Oct 8, 2026
Merged

KMchaudhary merged 5 commits into
developfrom
fix/dependabot-alerts-oct6

Conversation

@subodhr258

@subodhr258 subodhr258 commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

What this does

Fixes 41 of the 44 open Dependabot alerts (3 critical, 14 high, 22 moderate, 2 low), plus a new critical shell-quote advisory before Dependabot raises it here. Two of the bumps ship in the plugin's JavaScript and need a manual check: axios 1.18.0 to 1.20.0 and DOMPurify 3.4.13 to 3.4.16. Everything else is build or test tooling, and its compiled output is unchanged.

Dependabot reads main, so these alerts close when this reaches main with the next release.

Alerts addressed (41 of 44 open)

Alerts Severity Package Change
#333 #335 #339 #341 #343 #352 #353 #354 #355 #356 #357 #358 7 high, 5 moderate axios (shipped) Direct dependency and override 1.18.0 to 1.20.0
#331 #372 low dompurify (shipped, via isomorphic-dompurify) Override 3.4.13 to 3.4.16
#371 high source-map-js Override 1.2.2 (Node-side only, via jsdom; not in any bundle)
#370 critical proxy-addr Override ^2.0.8
#326 #344 high fast-uri Override ^3.1.8
#369 high compression Override ^1.8.2
#361 high http-cache-semantics Override ^4.3.0 (Dependabot lists no fix, but 4.3.0 is outside <= 4.2.0)
#327 #328 #336 moderate ip-address Override ^10.7.1 (10.3.1 to 10.7.3)
#329 moderate markdown-it Override ^14.3.1
#330 moderate moment Override 2.31.0
#348 #349 moderate brace-expansion Overrides 1.1.21 (14 copies) and 5.0.12
#368 moderate postcss-selector-parser Override ^7.1.6 for every copy, replacing the two range-scoped keys; the css-minimizer-webpack-plugin pin goes 7.1.3 to 7.1.6
#362 to #367 moderate @opentelemetry/instrumentation-* Give Lighthouse @sentry/node 10 instead of 9; the old instrumentation packages drop out
#161 #291 #292 moderate showdown Dev dependency @wordpress/blocks 15.7.0 to 15.27.0; 15.22.0 dropped showdown, which has no fixed release
#376 #377 #374 #375 2 critical, 2 high simple-git, @simple-git/argv-parser Remove the unused @wordpress/env dev dependency (and its wp-env npm script), the only thing that pulled simple-git in. The fix itself, simple-git 4, breaks wp-env
not raised yet critical shell-quote (GHSA-pqg4-j6r4-53mv, published 6 Oct) Override 1.9.0 to 1.11.0; Dependabot will flag 1.9.0 on its next scan of main

Not fixable in this PR (3 alerts)

Alerts Severity Why
#299 #319 extract-zip high No fixed release exists; still comes through puppeteer inside @wordpress/scripts
#373 sprintf-js moderate No fixed release exists

All 3 are development-only tools that never ship in the plugin.

Why removing @wordpress/env is safe

@wordpress/env spins up a throwaway Docker WordPress. Here it only backed a one-line "wp-env": "wp-env" npm script: the repo has no .wp-env.json, nothing in the README, docs or .github/workflows uses it, and PHP CI runs through setup-php. Anyone who wants it can still run npx @wordpress/env start. @wordpress/scripts lists it as an optional peer, so its lockfile entry was removed by hand and npm pruned the 83 packages only it used; nothing was added and no other version moved.

Verification

All on Node 22.14.0 / npm 10.9.2 (the repo's .nvmrc).

Check Before (develop) After
npm ci exit 0 exit 0
npm run build:prod exit 0, 318 files exit 0, 318 files, same warnings
npm run test:unit 35 suites, 496 tests pass 35 suites, 496 tests pass
npm audit, distinct advisories 52 7, none new (the leftovers are extract-zip, sprintf-js, braces, and 3 that GitHub auto-dismissed as low-impact dev-only: basic-ftp #359, body-parser #271, @babel/runtime #55)

Compiled output: 25 of 318 files change, and every one is explained by axios or DOMPurify:

  • 12 bundles carry DOMPurify 3.4.16 in place of 3.4.13. Front end and player: blocks/godam-player/index.js, js/godam-player-frontend.min.js, js/media-library.min.js, js/godam-gallery.min.js. Integrations: the 4 LifterLMS bundles and js/gf-godam-recorder-editor.min.js. Admin pages: pages/godam.min.js, pages/video-editor.min.js, pages/analytics.min.js.
  • 2 bundles carry axios 1.20.0: pages/analytics.min.js and pages/tools.min.js. The source imports axios only on the Tools and Analytics admin pages, for plain axios.get and axios.post calls.
  • 3 LICENSE.txt files change the DOMPurify version and gain one regenerator-runtime line, because DOMPurify 3.4.16's own build now embeds a small Babel helper. That helper is also why each DOMPurify bundle grows by 993 bytes.
  • 9 .asset.php files change only their 'version' hash.

A scratch build with only axios and DOMPurify bumped is byte-identical to this branch's build (318 of 318 files), so none of the other bumps changes shipped output.

DOMPurify 3.4.13 to 3.4.16 source changes: a new guard against mutation XSS through literal text, a clobber-safe removeAttributeNode, and pointer-events and vector-effect added to the allowed SVG attributes.

Also in this PR: languages/godam.pot regenerated

develop's committed POT stopped matching a fresh build after the 2.3.1 merge and the media library guided tour (#2154): 59 new strings and shifted references. That made the "Check the committed POT matches a fresh build" check fail on every PR to develop, this one included. Regenerated with npm ci, npm run build:prod and both make-pot passes (--slug=godam, so the folder name cannot leak into the header). The header matches develop's, and a re-run reproduces the file. A POT is a translators' template only; it does not change runtime behaviour.

Manual QA results (done on godam-dev.local, 7 Oct)

Same site and data, two builds: before = develop at this PR's base (d1326fc, axios 1.18.0, DOMPurify 3.4.13) and after = this PR (122c46d, axios 1.20.0, DOMPurify 3.4.16). Each run drove real Chrome through the steps below; every check gave identical results before and after, and no page threw a JavaScript error in either run.

# Check Result (before = after)
1 Tools > Retranscode Media > Fetch Media (axios GET) 200; API returns 27 items; screen reads "27/58 media file(s) require retranscoding"
2 Tools > Video Migration (axios GET x2) core and vimeo status both 200 and rendered
3 Tools > Media Usage Sync (axios GET + POST + POST) status 200; Resume Sync POST 200, screen shows running; Stop Sync POST 200, screen shows "20 of 23 posts synced (stopped)"
4 Analytics > A/B "Choose" a video (axios GET /wp/v2/media/<id>) 200 for video 476; its title and video appear on the page
5 Media library > video details (DOMPurify) Edit Video and Analytics buttons with correct links; file details shown
6 Video editor > HTML CTA layer (DOMPurify) existing HTML renders; pasting <b> + <img onerror> + <script> keeps <b>, strips onerror and <script>, nothing executes
7 Gravity Forms editor > GoDAM recorder max duration (DOMPurify) typed "120" kept; -90<img onerror=...> becomes 90<img src="x"><b>b</b>
8 Player: settings menu, seek/play/pause indicators, share modal (DOMPurify) menu Speed > 0.5x/1x/1.5x/2x; forward, play and pause indicators render; share modal has 6 links, all target=_blank rel=noopener, and the embed code

Side-effect tests (8 Oct, same two builds, each run against a database snapshot restored afterwards; identical results):

Action Result (before = after)
Tools > Retranscode one selected video (axios POST) 200; the plugin answers "Transcoding requests are not allowed in the localhost environment" by design, so no job reaches Central
Tools > Core video migration (axios POST) 200; the test post's core video block becomes a GoDAM block, and the front end shows the GoDAM player
Tools > Vimeo video migration (axios POST) 200, Central replies migration_status: success; the test embed stays as is because that video is not fetched on Central
Video editor > save an HTML CTA (DOMPurify preview) saved; editor preview and the visitor's player both show the text with onerror and <script> removed, and nothing executes
Gravity Forms > save recorder max duration 45 persisted; the form page shows "Max. duration: 45 seconds"

What the DOMPurify bump changes for GoDAM: both advisories (GHSA-p98j-92pf-mc4p, GHSA-6688-9rhm-gjv2) affect only DOMPurify's IN_PLACE mode. Running the advisory's own payload, 3.4.13 leaves a live onerror and 3.4.16 refuses the input; GoDAM never uses IN_PLACE (0 uses) and passes strings, where both versions return the same safe output. So the bump closes the alerts without changing what GoDAM renders, which is what the table shows.

Not covered: LifterLMS (not installed on godam-dev.local), the Retranscode and Video Migration start actions (they spend transcoding bandwidth; their GETs were tested), and js/godam-gallery.min.js (still built, but nothing in the plugin loads it any more; the shortcode, block and Elementor widget all use gallery v2).

Manual QA steps

Shipped changes (please check on a test site with this build):

  1. GoDAM > Tools: run each action on the page. Each completes, with no errors in the console or Network tab (axios).
  2. GoDAM > Analytics: the page loads its charts and numbers for a video with plays (axios).
  3. Player on the front end: a video with an HTML/CTA layer and a hotspot. The layer content renders as before, and a <script> or onerror= in layer HTML is still stripped (DOMPurify).
  4. Video editor: add or edit an HTML layer. The preview renders and saving works (DOMPurify).
  5. Media library and gallery: open the GoDAM media library and a page with a GoDAM gallery; thumbnails and titles render (DOMPurify).
  6. Integrations, if available on the test site: a LifterLMS lesson with a GoDAM block or embed, and a Gravity Forms form with the GoDAM recorder field in the form editor, render as before.

Development-only bumps (no runtime impact, nothing to check): source-map-js, proxy-addr, fast-uri, compression, http-cache-semantics, ip-address, markdown-it, moment, brace-expansion, postcss-selector-parser, @sentry/node, @wordpress/blocks, shell-quote, and the removal of @wordpress/env.

Bump axios to 1.20.0 and the dompurify override to 3.4.16. Both are
compiled into the plugin's admin and player bundles.

Raise or add overrides so the lockfile resolves to patched versions of
source-map-js, fast-uri, ip-address, markdown-it, moment,
brace-expansion (1.x and 5.x), compression, proxy-addr and
http-cache-semantics. These are build and test tooling and are not
shipped.

package-lock.json is regenerated with Node 22.14.0 and npm 10.9.2.
… showdown

- postcss-selector-parser ^7.1.6 for every copy, replacing the two
  range-scoped keys, and the css-minimizer-webpack-plugin pin 7.1.3 -> 7.1.6.
- lighthouse > @sentry/node ^10.0.0: moves @opentelemetry/core to 2.8.0
  and drops the old @opentelemetry/instrumentation-* packages. Lighthouse
  loads Sentry only when crash reporting is switched on.
- @wordpress/blocks 15.7.0 -> 15.27.0 (dev dependency): 15.22.0 dropped
  showdown, which has no fixed release.

Compiled output is byte-identical to the previous commit (318 of 318 files).
Copilot AI balanced review requested due to automatic review settings October 6, 2026 11:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Shipped runtime upgrades and broad transitive overrides still require the documented manual QA.

Review effort: Balanced
Findings: None

What changed in this PR

Updates runtime and development dependencies to resolve 37 Dependabot alerts.

Changes:

  • Upgrades axios and DOMPurify runtime dependencies.
  • Removes Showdown through an @wordpress/blocks upgrade.
  • Adds security overrides for vulnerable transitive tooling dependencies.
File Description
package.json Updates dependencies and security overrides.
package-lock.json Locks the resulting dependency graph.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

🔍 WordPress Plugin Check Report

⚠️ Status: Passed with warnings

📊 Report

🎯 Total Issues ❌ Errors ⚠️ Warnings
13 0 13

⚠️ Warnings (13)

📁 readme.txt (2 warnings)
📍 Line 🔖 Check 💬 Message
0 mismatched_plugin_name Plugin name "GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more" is different from the name declared in plugin header "GoDAM".
0 trademarked_term The plugin name includes a restricted term. Your chosen plugin name - "GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more" - contains the restricted term "wordpress" which cannot be used at all in your plugin name.
📁 assets/build/css/main.css (1 warning)
📍 Line 🔖 Check 💬 Message
0 EnqueuedStylesScope This style is being loaded in all contexts.
📁 assets/src/libs/analytics.min.js (5 warnings)
📍 Line 🔖 Check 💬 Message
0 EnqueuedScriptsScope This script is being loaded in all frontend contexts.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880 (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880/2026/10/08/hello-world/ (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880/sample-page/ (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880/demo-attachment-post/ (with handle analytics-library) is loaded in the footer. Consider a defer or async script loading strategy instead.
📁 assets/build/js/main.min.js (5 warnings)
📍 Line 🔖 Check 💬 Message
0 EnqueuedScriptsScope This script is being loaded in all frontend contexts.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880 (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880/2026/10/08/hello-world/ (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880/sample-page/ (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead.
0 NonBlockingScripts.NoStrategy This script on http://localhost:8880/demo-attachment-post/ (with handle rtgodam-script) is loaded in the footer. Consider a defer or async script loading strategy instead.

🤖 Generated by WordPress Plugin Check Action • Learn more about Plugin Check

Advisory published 2026-10-06; shell-quote 1.8.4 to 1.10.x is affected and
the override pinned 1.9.0. Development-only (npm-run-all, launch-editor).
Compiled output is byte-identical (318 of 318 files); unit tests pass.
It only backed the "wp-env" npm script: the repo has no .wp-env.json, no
docs or workflows use it, and PHP CI runs through setup-php. Removing it
drops simple-git and @simple-git/argv-parser (alerts #374 to #377, 2 of
them critical; the fix, simple-git 4, breaks wp-env) and the extract-zip
1.7.0 copy. @wordpress/scripts lists @wordpress/env as an optional peer,
so its lockfile entry was removed by hand and npm pruned the 83 packages
only it used. No other version changes.

Compiled output is byte-identical (318 of 318 files); 496 unit tests pass.
@subodhr258 subodhr258 changed the title Fix Dependabot security alerts: axios, DOMPurify and 35 dev-tool alerts Fix Dependabot security alerts: axios, DOMPurify, simple-git and 38 dev-tool alerts Oct 7, 2026
@subodhr258 subodhr258 changed the title Fix Dependabot security alerts: axios, DOMPurify, simple-git and 38 dev-tool alerts Fix 41 Dependabot security alerts: axios, DOMPurify, simple-git and dev tools Oct 7, 2026
@subodhr258
subodhr258 requested a review from KMchaudhary October 7, 2026 11:59
develop's committed POT no longer matched a fresh build after the 2.3.1
merge and the media library guided tour (#2154): 59 new strings and
shifted references, so the "POT matches a fresh build" check failed on
every PR to develop. Regenerated with npm ci, npm run build:prod and both
make-pot passes (--slug=godam so the worktree folder name does not leak
into the header). The header matches develop's; re-running reproduces
the file.
@KMchaudhary
KMchaudhary merged commit 2a5c69f into develop Oct 8, 2026
6 checks passed
@KMchaudhary
KMchaudhary deleted the fix/dependabot-alerts-oct6 branch October 8, 2026 09:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants