Skip to content

fix(deps): execute npm audit fix - #1917

Merged
jennifer-shehane merged 1 commit into
cypress-io:masterfrom
MikeMcC399:audit-fix
Sep 29, 2026
Merged

jennifer-shehane merged 1 commit into
cypress-io:masterfrom
MikeMcC399:audit-fix

Conversation

@MikeMcC399

@MikeMcC399 MikeMcC399 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Situation

npm audit reports multiple vulnerabilities in the root of the repo.

$ npm ci

> @cypress/github-action@0.0.0-development prepare
> husky


added 253 packages, and audited 254 packages in 3s

72 packages are looking for funding
  run `npm fund` for details

4 vulnerabilities (3 moderate, 1 high)

To address all issues, run:
  npm audit fix

Run `npm audit` for details.
mike@ubuntu-26:~/github/CYPRESS-IO/github-action$ npm audit
# npm audit report

@humanfs/node  <0.16.8
Severity: moderate
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree - https://github.com/advisories/GHSA-p498-v437-472g
fix available via `npm audit fix`
node_modules/@humanfs/node

ip-address  <=10.5.0
Severity: moderate
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts - https://github.com/advisories/GHSA-rpw4-54j3-4h4q
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass - https://github.com/advisories/GHSA-2vr4-cq9g-pvrc
fix available via `npm audit fix`
node_modules/ip-address

js-yaml  4.0.0 - 4.3.1
Severity: high
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources - https://github.com/advisories/GHSA-2883-xcg3-v3hh
fix available via `npm audit fix`
node_modules/js-yaml

undici  6.25.0 - 6.28.0 || 7.28.0 - 7.29.0
Severity: moderate
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression - https://github.com/advisories/GHSA-3wwx-pv8p-q78v
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression - https://github.com/advisories/GHSA-3wwx-pv8p-q78v
fix available via `npm audit fix`
node_modules/cheerio/node_modules/undici
node_modules/undici

4 vulnerabilities (3 moderate, 1 high)

To address all issues, run:
  npm audit fix

Change

The vulnerabilities will not be fixed by Renovate or by attempting to update direct dependencies.

Execute npm audit fix and rebuild action.


Note

Medium Risk
Updates bundled HTTP/WebSocket client code used by the action; changes are upstream security and robustness fixes rather than Cypress-specific logic.

Overview
Addresses npm audit findings by refreshing package-lock.json (notably undici 6.28.0→6.28.1 and nested 7.29.1, js-yaml, ip-address, @humanfs/*) and rebuilding the bundled dist/index.js.

The rebuilt bundle picks up upstream undici fixes: idle keep-alive reuse now uses a ref’d setImmediate instead of setTimeout(0) (GHSA-35p6-xmwp-9g52), WebSocket permessage-deflate teardown on oversize payloads to avoid unhandled errors (GHSA-3wwx-pv8p-q78v), safer subprotocol handling when the request list is null, plus retry/EventSource parser changes shipped in that release.

Reviewed by Cursor Bugbot for commit 322b91c. Bugbot is set up for automated code reviews on this repo. Configure here.

@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Sep 29, 2026
@MikeMcC399 MikeMcC399 self-assigned this Sep 29, 2026
@MikeMcC399
MikeMcC399 marked this pull request as ready for review September 29, 2026 15:07
@MikeMcC399

Copy link
Copy Markdown
Collaborator Author

Please let me know if I should continue to explicitly request reviews and whom I should tag. In the last weeks I was tagging @mschile whilst he was on vacation, because I didn't know anything about his availability.

@jennifer-shehane
jennifer-shehane merged commit 789d836 into cypress-io:master Sep 29, 2026
94 checks passed
@MikeMcC399
MikeMcC399 deleted the audit-fix branch September 29, 2026 15:23
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 7.4.5 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants