Skip to content

fix(security): bump fast-uri, ip-address, express-rate-limit and undici - #1051

Merged
adubovikov merged 1 commit into
homer11from
fix-dependabot-fast-uri-ip-address
Sep 30, 2026
Merged

adubovikov merged 1 commit into
homer11from
fix-dependabot-fast-uri-ip-address

Conversation

@adubovikov

Copy link
Copy Markdown
Member

Closes the two open Dependabot alerts on src/ui/package-lock.json:

Both versions were held back by overrides in src/ui/package.json, so a plain lockfile refresh could not move them. The same pass fixes what npm audit reports beyond the open alerts: express-rate-limit 8.5.1 → 8.5.2, undici → 7.29.1. brace-expansion resolves to 5.0.12 and 1.1.21, both past the advisory, without an override; pinning it would force the 5.x line on minimatch 3.x, which depends on 1.x.

Test plan

  • npm audit reports 0 vulnerabilities
  • npm ci && npm run build succeeds
  • npm test: 252 passed, 1 failed (ProfilePanel.test.tsx missing DetailsTabProvider), same failure on homer11 without this change

npm overrides pinned fast-uri at 3.1.6 and ip-address at 10.3.1, which
Dependabot flags (CVE-2026-84394, CVE-2026-101910). Raise them to the
patched releases and bump express-rate-limit and undici the same way;
brace-expansion resolves to patched versions without an override.
npm audit reports no vulnerabilities.
@adubovikov
adubovikov merged commit b3e953c into homer11 Sep 30, 2026
14 checks passed
@adubovikov adubovikov mentioned this pull request Oct 4, 2026
1 task done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant