fix(deps): patch HIGH/CRITICAL advisories #19

Merged
siax-bot merged 2 commits from fix/cve-lockfile-2026-09-30 into main 2026-10-01 15:52:11 +00:00
Owner

Summary

Lockfile-level fix for the HIGH/CRITICAL advisories that the estate CI (trivy) reports on main @ 23f99f9. Only vulnerable packages were touched; every bump stays inside its current major.

Scanner: trivy fs --scanners vuln --severity HIGH,CRITICAL (trivy 0.73.0, vuln DB updated 2026-09-30 01:15 UTC, used offline with --skip-db-update), run in default mode and with --include-dev-deps. Cross-checked with npm audit --audit-level=high.

Note: the advisories named in the estate alert for other repos (fast-uri CVE-2026-84292, @xhmikosr/decompress CVE-2026-101894) are not in this repo's lockfile. brace-expansion CVE-2026-102276 is present, as a dev-only transitive.

Findings before -> after

Package Before After Advisory Kind
next 16.3.1 16.3.3 CVE-2026-75604 / GHSA-2xp9-vwfh-vxw4 (CRITICAL) direct, exact pin, patch
js-yaml 4.3.1 4.3.2 CVE-2026-84375 (HIGH) direct, exact pin, patch
nodemailer 9.0.5 9.1.1 GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj (HIGH) direct, exact pin, minor
sharp 0.35.3 0.35.5 GHSA-rgj7-g3m4-5g8c (HIGH) direct + override, in range (^0.35.3), lockfile only
undici 6.28.0 6.29.0 CVE-2026-19534 (HIGH) transitive via @ai-sdk/provider-utils (^6.28.0), lockfile only
brace-expansion 1.1.18 / 2.1.4 1.1.21 / 2.1.7 CVE-2026-102276, CVE-2026-102278 (HIGH) dev-only transitive, lockfile only
minimatch 9.0.5 (typescript-estree) 9.0.9 CVE-2026-26996, CVE-2026-27903, CVE-2026-27904 (HIGH) dev-only transitive, lockfile only

Trivy (default mode): 7 findings -> 1. Trivy (--include-dev-deps): 14 findings -> 1.

Companion lockfile movement that comes with the above and nothing else: sharp platform binaries and libvips (@img/sharp-* 0.35.5, @img/sharp-libvips-* 1.3.4), @emnapi/runtime 1.11.3, @next/env and @next/swc-* 16.3.3, and the nested @eslint/eslintrc/node_modules/js-yaml copy deduped into the top-level js-yaml.

Files

  • package.json: exact pins for next, js-yaml, nodemailer (they were exact-pinned, so an in-range update could not reach the fix).
  • package-lock.json: as above.
  • scripts/checks/no-new-antipatterns.mjs: PINNED_DEPS nodemailer 9.0.5 -> 9.1.1 with the reason updated. Without this, the pinned-dep guard in check:guards fails hard. The guard text asks for nodemailer bumps to be deliberate, reviewed PRs, so this is the explicit reviewed bump. Please review it on its own: nodemailer sits on the outbound-mail path (extensions/general/email/lib/smtp-service.ts). I diffed the published 9.0.5 and 9.1.1 tarballs; changes are security/bug fixes plus an opt-in maxRecipients option, no dependency changes.

Remaining finding (not fixed here, needs a decision)

  • nodemailer GHSA-v53p-9fqp-m79j (HIGH, addressparser quadratic backtracking DoS), plus GHSA-6vj9-mwq6-2f5v, GHSA-8vvx-rff5-p5rq, GHSA-g57g-f23g-4646 in npm audit. All are fixed only in nodemailer 10.x (trivy: 10.0.6, npm audit: 10.0.13). That is a major bump of a direct dependency, so it is out of scope for this lockfile PR. Suggested follow-up: a separate reviewed PR moving nodemailer to 10.x (mailparser already carries a nested nodemailer 10.0.10, which is not flagged) together with the PINNED_DEPS update.
  • npm audit also lists @babel/core <=7.29.0 (GHSA-4x5r-pxfx-6jf8), severity low, so below the HIGH/CRITICAL gate. Not touched.

Checks run locally

Node v26.10.0 / npm 11.19.1, on the branch head:

  • npm ci (frozen install): pass, lockfile unchanged afterwards.
  • npm run check:types: pass (533 errors, equal to the baseline of 533, no new).
  • npm run check:lint: pass (0, baseline 0).
  • npm run check:guards: pass (pinned-dep: 0); it failed before the PINNED_DEPS update.
  • npm run skills:check, taxonomy:check, apiskill:check, validate:packs, validate:registry: pass.
  • vitest run --project unit (full): started but stopped at my 10 minute cap, because the machine was at load average 30 to 54. About 22.3k tests had passed by then with no failures printed; it did not complete, so treat the full run as not verified locally (CI shards it 4 ways).
  • Targeted vitest runs over the code that uses the bumped packages: extensions/general/email/__tests__/smtp-service.test.ts (nodemailer), lib/packs (js-yaml), lib/invoices/__tests__/pdf-render-helpers.test.ts, lib/api/__tests__/content-disposition.test.ts, and the documents inline route test: 7 files, 95 tests, all pass.
  • trivy re-scan: 1 remaining finding (nodemailer, above), in both default and --include-dev-deps mode.
  • npm audit --audit-level=high: 8 findings on main (1 low, 6 high, 1 critical) -> 2 (1 low, 1 high: nodemailer, above).

Not run: npm run build and the sharded test:pg / tool-pg projects (need Postgres). The Sonar job on main is red on a missing SONAR_TOKEN, unrelated and untouched.

🤖 Generated with Claude Code

## Summary Lockfile-level fix for the HIGH/CRITICAL advisories that the estate CI (trivy) reports on `main` @ 23f99f9. Only vulnerable packages were touched; every bump stays inside its current major. Scanner: `trivy fs --scanners vuln --severity HIGH,CRITICAL` (trivy 0.73.0, vuln DB updated 2026-09-30 01:15 UTC, used offline with `--skip-db-update`), run in default mode and with `--include-dev-deps`. Cross-checked with `npm audit --audit-level=high`. Note: the advisories named in the estate alert for other repos (fast-uri CVE-2026-84292, @xhmikosr/decompress CVE-2026-101894) are not in this repo's lockfile. brace-expansion CVE-2026-102276 is present, as a dev-only transitive. ## Findings before -> after | Package | Before | After | Advisory | Kind | |---|---|---|---|---| | next | 16.3.1 | 16.3.3 | CVE-2026-75604 / GHSA-2xp9-vwfh-vxw4 (CRITICAL) | direct, exact pin, patch | | js-yaml | 4.3.1 | 4.3.2 | CVE-2026-84375 (HIGH) | direct, exact pin, patch | | nodemailer | 9.0.5 | 9.1.1 | GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj (HIGH) | direct, exact pin, minor | | sharp | 0.35.3 | 0.35.5 | GHSA-rgj7-g3m4-5g8c (HIGH) | direct + override, in range (`^0.35.3`), lockfile only | | undici | 6.28.0 | 6.29.0 | CVE-2026-19534 (HIGH) | transitive via @ai-sdk/provider-utils (`^6.28.0`), lockfile only | | brace-expansion | 1.1.18 / 2.1.4 | 1.1.21 / 2.1.7 | CVE-2026-102276, CVE-2026-102278 (HIGH) | dev-only transitive, lockfile only | | minimatch | 9.0.5 (typescript-estree) | 9.0.9 | CVE-2026-26996, CVE-2026-27903, CVE-2026-27904 (HIGH) | dev-only transitive, lockfile only | Trivy (default mode): 7 findings -> 1. Trivy (`--include-dev-deps`): 14 findings -> 1. Companion lockfile movement that comes with the above and nothing else: sharp platform binaries and libvips (`@img/sharp-*` 0.35.5, `@img/sharp-libvips-*` 1.3.4), `@emnapi/runtime` 1.11.3, `@next/env` and `@next/swc-*` 16.3.3, and the nested `@eslint/eslintrc/node_modules/js-yaml` copy deduped into the top-level js-yaml. ## Files - `package.json`: exact pins for next, js-yaml, nodemailer (they were exact-pinned, so an in-range update could not reach the fix). - `package-lock.json`: as above. - `scripts/checks/no-new-antipatterns.mjs`: `PINNED_DEPS` nodemailer 9.0.5 -> 9.1.1 with the reason updated. Without this, the `pinned-dep` guard in `check:guards` fails hard. The guard text asks for nodemailer bumps to be deliberate, reviewed PRs, so this is the explicit reviewed bump. Please review it on its own: nodemailer sits on the outbound-mail path (`extensions/general/email/lib/smtp-service.ts`). I diffed the published 9.0.5 and 9.1.1 tarballs; changes are security/bug fixes plus an opt-in `maxRecipients` option, no dependency changes. ## Remaining finding (not fixed here, needs a decision) - **nodemailer GHSA-v53p-9fqp-m79j (HIGH, addressparser quadratic backtracking DoS)**, plus GHSA-6vj9-mwq6-2f5v, GHSA-8vvx-rff5-p5rq, GHSA-g57g-f23g-4646 in `npm audit`. All are fixed only in nodemailer 10.x (trivy: 10.0.6, npm audit: 10.0.13). That is a major bump of a direct dependency, so it is out of scope for this lockfile PR. Suggested follow-up: a separate reviewed PR moving nodemailer to 10.x (mailparser already carries a nested nodemailer 10.0.10, which is not flagged) together with the `PINNED_DEPS` update. - `npm audit` also lists `@babel/core <=7.29.0` (GHSA-4x5r-pxfx-6jf8), severity low, so below the HIGH/CRITICAL gate. Not touched. ## Checks run locally Node v26.10.0 / npm 11.19.1, on the branch head: - `npm ci` (frozen install): pass, lockfile unchanged afterwards. - `npm run check:types`: pass (533 errors, equal to the baseline of 533, no new). - `npm run check:lint`: pass (0, baseline 0). - `npm run check:guards`: pass (`pinned-dep: 0`); it failed before the `PINNED_DEPS` update. - `npm run skills:check`, `taxonomy:check`, `apiskill:check`, `validate:packs`, `validate:registry`: pass. - `vitest run --project unit` (full): started but stopped at my 10 minute cap, because the machine was at load average 30 to 54. About 22.3k tests had passed by then with no failures printed; it did not complete, so treat the full run as not verified locally (CI shards it 4 ways). - Targeted vitest runs over the code that uses the bumped packages: `extensions/general/email/__tests__/smtp-service.test.ts` (nodemailer), `lib/packs` (js-yaml), `lib/invoices/__tests__/pdf-render-helpers.test.ts`, `lib/api/__tests__/content-disposition.test.ts`, and the documents inline route test: 7 files, 95 tests, all pass. - trivy re-scan: 1 remaining finding (nodemailer, above), in both default and `--include-dev-deps` mode. - `npm audit --audit-level=high`: 8 findings on main (1 low, 6 high, 1 critical) -> 2 (1 low, 1 high: nodemailer, above). Not run: `npm run build` and the sharded `test:pg` / `tool-pg` projects (need Postgres). The Sonar job on main is red on a missing `SONAR_TOKEN`, unrelated and untouched. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
admin added 1 commit 2026-09-30 15:17:58 +00:00
fix(deps): patch HIGH/CRITICAL advisories
masterplan-lock / check (push) Successful in 6s
masterplan-lock / check (pull_request) Successful in 33s
0250b4bab2
Lockfile-level update of the packages trivy flags on main, all within
their current major:

- next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL)
- js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375)
- nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj)
- sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c)
- undici 6.28.0 -> 6.29.0 (CVE-2026-19534)
- brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev)
- minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev)

next, js-yaml and nodemailer were exact-pinned, so their pins move too.
PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without
it the pinned-dep guard fails.

Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major
bump of a direct dependency, left for a separate reviewed change).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
admin added 1 commit 2026-09-30 16:50:57 +00:00
fix(deps): next 16.3.3 -> 16.3.6 (GHSA-vcvr-r3jv-pc5j, CRITICAL)
masterplan-lock / check (pull_request) Successful in 9s
masterplan-lock / check (push) Successful in 35s
ddc4cce3eb
Remote code execution in next/og ImageResponse, fixed in 16.3.6.
Same minor line; the exact pin in package.json moves too and the
lockfile follows (next, @next/env, @next/swc-* platform binaries,
sharp optional range ^0.35.4).

Not fixed here (need a direct-dependency major bump or have no fix):
- nodemailer 9.1.1: GHSA-prgh-xp8r-p3m5 / GHSA-v53p-9fqp-m79j fixed only in 10.0.5/10.0.6 (major)
- xlsx 0.20.3: GHSA-4r6h-8v6p-xvw6 / GHSA-5pgg-2g8v-p4x9 have no published fix

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Author
Owner

OSV-svep (api.osv.dev) mot PR-grenen: before/after

Before (head 0250b4b): CRITICAL 1, HIGH 4
After (head ddc4cce): CRITICAL 0, HIGH 4

Fixat i ddc4cce (endast package.json + package-lock.json):

  • next 16.3.3 -> 16.3.6 (GHSA-vcvr-r3jv-pc5j, CRITICAL, RCE i next/og ImageResponse). Samma minor-linje, exakt pin flyttad. Lockfilen drog med @next/env, @next/swc-* och sharp-range ^0.35.4. 16.3.6 publicerades 2026-09-22 (> 7 dygn).

Kvarstår (ej fixbart inom reglerna):

  • nodemailer 9.1.1 (direkt dependency): GHSA-prgh-xp8r-p3m5 (fixed 10.0.5) och GHSA-v53p-9fqp-m79j (fixed 10.0.6), båda kräver major-bump till 10.x. Hela 9.x-serien är påverkad av v53p, så att gå tillbaka till 9.0.x ger ingen vinst.
  • xlsx 0.20.3 (direkt dependency, SheetJS CDN): GHSA-4r6h-8v6p-xvw6 och GHSA-5pgg-2g8v-p4x9, ingen publicerad fix.

Verifierat på ddc4cce:

  • npm ci OK (frozen lockfile)
  • npm run check:guards OK
  • npm run check:types OK (533 fel, baseline 533)
  • npm run check:lint OK (0 fel, baseline 0)
  • npm test (vitest unit): 22336 passed, 3 failed med "timed out in 5000ms" under maskinlast ~30+; samma 3 filer kördes om isolerat: 13/13 passed
  • npm run build (next 16.3.6): "Compiled successfully" + TypeScript-steget klart, men "Collecting page data" hann inte klart inom tidsboxen (avbröts efter 560 s) — build är alltså INTE fullt verifierad

Ingen CI-workflow, test, lint-regel eller gate ändrad.

🤖 Generated with Claude Code

**OSV-svep (api.osv.dev) mot PR-grenen: before/after** Before (head 0250b4b): CRITICAL 1, HIGH 4 After (head ddc4cce): CRITICAL 0, HIGH 4 Fixat i ddc4cce (endast `package.json` + `package-lock.json`): - next 16.3.3 -> 16.3.6 (GHSA-vcvr-r3jv-pc5j, CRITICAL, RCE i next/og ImageResponse). Samma minor-linje, exakt pin flyttad. Lockfilen drog med @next/env, @next/swc-* och sharp-range ^0.35.4. 16.3.6 publicerades 2026-09-22 (> 7 dygn). Kvarstår (ej fixbart inom reglerna): - nodemailer 9.1.1 (direkt dependency): GHSA-prgh-xp8r-p3m5 (fixed 10.0.5) och GHSA-v53p-9fqp-m79j (fixed 10.0.6), båda kräver major-bump till 10.x. Hela 9.x-serien är påverkad av v53p, så att gå tillbaka till 9.0.x ger ingen vinst. - xlsx 0.20.3 (direkt dependency, SheetJS CDN): GHSA-4r6h-8v6p-xvw6 och GHSA-5pgg-2g8v-p4x9, ingen publicerad fix. Verifierat på ddc4cce: - `npm ci` OK (frozen lockfile) - `npm run check:guards` OK - `npm run check:types` OK (533 fel, baseline 533) - `npm run check:lint` OK (0 fel, baseline 0) - `npm test` (vitest unit): 22336 passed, 3 failed med "timed out in 5000ms" under maskinlast ~30+; samma 3 filer kördes om isolerat: 13/13 passed - `npm run build` (next 16.3.6): "Compiled successfully" + TypeScript-steget klart, men "Collecting page data" hann inte klart inom tidsboxen (avbröts efter 560 s) — build är alltså INTE fullt verifierad Ingen CI-workflow, test, lint-regel eller gate ändrad. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
siax-bot approved these changes 2026-10-01 15:52:07 +00:00
siax-bot left a comment
Collaborator

Approved via siax-bot (Simon decision: merge all)

Approved via siax-bot (Simon decision: merge all)
siax-bot merged commit 49e939f1df into main 2026-10-01 15:52:11 +00:00
siax-bot deleted branch fix/cve-lockfile-2026-09-30 2026-10-01 15:52:11 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: admin/accounted#19