Conversation
- Updated 17 dependencies - Fixed 47 security vulnerabilities - Updated CircleCI orb: 1.1.19 → 2.1.7 - Updated Docker base image: 22.22.0-alpine3.23 → 24.21.0-alpine3.24 - Added 9 Docker CVE suppression(s) to .grype.yaml - Added 7 GHSA ID(s) to audit-ci.jsonc allowlist - Added 6 npm vulnerability ignore(s) to .grype.yaml - Updated .nvmrc: 22.22.1 → 24.21.0 - Confidence score: 68% 🤖 Generated with ml-repo-maintenance Co-Authored-By: ml-repo-maintenance <noreply@mojaloop.org>
brace-expansion 5.0.6 -> 5.0.12, qs 6.15.3 -> 6.16.0 and sanitize-html 2.17.6 -> 2.17.7 clear the 14 npm audit findings the tool left behind, so the six GHSA ids it appended to audit-ci.jsonc and the eight matching .grype.yaml ignores are removed; the three documented pre-existing allowlist entries keep their comments. npm audit 0, grype 0 Medium+, audit-ci/dep:check/lint/test/coverage/license/standard-version --dry-run pass.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔒 Security & Dependency Updates
Summary
This PR updates dependencies and applies security patches to address vulnerabilities.
Confidence Score: 68%⚠️ (Draft PR - requires review)
📦 Dependency Updates (17 packages)
Updated all dependencies to latest versions via
npm run dep:update:View all 17 dependency updates
Dependencies
🔄 CircleCI Orb Update
Updated the Mojaloop CI/CD orb to the latest version:
Source: mojaloop/ci-config-orb-build
🐳 Docker Image Updates
Base Image Update
Updated the Node.js Alpine base image to the latest version:
Docker CVE Suppressions
Added 9 Docker-specific vulnerability suppression(s) to
.grype.yaml.These are Alpine (apk), Node.js binary, or base image npm vulnerabilities that cannot be fixed via application dependencies.
Docker Image Scan Results
🛡️ Security Patches (47 vulnerabilities fixed)
Applied targeted security fixes for remaining vulnerabilities:
Critical Severity
The fix for CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.
When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.
Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Patches:
Users should upgrade to version 4.18.0.
Workarounds:
Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.
Fixed: 4.17.23 → 4.18.0
GHSA-r5fr-rjxr-66jc | CVE-2026-4800
handlebars - Handlebars.js has JavaScript Injection via AST Type Confusion
undici - undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer's error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.
convict - Convict has Prototype Pollution via startsWith() function
High Severity
nodemailer - Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
nodemailer - Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
axios - axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an application passes attacker-controlled FormData field names, a field name with thousands of nested bracket-delimited segments causes unbounded recursion in buildPath(), exhausting the JavaScript call stack (RangeError: Maximum call stack size exceeded) and causing denial of service for that request, or process termination in applications without appropriate error handling.
protobufjs - protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
shell-quote - shell-quote: Quadratic-complexity Denial of Service in
parse()(CWE-407)@grpc/grpc-js - @grpc/grpc-js: A malformed request can cause a server crash
@hapi/content - @hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
brace-expansion - The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.
browserslist - Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
fast-uri - fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
form-data - form-data: CRLF injection in form-data via unescaped multipart field names and filenames
immutable - Immutable.js
List32-bit trie overflow → unrecoverable DoSjs-yaml - js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
linkify-it - linkify-it: Quadratic-complexity DoS via the
mailto:validator scan-loop on attacker textpath-to-regexp - path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
picomatch - Picomatch has a ReDoS vulnerability via extglob quantifiers
nanoid - nanoid: custom generators can loop indefinitely when size is zero
fast-xml-builder - fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
underscore - Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
Moderate Severity
lodash - lodash vulnerable to Prototype Pollution via array path bypass in
_.unsetand_.omitnodemailer - Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
nodemailer - Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
nodemailer - Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
nodemailer - Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
nodemailer - Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
nodemailer - Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
nodemailer - Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
ajv - ajv has ReDoS when using
$dataoptionpostcss - PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when
fromis unsetuuid - uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
@hapi/wreck - @hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
fast-xml-parser - fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
sanitize-html - ApostropheCMS: Mutation-XSS / allowedTags bypass via literal
</textarea/>solidus closebody-parser - Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error at parser construction time instead of silently disabling enforcement, while null and undefined continue to fall back to the default limit of 100kb. Workarounds: Validate the limit value before passing it to body-parser. For example, parse the value at startup and reject any configuration where the result is null or a non-finite number.
markdown-it - markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
qs - qs array-limit bypass via bracket-key comma parsing
yaml - yaml is vulnerable to Stack Overflow via deeply nested YAML collections
@humanfs/node - humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
baseline-browser-mapping - baseline-browser-mapping process termination on invalid input causes denial of service
follow-redirects - follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets
Low Severity
nodemailer - Nodemailer has SMTP command injection due to unsanitized
envelope.sizeparameterjoi - joi: Prototype pollution via a
__proto__language key in custom messages@babel/core - @babel/core: Arbitrary File Read via sourceMappingURL Comment
The following vulnerabilities could not be automatically fixed:
Action Required: Manual review recommended for unfixable vulnerabilities.
📋 Audit CI Allowlist Updates
Added 7 unfixable vulnerability ID(s) to
audit-ci.jsoncallowlist.These are transitive vulnerabilities in upstream dependencies that cannot be resolved here.
🔍 Grype npm Vulnerability Ignores
Added 6 unfixable npm vulnerability ignore(s) to
.grype.yaml.These are transitive npm vulnerabilities that are also checked by Grype CI scans.
✅ Validation Results
Baseline Validation (before changes)
Tests (after changes)
npm test🤖 Automated Changes
This PR was automatically generated by ml-repo-maintenance.
Changed Files:
package.json- Updated dependency versions and added npm overrides.circleci/config.yml- Updated orb version.nvmrc- Updated Node.js version: 22.22.1 → 24.21.0Dockerfile- Updated Node.js Alpine base image.grype.yaml- Added Docker vulnerability suppressions and npm vulnerability ignoresReview Checklist:
🤖 Generated with ml-repo-maintenance
Co-Authored-By: ml-repo-maintenance noreply@mojaloop.org
🤖 Automated maintenance (dependencies + security)
🔒 Security & Dependency Updates
Summary
This PR updates dependencies and applies security patches to address vulnerabilities.
Confidence Score: 90% ✅ (Standard PR - ready for review)
✅ Validation Results
No validation checks were run.
🤖 Automated Changes
This PR was automatically generated by ml-repo-maintenance.
Changed Files:
package.json- Updated dependency versions and added npm overridesReview Checklist:
🤖 Generated with ml-repo-maintenance
Co-Authored-By: ml-repo-maintenance noreply@mojaloop.org