Skip to content

fix(deps): remediate high/moderate audit advisories (no breaking changes) - #133

Merged
EmeditWeb merged 1 commit into
mainfrom
fix/api-deps-security-safe
Sep 18, 2026
Merged

EmeditWeb merged 1 commit into
mainfrom
fix/api-deps-security-safe

Conversation

@EmeditWeb

@EmeditWeb EmeditWeb commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

What & why

Security remediation of the in-range, non-breaking slice of the API's dependency advisories, delivered ahead of the larger framework migrations so the safe fixes land now.

Fixed — npm audit 20 → 8

  • 7 high: axios, brace-expansion, browserslist, fast-uri, ip-address, multer, @nestjs/platform-express
  • 4 moderate: hono, @hono/node-server, qs, baseline-browser-mapping
  • 1 low: body-parser

Mechanism: targeted npm update of the in-range transitive advisories (patches each instance within its parent's accepted range — brace-expansion/fast-uri/js-yaml live at multiple majors), plus a multer floor bump ^2.1.1 → ^2.4.0 (advisory affects <=2.2.0) pinned with overrides: { "multer": "$multer" } so @nestjs/platform-express's nested copy dedupes to the patched 2.4.0. Deliberately not npm audit fix — that churns the @nestjs/platform-fastify plugin cluster and trips the @fastify/static v9↔v10 peer conflict.

Deferred — dedicated migration PRs (no safe in-range fix)

  • fastify v5 cluster: fastify, @fastify/static (→v10), find-my-way, @nestjs/platform-fastify, @nestjs/swagger. The root still declares fastify ^4 while @nestjs/platform-fastify@11 bundles fastify 5 — a genuine v4→v5 migration.
  • legacy stellar-sdk: stellar-sdk ^11 → @stellar/stellar-sdk (npm's only offered "fix" is a bogus downgrade to 0.2.1) plus its vulnerable toml dependency.
  • js-yaml: the CVE fix ships only in the 5.x major and was not backported to the 3.x/4.x lines the tree uses (via @nestjs/swagger, eslint, istanbul). Reachable only through developer-controlled YAML (OpenAPI generation, lint/nyc config), not user input.

Test plan

  • npm ci (strict, from the regenerated lock) — passes; lock ↔ manifest in sync
  • npm run build (nest build) — passes
  • npm test — 39 suites / 460 tests pass (incl. multer-backed upload paths and the auth/admin guards)
  • Only package.json + package-lock.json changed
  • CI green on this PR

…changes

Targeted npm update of in-range transitive advisories plus a multer floor bump, avoiding the fastify v4->v5 and legacy-stellar-sdk migrations. Clears 7 high (axios, brace-expansion, browserslist, fast-uri, ip-address, multer, @nestjs/platform-express), all 4 moderate (hono, @hono/node-server, qs, baseline-browser-mapping), and the 1 low (body-parser).

multer: bumped ^2.1.1 -> ^2.4.0 (advisory affects <=2.2.0) and pinned via overrides { multer: $multer } so @nestjs/platform-express's nested copy dedupes to the patched 2.4.0 too. Same-major, API-compatible.

Deferred to dedicated migration PRs (no safe in-range fix): the fastify v5 cluster (fastify, @fastify/static, find-my-way, @nestjs/platform-fastify, @nestjs/swagger); the legacy stellar-sdk -> @stellar/stellar-sdk migration (+ its vulnerable toml dep); and js-yaml (fix lands only in the 5.x major, not backported to the 3.x/4.x lines the tree uses; reachable only via developer-controlled YAML).

Audit: 20 -> 8 total (high 15->8, moderate 4->0, low 1->0). Verified: npm ci + nest build + jest (39 suites / 460 tests) all pass. Only package.json and package-lock.json changed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@EmeditWeb
EmeditWeb merged commit 1dd8c01 into main Sep 18, 2026
2 checks passed
@EmeditWeb
EmeditWeb deleted the fix/api-deps-security-safe branch September 29, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant