Skip to content

fix(deps): override transitive deps to remediate 13 Dependabot advisories - #1686

Merged
kalverra merged 1 commit into
mainfrom
DX-4463-security-overrides-wave3
Oct 7, 2026
Merged

kalverra merged 1 commit into
mainfrom
DX-4463-security-overrides-wave3

Conversation

@kalverra

@kalverra kalverra commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds pnpm.overrides to force vulnerable transitive dependencies to patched versions. Closes 13 Dependabot alerts in one atomic, lockfile-level change.

Package Override Advisory Issue
shell-quote 1.11.0 GHSA-pqg4-j6r4-53mv (Critical, CVSS 8.1) quote() command injection via line terminator after { comment } token
vite 7.3.7 GHSA-fx2h-pf6j-xcff, GHSA-p9ff-h696-f583, GHSA-v2wj-q39q-566r server.fs.deny bypasses; dev server WebSocket arbitrary file read
undici 6.29.0 GHSA-vxpw-j846-p89q, GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8 WebSocket fragment bypass / permessage-deflate DoS / invalid window bits crash
form-data 4.0.6 GHSA-hmw2-7cc7-3qxx (CVSS 7.5) CRLF injection via unescaped multipart field names and filenames
@graphql-tools/utils 12.0.1 GHSA-7mx3-vvmw-hjmv mergeDeep prototype pollution
@fastify/busboy 3.2.2 GHSA-x8mw-p69m-v3mx (CVSS 7.5) DoS via prototype-named multipart part header
http-cache-semantics 4.3.0 GHSA-ch52-4w7c-c8xp (CVSS 7.5) max-stale cross-user cached response disclosure
source-map-js 1.2.2 GHSA-68fv-2mgg-jv7q (CVSS 7.5) Event-loop DoS via indexed source-map section offsets
picomatch 4.0.7 (scoped picomatch@>=4.0.0) GHSA-c2c7-rcm5-vvqj (CVSS 7.5) ReDoS via extglob quantifiers

Notes:

  • picomatch override is scoped to the 4.x line so picomatch 2.x consumers (micromatch) are untouched.
  • braces (DX-5539, GHSA-vfj7-8cjw-p6xm) has no patched release (3.0.3 is latest); left as-is and ticket remains open pending upstream fix.
  • Lockfile was fully regenerated: the previous lockfile contained stale resolutions that silently ignored the vite override (peer-suffixed instances pinned at 7.3.1). Full regen also floated a few in-range minors (@actions/artifact 6.3.1, @actions/cache 5.3.0, @bufbuild/protobuf 2.16.0).
  • nx advisories (GHSA-w2vw-w76x-qr89, GHSA-w3vv-58gj-gw77, GHSA-vp3h-ghgh-jr7g) are fixed separately in fix(deps): bump nx to 22.7.9 for security advisories #1685.

Verification

  • pnpm audit — no remaining hits for any of the 13 targeted advisories
  • Lockfile contains only patched versions: shell-quote@1.11.0, vite@7.3.7, undici@6.29.0 (5.x purged), form-data@4.0.6, @graphql-tools/utils@12.0.1, @fastify/busboy@3.2.2, http-cache-semantics@4.3.0, source-map-js@1.2.2, picomatch@4.0.7
  • pnpm lint — 4 projects pass
  • pnpm build — 18 projects pass
  • pnpm test — 19 projects pass
  • Bundled action artifacts rebuilt via pnpm build:artifacts
  • Changeset added

Fixes DX-5556, DX-4463, DX-4458, DX-3679, DX-3677, DX-4480, DX-3434, DX-3433, DX-5543, DX-5542, DX-5541, DX-5546, DX-3573

…ries

Add pnpm.overrides to bump vulnerable transitive dependencies:

- shell-quote 1.11.0: GHSA-pqg4-j6r4-53mv (Critical, quote() command injection)
- vite 7.3.7: GHSA-fx2h-pf6j-xcff, GHSA-p9ff-h696-f583, GHSA-v2wj-q39q-566r
  (fs.deny bypasses, dev server WebSocket file read)
- undici 6.29.0: GHSA-vxpw-j846-p89q, GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8
  (WebSocket DoS)
- form-data 4.0.6: GHSA-hmw2-7cc7-3qxx (CRLF injection in multipart)
- @graphql-tools/utils 12.0.1: GHSA-7mx3-vvmw-hjmv (mergeDeep prototype pollution)
- @fastify/busboy 3.2.2: GHSA-x8mw-p69m-v3mx (prototype-named header DoS)
- http-cache-semantics 4.3.0: GHSA-ch52-4w7c-c8xp (cross-user cache disclosure)
- source-map-js 1.2.2: GHSA-68fv-2mgg-jv7q (event-loop DoS)
- picomatch 4.0.7 (scoped to 4.x): GHSA-c2c7-rcm5-vvqj (ReDoS)

Lockfile fully regenerated (previous lockfile held stale resolutions that
ignored the vite override).

Verified: lint (4 projects), build (18 projects), test (19 projects),
pnpm audit clean for all targeted advisories.

Fixes DX-5556, DX-4463, DX-4458, DX-3679, DX-3677, DX-4480, DX-3434,
DX-3433, DX-5543, DX-5542, DX-5541, DX-5546, DX-3573
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

👋 kalverra, thanks for creating this pull request!

To help reviewers, please consider creating future PRs as drafts first. This allows you to self-review and make any final changes before notifying the team.

Once you're ready, you can mark it as "Ready for review" to request feedback. Thanks!

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🦋 Changeset is good to go

Latest commit: c1daefd

We got this.

Not sure what this means? Click here to learn what changesets are.

@kalverra
kalverra merged commit a29039c into main Oct 7, 2026
19 checks passed
@kalverra
kalverra deleted the DX-4463-security-overrides-wave3 branch October 7, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants