2.5.0 Dependency Updates #268

Closed
opened 2025-09-20 16:18:18 +01:00 by Vylpes · 1 comment
Owner
  • Execute dependency update skill
  • Fix pipeline
- [x] Execute dependency update skill - [x] Fix pipeline
Vylpes added this to the 2.5.0 milestone 2025-09-20 16:18:18 +01:00
Vylpes self-assigned this 2026-09-10 17:56:45 +01:00
Member

Dependency audit overview — release 2.5.0

Date: 2026-09-10
Branch: release/2.5.0
Package manager: Yarn Classic (v1.22.22)

Summary

Metric Before After
Unique advisories 54 0
Critical 1 0
High many (paths aggregated) 0
Moderate many 0
Low few 0
yarn audit total findings 304 (path-counted) 0
Tests / build / lint — all passing

All known vulnerabilities were cleared with yarn resolutions plus within-range upgrades of direct dependencies. Non-vulnerable packages were then brought up to the latest versions allowed by existing semver ranges. Major-version bumps (e.g. ESLint 10, TypeScript 7, Commander 15) were left for separate follow-up.

Phase 1 — Vulnerability fixes

Approach

  1. Ran yarn audit and deduplicated advisories by ID (54 unique).
  2. Upgraded direct parents that pulled in vulnerable transitive packages (@yao-pkg/pkg, jest, eslint, np, etc.).
  3. Expanded resolutions to pin patched transitive versions where parents had not yet absorbed fixes.

Critical / high issues addressed

Package Issue (examples) Resolution pin / fix
tar Multiple path traversal / DoS / hardlink issues (incl. CVE-2026-59873 critical) 7.5.22
tar-fs Symlink validation bypass 3.1.3
minimatch ReDoS (multiple CVEs across lines) 9.0.9
brace-expansion DoS / OOM (CVE-2026-13149, -14257, -69152, …) 2.1.4 (was ^2.0.2)
picomatch ReDoS / method injection 4.0.7
glob CLI command injection (CVE-2025-64756) 13.0.6
tmp Path traversal 0.2.7
js-yaml Prototype pollution / quadratic DoS 4.3.2
lodash Code injection / prototype pollution 4.18.1
browserslist OOM / prototype write 4.28.9
ajv ReDoS with $data 6.15.0
@babel/core Arbitrary file read via sourceMappingURL 7.29.7
@humanfs/node Symlink follow on copy 0.16.8
@eslint/plugin-kit ReDoS in ConfigCommentParser 0.4.1
flatted Unbounded recursion / prototype pollution 3.4.4

Resolutions block (after)

"resolutions": {
  "@babel/core": "7.29.7",
  "@eslint/plugin-kit": "0.4.1",
  "@humanfs/node": "0.16.8",
  "ajv": "6.15.0",
  "brace-expansion": "2.1.4",
  "browserslist": "4.28.9",
  "flatted": "3.4.4",
  "glob": "13.0.6",
  "js-yaml": "4.3.2",
  "lodash": "4.18.1",
  "minimatch": "9.0.9",
  "picomatch": "4.0.7",
  "tar": "7.5.22",
  "tar-fs": "3.1.3",
  "tmp": "0.2.7"
}

Yarn may warn that some of these pins are outside a dependent’s declared range; that is intentional for security. Runtime verification: yarn test, yarn build, and yarn lint all succeed after the pins.

Phase 2 — Non-vulnerable package updates

Direct dependencies were updated to the latest within their existing major / caret ranges (Current = Wanted in yarn outdated).

Runtime dependencies

Package From To
commander ^14.0.0 ^14.0.3
htmlparser2 ^10.0.0 ^10.1.0
glob-parent ^6.0.0 unchanged (already current)
got-cjs ^12.5.4 unchanged (already current)
linqts ^2.0.0 unchanged (already current in range)

Dev dependencies

Package From To
@eslint/eslintrc ^3.3.1 ^3.3.7
@eslint/js ^9.30.1 ^9.39.5
@jest/globals ^30.0.4 ^30.5.1
@types/node ^24.0.12 ^24.13.4
@typescript-eslint/eslint-plugin ^8.36.0 ^8.70.0
@typescript-eslint/parser ^8.36.0 ^8.70.0
@yao-pkg/pkg ^6.5.1 ^6.22.0
eslint ^9.30.1 ^9.39.5
jest ^30.0.4 ^30.5.1
jest-mock-extended ^4.0.0 ^4.0.1
np ^10.2.0 ^10.3.0
ts-jest ^29.4.0 ^29.4.12
typescript ^5.8.3 ^5.9.3
typescript-eslint ^8.36.0 ^8.70.0

Deferred major upgrades

These have newer majors available and were not applied in this pass. Tracked under milestone 2.6.0:

Package Current major Latest major Ticket
commander 14 15 #287
htmlparser2 10 12 #288
linqts 2 3 #289
eslint / @eslint/js 9 10 #290
np 10 12 #291
typescript 5 7 #292

Verification

Commands run after the changes:

yarn audit   # 0 vulnerabilities
yarn test    # 4 suites / 26 tests passed
yarn build   # tsc OK
yarn lint    # eslint OK

Files changed

  • package.json — dependency range bumps + expanded resolutions
  • yarn.lock — regenerated lockfile
  • docs/dependency-audit-2.5.0.md — this overview
# Dependency audit overview — release 2.5.0 **Date:** 2026-09-10 **Branch:** `release/2.5.0` **Package manager:** Yarn Classic (v1.22.22) ## Summary | Metric | Before | After | |--------|--------|-------| | Unique advisories | 54 | 0 | | Critical | 1 | 0 | | High | many (paths aggregated) | 0 | | Moderate | many | 0 | | Low | few | 0 | | `yarn audit` total findings | 304 (path-counted) | 0 | | Tests / build / lint | — | all passing | All known vulnerabilities were cleared with yarn `resolutions` plus within-range upgrades of direct dependencies. Non-vulnerable packages were then brought up to the latest versions allowed by existing semver ranges. Major-version bumps (e.g. ESLint 10, TypeScript 7, Commander 15) were left for separate follow-up. ## Phase 1 — Vulnerability fixes ### Approach 1. Ran `yarn audit` and deduplicated advisories by ID (54 unique). 2. Upgraded direct parents that pulled in vulnerable transitive packages (`@yao-pkg/pkg`, `jest`, `eslint`, `np`, etc.). 3. Expanded `resolutions` to pin patched transitive versions where parents had not yet absorbed fixes. ### Critical / high issues addressed | Package | Issue (examples) | Resolution pin / fix | |---------|------------------|----------------------| | `tar` | Multiple path traversal / DoS / hardlink issues (incl. CVE-2026-59873 critical) | `7.5.22` | | `tar-fs` | Symlink validation bypass | `3.1.3` | | `minimatch` | ReDoS (multiple CVEs across lines) | `9.0.9` | | `brace-expansion` | DoS / OOM (CVE-2026-13149, -14257, -69152, …) | `2.1.4` (was `^2.0.2`) | | `picomatch` | ReDoS / method injection | `4.0.7` | | `glob` | CLI command injection (CVE-2025-64756) | `13.0.6` | | `tmp` | Path traversal | `0.2.7` | | `js-yaml` | Prototype pollution / quadratic DoS | `4.3.2` | | `lodash` | Code injection / prototype pollution | `4.18.1` | | `browserslist` | OOM / prototype write | `4.28.9` | | `ajv` | ReDoS with `$data` | `6.15.0` | | `@babel/core` | Arbitrary file read via sourceMappingURL | `7.29.7` | | `@humanfs/node` | Symlink follow on copy | `0.16.8` | | `@eslint/plugin-kit` | ReDoS in ConfigCommentParser | `0.4.1` | | `flatted` | Unbounded recursion / prototype pollution | `3.4.4` | ### Resolutions block (after) ```json "resolutions": { "@babel/core": "7.29.7", "@eslint/plugin-kit": "0.4.1", "@humanfs/node": "0.16.8", "ajv": "6.15.0", "brace-expansion": "2.1.4", "browserslist": "4.28.9", "flatted": "3.4.4", "glob": "13.0.6", "js-yaml": "4.3.2", "lodash": "4.18.1", "minimatch": "9.0.9", "picomatch": "4.0.7", "tar": "7.5.22", "tar-fs": "3.1.3", "tmp": "0.2.7" } ``` Yarn may warn that some of these pins are outside a dependent’s declared range; that is intentional for security. Runtime verification: `yarn test`, `yarn build`, and `yarn lint` all succeed after the pins. ## Phase 2 — Non-vulnerable package updates Direct dependencies were updated to the latest **within** their existing major / caret ranges (`Current` = `Wanted` in `yarn outdated`). ### Runtime dependencies | Package | From | To | |---------|------|----| | `commander` | `^14.0.0` | `^14.0.3` | | `htmlparser2` | `^10.0.0` | `^10.1.0` | | `glob-parent` | `^6.0.0` | unchanged (already current) | | `got-cjs` | `^12.5.4` | unchanged (already current) | | `linqts` | `^2.0.0` | unchanged (already current in range) | ### Dev dependencies | Package | From | To | |---------|------|----| | `@eslint/eslintrc` | `^3.3.1` | `^3.3.7` | | `@eslint/js` | `^9.30.1` | `^9.39.5` | | `@jest/globals` | `^30.0.4` | `^30.5.1` | | `@types/node` | `^24.0.12` | `^24.13.4` | | `@typescript-eslint/eslint-plugin` | `^8.36.0` | `^8.70.0` | | `@typescript-eslint/parser` | `^8.36.0` | `^8.70.0` | | `@yao-pkg/pkg` | `^6.5.1` | `^6.22.0` | | `eslint` | `^9.30.1` | `^9.39.5` | | `jest` | `^30.0.4` | `^30.5.1` | | `jest-mock-extended` | `^4.0.0` | `^4.0.1` | | `np` | `^10.2.0` | `^10.3.0` | | `ts-jest` | `^29.4.0` | `^29.4.12` | | `typescript` | `^5.8.3` | `^5.9.3` | | `typescript-eslint` | `^8.36.0` | `^8.70.0` | ### Deferred major upgrades These have newer majors available and were **not** applied in this pass. Tracked under milestone **2.6.0**: | Package | Current major | Latest major | Ticket | |---------|---------------|--------------|--------| | `commander` | 14 | 15 | [#287](https://git.vylpes.xyz/RabbitLabs/random-bunny/issues/287) | | `htmlparser2` | 10 | 12 | [#288](https://git.vylpes.xyz/RabbitLabs/random-bunny/issues/288) | | `linqts` | 2 | 3 | [#289](https://git.vylpes.xyz/RabbitLabs/random-bunny/issues/289) | | `eslint` / `@eslint/js` | 9 | 10 | [#290](https://git.vylpes.xyz/RabbitLabs/random-bunny/issues/290) | | `np` | 10 | 12 | [#291](https://git.vylpes.xyz/RabbitLabs/random-bunny/issues/291) | | `typescript` | 5 | 7 | [#292](https://git.vylpes.xyz/RabbitLabs/random-bunny/issues/292) | ## Verification Commands run after the changes: ```bash yarn audit # 0 vulnerabilities yarn test # 4 suites / 26 tests passed yarn build # tsc OK yarn lint # eslint OK ``` ## Files changed - `package.json` — dependency range bumps + expanded `resolutions` - `yarn.lock` — regenerated lockfile - `docs/dependency-audit-2.5.0.md` — this overview
Vylpes stopped working 2026-09-10 18:17:56 +01:00
21 minutes 10 seconds
Vylpes stopped working 2026-09-19 19:02:55 +01:00
4 minutes 9 seconds
Commenting is not possible because the repository is archived.
No milestone
No project
No assignees
2 participants
Total time spent: 25 minutes 19 seconds
Vylpes
25 minutes 19 seconds
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
RabbitLabs/random-bunny#268
No description provided.