fix(deps): close the two grpc-js alerts from today's advisories - #172
Conversation
…HSA-f596-whhp-79r4 Lockfile only. grpc-js arrives through dockerode, which testcontainers uses in the integration tests; dockerode's ^1.11.1 range already allows 1.14.5. It is a dev dependency and does not reach the runtime image.
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Repository: GeiserX/Pumperly/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Two advisories published today cover
@grpc/grpc-js1.14.0 to 1.14.4, and Pumperly's lockfile has 1.14.4: GHSA-m9gg-hp2v-232j (HIGH,getAuthContextcan report unauthorized certificates as authorized) and GHSA-f596-whhp-79r4 (LOW, handler error text sent to the client). This moves it to 1.14.5, the patched version.It arrives through
dockerode, whichtestcontainersuses for the integration tests.dockerodeasks for^1.11.1, so this is a lockfile-only change with no override, and it does not reach the runtime image.The lockfile diff is the one package:
1.14.4to1.14.5.npm auditreports 0 vulnerabilities both before and after, because npm's advisory data does not list these two yet, so it is not evidence either way here. The evidence is the resolved version against the advisories' patched version.