Skip to content

fix(deps): close the two grpc-js alerts from today's advisories - #172

Merged
GeiserX merged 1 commit into
mainfrom
fix/grpc-js-1-14-5
Sep 30, 2026
Merged

GeiserX merged 1 commit into
mainfrom
fix/grpc-js-1-14-5

Conversation

@GeiserX

@GeiserX GeiserX commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Two advisories published today cover @grpc/grpc-js 1.14.0 to 1.14.4, and Pumperly's lockfile has 1.14.4: GHSA-m9gg-hp2v-232j (HIGH, getAuthContext can report unauthorized certificates as authorized) and GHSA-f596-whhp-79r4 (LOW, handler error text sent to the client). This moves it to 1.14.5, the patched version.

It arrives through dockerode, which testcontainers uses for the integration tests. dockerode asks for ^1.11.1, so this is a lockfile-only change with no override, and it does not reach the runtime image.

The lockfile diff is the one package: 1.14.4 to 1.14.5.

npm audit reports 0 vulnerabilities both before and after, because npm's advisory data does not list these two yet, so it is not evidence either way here. The evidence is the resolved version against the advisories' patched version.

…HSA-f596-whhp-79r4

Lockfile only. grpc-js arrives through dockerode, which testcontainers uses
in the integration tests; dockerode's ^1.11.1 range already allows 1.14.5.
It is a dev dependency and does not reach the runtime image.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json, !**/package-lock.json

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Repository: GeiserX/Pumperly/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 06fff0dc-8642-4268-aef8-57802d4f0372

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@GeiserX
GeiserX merged commit 6de80fe into main Sep 30, 2026
10 checks passed
@GeiserX
GeiserX deleted the fix/grpc-js-1-14-5 branch September 30, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant