Skip to content

Conversation

@serhalp
Copy link
Member

@serhalp serhalp commented Nov 28, 2025

Summary

Before:

$ npm audit --omit=dev
glob  10.2.0 - 10.4.5
Severity: high
glob CLI: Command injection via -c/--cmd executes matches with shell:true - https://github.com/advisories/GHSA-5j98-mcp5-4vw2
fix available via `npm audit fix`
node_modules/glob

node-forge  <=1.3.1
Severity: high
node-forge has ASN.1 Unbounded Recursion - https://github.com/advisories/GHSA-554w-wpv2-vw27
node-forge is vulnerable to ASN.1 OID Integer Truncation - https://github.com/advisories/GHSA-65ch-62r8-g69g
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization - https://github.com/advisories/GHSA-5gfm-wpxj-wjgq
fix available via `npm audit fix`
node_modules/node-forge

2 high severity vulnerabilities

After:

$ npm audit --omit=dev
found 0 vulnerabilities

Before:
```
$ npm audit --omit=dev
glob  10.2.0 - 10.4.5
Severity: high
glob CLI: Command injection via -c/--cmd executes matches with shell:true - GHSA-5j98-mcp5-4vw2
fix available via `npm audit fix`
node_modules/glob

node-forge  <=1.3.1
Severity: high
node-forge has ASN.1 Unbounded Recursion - GHSA-554w-wpv2-vw27
node-forge is vulnerable to ASN.1 OID Integer Truncation - GHSA-65ch-62r8-g69g
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization - GHSA-5gfm-wpxj-wjgq
fix available via `npm audit fix`
node_modules/node-forge

2 high severity vulnerabilities
```

After:

```
$ npm audit --omit=dev
found 0 vulnerabilities
```
@serhalp serhalp requested a review from a team as a code owner November 28, 2025 19:15
@github-actions
Copy link

📊 Benchmark results

Comparing with 41c2ae8

  • Dependency count: 1,044 (no change)
  • Package size: 304 MB ⬇️ 0.00% decrease vs. 41c2ae8
  • Number of ts-expect-error directives: 378 (no change)

@serhalp serhalp enabled auto-merge (squash) November 28, 2025 19:56
@serhalp serhalp merged commit 1c41700 into main Nov 28, 2025
103 of 104 checks passed
@serhalp serhalp deleted the fix/resolve-high-sev-security-warnings branch November 28, 2025 20:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants