fix(deps): bump fast-uri, undici and brace-expansion past their advisories - #3958
Merged
Merged
Conversation
fast-uri 4.1.3 is affected by GHSA-58mr-gqgx-xq4g (host confusion via an unclosed authority bracket) and GHSA-qw65-cvwx-89v3 (authority injection via an unvalidated port in serialize). Both are fixed in 4.1.4. fast-uri comes in through ajv, which still declares `fast-uri: ^3.0.1` as of its latest release 8.20.0, so the override is the only lever. Cap the range below v5 so the next major cannot be picked up unnoticed, the way v4 was. Drop the minimumReleaseAgeExclude entry for fast-uri@4.1.2 while here: the floor has moved past it and 4.1.4 was published on 2026-09-02, well beyond the 24 hour hold.
undici 7.28.0 is affected by GHSA-w293-vg96-wgc3 (TLS certificate validation bypass through connect options dropped in BalancedPool) and GHSA-rfgv-xxqx-mfg5 (denial of service via an unrequested WebSocket subprotocol). Both are fixed in 7.29.1. It is a runtime dependency of @kintone/rest, so move the pin up. brace-expansion is affected by GHSA-6j4f-fj2g-mc7p and GHSA-qhr7-859c-m2p7, both stack exhaustion through uncontrolled recursion. Raise the override floors to the patched versions: 1.1.20, 2.1.6 and 5.0.11. The lockfile resolves 1.1.21, 2.1.7 and 5.0.12. Cap the `^5` override below v6 while here, so it matches the other two entries and cannot cross a major that its consumers do not declare. Drop the minimumReleaseAgeExclude entry for undici@7.28.0: the pin has moved past it and 7.29.1 was published on 2026-09-04, well beyond the 24 hour hold.
4 tasks
shabaraba
marked this pull request as ready for review
October 1, 2026 00:53
shabaraba
requested review from
chihiro-adachi and
nameless-mc
and removed request for
a team
October 1, 2026 00:53
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The manifests and lockfile are consistent, and all targeted dependencies resolve to patched versions.
Review effort: Balanced
Findings: None
What changed in this PR
Updates vulnerable dependencies to patched releases across the workspace.
Changes:
- Raises
brace-expansionandfast-urioverride floors. - Upgrades runtime dependency
undicito 7.29.1. - Refreshes the lockfile and removes obsolete release-age exceptions.
| File | Description |
|---|---|
package.json |
Updates security override ranges. |
packages/rest/package.json |
Upgrades undici. |
pnpm-lock.yaml |
Resolves patched dependency versions. |
pnpm-workspace.yaml |
Removes obsolete release-age exclusions. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
nameless-mc
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Three packages in the dependency graph are on versions with open high severity advisories.
fast-uri@4.1.3— fixed in4.1.4:parse()accepts a host with an unclosed authority bracket ([@127.0.0.1), so an application that makes a host decision fromparse().hostand then hands the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches.serialize()concatenates theportcomponent verbatim, so a non-numeric port can inject authority delimiters and demote the intended host to userinfo.fast-uriis not a direct dependency. It comes in throughajv, which uses it to normalize and compare$id/$refschema identifiers. That path makes no host decisions, and theportit serializes always comes fromparse(), which the second advisory calls out as unaffected. Exploitability is low; the point is to stop shipping an affected version in the lockfile.undici@7.28.0— fixed in7.29.1:BalancedPool.Unlike the other two, this one is a runtime dependency of
@kintone/rest, so it reaches consumers of the published package.brace-expansionat1.1.16/2.1.2/5.0.9— fixed in1.1.20/2.1.6/5.0.11:parseCommaParts.What
fast-urioverride:>=4.1.3→>=4.1.4 <5. The lockfile resolves4.2.1for bothajv@8.18.0andajv@8.20.0.ajvstill declaresfast-uri: ^3.0.1as of its latest release8.20.0, so v4 is reached only through this override. The upper bound is there so the next major cannot be picked up unnoticed, which is how v4 was reached in the first place. Drop it onceajvdeclares v4 or later.undiciinpackages/rest:7.28.0→7.29.1.brace-expansionoverrides:^1→>=1.1.20 <2,^2→>=2.1.6 <3,^5→>=5.0.11 <6. The lockfile resolves1.1.21,2.1.7and5.0.12. The^5entry gains an upper bound so it matches the other two and cannot cross a major its consumers do not declare.minimumReleaseAgeExcludeentries forfast-uri@4.1.2andundici@7.28.0go away. Both floors have moved past those versions, and4.1.4(2026-09-02) and7.29.1(2026-09-04) are well beyond the 24 hour hold.This supersedes #3934, which raised the
brace-expansionfloors for an earlier advisory (CVE-2026-69152) to versions that the two advisories above have since overtaken. It also covers #3924, which bumpsundicito7.29.0— one patch short of the fix.How to test
All green locally: lint, and 842 tests across the seven packages. That includes
packages/rest, which is the directundiciconsumer, and the 113 tests inplugin-manifest-validator, the heaviestajvuser in the repo.Two notes on running this locally.
pnpm buildhas to come first, otherwiselint:packagefails on the missinglib/es/index.d.ts. Andpnpm test:rootfails here for a reason unrelated to this change —__tests__/lib/workspace.tspasses"--depth 0"topnpm m lsas a single argument, which a recent pnpm rejects — it fails the same way on an unmodifiedmain, so the package suites were run directly.Checklist
pnpm lintandpnpm teston the root directory.Related PRs
The same
fast-urioverride change is going out to the other repositories in this org: