Skip to content

fix(deps): resolve Snyk and npm audit vulnerabilities - #81

Open
cs-raj wants to merge 1 commit into
mainfrom
fix/snyk-vulnerability-resolution
Open

cs-raj wants to merge 1 commit into
mainfrom
fix/snyk-vulnerability-resolution

Conversation

@cs-raj

@cs-raj cs-raj commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Problem

A full audit of main (clean npm install, then npm audit + snyk test) found:

Snyk — 25 issues total (2 critical, 7 high, 16 medium), of which 14 are security vulnerabilities (2 critical, 7 high, 5 medium) and 11 are LGPL-3.0 license notices:

Package Severity Issue Path
undici@8.10.0 critical Improper Certificate Validation isomorphic-dompurify > jsdom > undici
undici@8.10.0 critical Origin Validation Error isomorphic-dompurify > jsdom > undici
undici@8.10.0 high Missing Release of Resource after Effective Lifetime isomorphic-dompurify > jsdom > undici
undici@8.10.0 high Allocation of Resources Without Limits or Throttling isomorphic-dompurify > jsdom > undici
undici@8.10.0 high Uncaught Exception (x3) isomorphic-dompurify > jsdom > undici
undici@8.10.0 high Use of Persistent Cookies Containing Sensitive Information isomorphic-dompurify > jsdom > undici
undici@8.10.0 medium HTTP Request Smuggling isomorphic-dompurify > jsdom > undici
undici@8.10.0 medium Numeric Truncation Error isomorphic-dompurify > jsdom > undici
undici@8.10.0 medium Insufficient Verification of Data Authenticity isomorphic-dompurify > jsdom > undici
sharp@0.35.3 high Heap-based Buffer Overflow (libheif) next > sharp
qs@6.15.3 medium Allocation of Resources Without Limits or Throttling @contentstack/delivery-sdk > @contentstack/core > qs
qs@6.15.3 medium Uncaught Exception @contentstack/delivery-sdk > @contentstack/core > qs

npm audit — 6 vulnerabilities (0 critical, 3 high, 3 moderate): sharp, next (via sharp), js-yaml (via @eslint/eslintrc), qs, @contentstack/core, @contentstack/delivery-sdk.

Every finding sits in a transitive dependency. npm audit proposed a @contentstack/delivery-sdk major downgrade and Snyk proposed an isomorphic-dompurify 3.x → 4.x major bump — neither was applied.

Fix

All fixes are same-major version pins applied through the existing overrides block, so no direct dependency changes majors:

Override Before After Clears
qs 6.15.3 6.16.0 2 medium
sharp 0.35.3 0.35.4 1 high (+ the next high in npm audit)
undici (new) 8.10.2 2 critical, 5 high, 3 medium
js-yaml (new) 4.3.2 1 npm audit high

postcss (8.5.25) and nanoid (3.3.18) overrides are unchanged. Package version bumped 1.2.2 → 1.2.3.

Results after a clean install (rm -rf node_modules package-lock.json && npm install)

Scanner Before After Resolved
Snyk (security) 14 (C:2 H:7 M:5) 0 14
Snyk (total incl. license) 25 (C:2 H:7 M:16) 11 (all medium) 14
npm audit 6 (H:3 M:3) 0 6

The 11 remaining Snyk findings are all LGPL-3.0 license notices on optional platform binaries of sharp/libvips (@img/sharp-libvips-*) — license metadata, not security vulnerabilities, and not fixable by a version bump.

next also floated 16.3.3 → 16.3.4 within its existing ^16.2.12 range on the fresh lockfile.

Verification

  • npm run build — passes (Next.js 16.3.4, Turbopack; TypeScript check clean; 4/4 pages generated). Run twice, exit code 0 both times.
  • npm audit — 0 vulnerabilities.
  • snyk test — 0 security issues.
  • snyk code test returned 5 findings for files that do not exist in this repository (src/main.ts, test/service-tests/..., scripts/db/migrations/...) — stale results from a mismatched server-side Snyk Code project, not applicable to this codebase.

🤖 Generated with Claude Code

Clear all 14 security findings reported by Snyk (2 critical, 7 high,
5 medium) and all 6 npm audit findings (3 high, 3 moderate) by pinning
fixed transitive versions through the overrides block. No major version
bumps were applied.

- qs 6.15.3 -> 6.16.0 (resource exhaustion, uncaught exception)
- sharp 0.35.3 -> 0.35.4 (heap-based buffer overflow via libheif)
- undici -> 8.10.2 (improper certificate validation, origin validation
  error, request smuggling, cookie leakage and 5 more)
- js-yaml -> 4.3.2 (CPU exhaustion via empty merge sources)

Bump package version 1.2.2 -> 1.2.3.

Remaining 11 Snyk findings are LGPL-3.0 license notices on optional
platform binaries of sharp/libvips, not security vulnerabilities.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@cs-raj
cs-raj requested a review from a team as a code owner September 10, 2026 12:59
@snyk-io

snyk-io Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 21 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 0
  • High without fixes: 0
  • Medium without fixes: 21
  • Low without fixes: 0

✅ BUILD PASSED - All security checks passed

@amit-kanswal-cs amit-kanswal-cs left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants