Security: patch vulnerable transitive npm deps (form-data HIGH, uuid MEDIUM) #36

Closed
opened 2026-07-02 20:30:07 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-02 20:30:07 +00:00 (Migrated from github.com)

Context

Dependabot flagged two open alerts on main in pnpm-lock.yaml (surfaced during #10 development):

Severity Package Vulnerable Patched Issue
HIGH form-data >=4.0.0 <4.0.6 4.0.6 CRLF injection via unescaped multipart field names/filenames
MEDIUM uuid <11.1.1 11.1.1 Missing buffer bounds check in v3/v5/v6 when buf provided

Both are transitive dev-tooling deps (pulled in by wrangler / @usebruno/cli), NOT shipped in the Go/Wasm Worker, so runtime exposure is low — but they are real alerts and cheap to fix.

Scope

  • Force patched versions via pnpm overrides in package.json ("pnpm": { "overrides": { "form-data": ">=4.0.6", "uuid": ">=11.1.1" } }) or pnpm update, then regenerate pnpm-lock.yaml.
  • Verify pnpm install exits 0 and the resolved versions are patched.
  • Confirm the Bruno suite (pnpm run test:api) and wrangler still work.

Acceptance criteria

  • Both Dependabot alerts resolve (patched versions in the lockfile); pnpm install clean; Bruno + wrangler unaffected.
## Context Dependabot flagged two open alerts on `main` in `pnpm-lock.yaml` (surfaced during #10 development): | Severity | Package | Vulnerable | Patched | Issue | |---|---|---|---|---| | **HIGH** | `form-data` | `>=4.0.0 <4.0.6` | `4.0.6` | CRLF injection via unescaped multipart field names/filenames | | MEDIUM | `uuid` | `<11.1.1` | `11.1.1` | Missing buffer bounds check in v3/v5/v6 when `buf` provided | Both are **transitive dev-tooling deps** (pulled in by `wrangler` / `@usebruno/cli`), NOT shipped in the Go/Wasm Worker, so runtime exposure is low — but they are real alerts and cheap to fix. ## Scope - [ ] Force patched versions via **pnpm overrides** in `package.json` (`"pnpm": { "overrides": { "form-data": ">=4.0.6", "uuid": ">=11.1.1" } }`) or `pnpm update`, then regenerate `pnpm-lock.yaml`. - [ ] Verify `pnpm install` exits 0 and the resolved versions are patched. - [ ] Confirm the Bruno suite (`pnpm run test:api`) and `wrangler` still work. ## Acceptance criteria - Both Dependabot alerts resolve (patched versions in the lockfile); `pnpm install` clean; Bruno + wrangler unaffected.
Sign in to join this conversation.