From 2431047ce81b5cf3a75a41b3582325fe3f14e289 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=ABl=20Poyet?= Date: Thu, 16 Apr 2026 08:43:17 +0200 Subject: [PATCH] Update axios and lodash to address reported vulnerabilities - Bump axios from ^1.13.2 to ^1.15.0 to patch GHSA-fvcv-3m26-pcqx (unrestricted cloud metadata exfiltration via header injection) and GHSA-3p68-rc4w-qgx5 (NO_PROXY hostname normalization bypass leading to SSRF). - Bump lodash from ^4.17.21 to ^4.17.24 to patch GHSA-r5fr-rjxr-66jc (code injection via _.template) and GHSA-f23m-r3pf-42rh (prototype pollution via array path bypass in _.unset and _.omit). - Add an explicit overrides entry for follow-redirects ^1.15.12 to clear GHSA-r4q5-vmmm-2653 (custom authentication headers leaked to cross-domain redirect targets). axios 1.15.0 still pins follow-redirects@1.15.11, which is the upper bound of the vulnerable range; the override pulls in 1.16.0. npm audit now reports 0 vulnerabilities. All unit tests, lint, and prettier checks pass. Co-Authored-By: Claude Opus 4.6 (1M context) --- npm-shrinkwrap.json | 34 +++++++++++++++++++--------------- package.json | 7 +++++-- 2 files changed, 24 insertions(+), 17 deletions(-) diff --git a/npm-shrinkwrap.json b/npm-shrinkwrap.json index 8e7e15b53..f08d9fe28 100644 --- a/npm-shrinkwrap.json +++ b/npm-shrinkwrap.json @@ -11,7 +11,7 @@ "dependencies": { "ajv": "^8.17.1", "antlr4": "^4.13.2", - "axios": "^1.13.2", + "axios": "^1.15.0", "chalk": "^4.1.2", "commander": "^13.1.0", "fhir-package-loader": "^2.2.3", @@ -21,7 +21,7 @@ "https-proxy-agent": "^7.0.5", "ini": "^5.0.0", "junk": "^3.1.0", - "lodash": "^4.17.21", + "lodash": "^4.17.24", "readline-sync": "^1.4.10", "sanitize-filename": "^1.6.3", "sax": "^1.5.0", @@ -2794,14 +2794,14 @@ "license": "MIT" }, "node_modules/axios": { - "version": "1.13.6", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.13.6.tgz", - "integrity": "sha512-ChTCHMouEe2kn713WHbQGcuYrr6fXTBiu460OTwWrWob16g1bXn4vtz07Ope7ewMozJAnEquLk5lWQWtBig9DQ==", + "version": "1.15.0", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.15.0.tgz", + "integrity": "sha512-wWyJDlAatxk30ZJer+GeCWS209sA42X+N5jU2jy6oHTp7ufw8uzUTVFBX9+wTfAlhiJXGS0Bq7X6efruWjuK9Q==", "license": "MIT", "dependencies": { "follow-redirects": "^1.15.11", "form-data": "^4.0.5", - "proxy-from-env": "^1.1.0" + "proxy-from-env": "^2.1.0" } }, "node_modules/b4a": { @@ -4509,9 +4509,9 @@ "integrity": "sha512-GRnmB5gPyJpAhTQdSZTSp9uaPSvl09KoYcMQtsB9rQoOmzs9dH6ffeccH+Z+cv6P68Hu5bC6JjRh4Ah/mHSNRw==" }, "node_modules/follow-redirects": { - "version": "1.15.11", - "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.11.tgz", - "integrity": "sha512-deG2P0JfjrTxl50XGCDyfI97ZGVCxIpfKYmfyrQ54n5FO/0gfIES8C/Psl6kWVDolizcaaxZJnTS0QSMxvnsBQ==", + "version": "1.16.0", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.16.0.tgz", + "integrity": "sha512-y5rN/uOsadFT/JfYwhxRS5R7Qce+g3zG97+JrtFZlC9klX/W5hD7iiLzScI4nZqUS7DNUdhPgw4xI8W2LuXlUw==", "funding": [ { "type": "individual", @@ -6330,9 +6330,9 @@ } }, "node_modules/lodash": { - "version": "4.17.23", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", - "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", + "version": "4.18.1", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz", + "integrity": "sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==", "license": "MIT" }, "node_modules/lodash.memoize": { @@ -7154,9 +7154,13 @@ } }, "node_modules/proxy-from-env": { - "version": "1.1.0", - "resolved": "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-1.1.0.tgz", - "integrity": "sha512-D+zkORCbA9f1tdWRK0RaCR3GPv50cMxcrz4X8k5LTSUD1Dkw47mKJEZQNunItRTkWwgtaUSo1RVFRIG9ZXiFYg==" + "version": "2.1.0", + "resolved": "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-2.1.0.tgz", + "integrity": "sha512-cJ+oHTW1VAEa8cJslgmUZrc+sjRKgAKl3Zyse6+PV38hZe/V6Z14TbCuXcan9F9ghlz4QrFr2c92TNF82UkYHA==", + "license": "MIT", + "engines": { + "node": ">=10" + } }, "node_modules/pump": { "version": "3.0.0", diff --git a/package.json b/package.json index 8e7d46f0b..bead102bf 100644 --- a/package.json +++ b/package.json @@ -89,7 +89,7 @@ "dependencies": { "ajv": "^8.17.1", "antlr4": "^4.13.2", - "axios": "^1.13.2", + "axios": "^1.15.0", "chalk": "^4.1.2", "commander": "^13.1.0", "fhir-package-loader": "^2.2.3", @@ -99,7 +99,7 @@ "https-proxy-agent": "^7.0.5", "ini": "^5.0.0", "junk": "^3.1.0", - "lodash": "^4.17.21", + "lodash": "^4.17.24", "readline-sync": "^1.4.10", "sanitize-filename": "^1.6.3", "sax": "^1.5.0", @@ -110,5 +110,8 @@ "valid-url": "^1.0.9", "winston": "^3.19.0", "yaml": "^1.10.2" + }, + "overrides": { + "follow-redirects": "^1.15.12" } }