Repository navigation
Conversation
bump dependencies in chat-notification-pubnub-example, chat-notification-socketio-example, and telemed-app sandbox services to address security vulnerabilities flagged by trivy
|
There was a problem hiding this comment.
Approving. The sandbox lockfiles go from 61 HIGH to 6 on a Trivy scan, and CI is green.
One thing worth a follow-up: the root package-lock.json was regenerated as well, and a few packages went backwards there. loopback-connector-kv-redis's nested loopback-connector dropped from 4.11.1 to 4.2.2, which pulls in cross-spawn 5.1.0 (CVE-2024-21538).
postman-request went from postman.49 to postman.8-beta.1, nx from 22.7.8 to 22.6.4, and ejs from 5 to 3. Overall the root lock is still better (20 → 18 HIGH), so not blocking.
But it'd be good to restore those in the next pass, e.g. update from the existing lockfile rather than a fresh resolve, or add an overrides entry for loopback-connector.
Also, adding fast-uri as a direct dependency in the sandbox package.json files works, but an overrides entry would keep it out of each app's own dependency list.



Summary
chat-notification-pubnub-example,chat-notification-socketio-example, andtelemed-appsandbox servicespackage-lock.jsonfiles to resolve security vulnerabilities flagged by TrivyTest plan