Skip to content

Fix vulnerabilities in various package.json and Gemfile files - #7167

Open
SherfeyInv wants to merge 37 commits into
snyk:mainfrom
Aysher-Intelligence-Agency:Aysher
Open

Fix vulnerabilities in various package.json and Gemfile files#7167
SherfeyInv wants to merge 37 commits into
snyk:mainfrom
Aysher-Intelligence-Agency:Aysher

Conversation

@SherfeyInv

@SherfeyInv SherfeyInv commented Aug 24, 2026

Copy link
Copy Markdown

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

Where should the reviewer start?

How should this be manually tested?

What's the product update that needs to be communicated to CLI users?


Note

Low Risk
Changes are a direct dependency version bump and a test fixture pin; no production logic or auth flows are modified in the diff.

Overview
Bumps the root CLI dependency uuid from ^11.1.1 to ^14.0.0, aligning with existing package.json overrides that pin transitive uuid consumers to the same version.

Updates the snyk-fix pip-requirements acceptance workspace so pip-app/requirements.txt expects Django==3.2.14 instead of 1.6.1, keeping the update-dependencies test fixture in line with the remediated pin.

Reviewed by Cursor Bugbot for commit 6f42919. Bugbot is set up for automated code reviews on this repo. Configure here.

snyk-bot and others added 30 commits September 16, 2025 04:39
…ues-and-project-with-error/project-with-issues/package.json & test/fixtures/snyk-test-all-projects-exit-codes/project-with-issues-and-project-with-error/project-with-issues/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-LODASH-6139239
- https://snyk.io/vuln/SNYK-JS-LODASH-608086
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
…b77f22451131d9cba8b4a3186a0

[Snyk] Security upgrade lodash from 4.17.0 to 4.17.12
…b4ea41836b16a880a90de2a20f8

[Snyk] Security upgrade django from 1.6.1 to 3.2.14
…900daec797fdf72c68c03febe12

[Snyk] Security upgrade lodash from 4.17.15 to 4.17.21
…on & packages/snyk-protect/test/fixtures/no-matching-paths/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-AJV-15274295
- https://snyk.io/vuln/SNYK-JS-QS-15268416
…pp-2/bundler-app-3/bundler-app-4/bundler-app-5/bundler-app-17/Gemfile & test/acceptance/workspaces/large-mono-repo/bundler-app/bundler-app-2/bundler-app-3/bundler-app-4/bundler-app-5/bundler-app-17/Gemfile.lock to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-RUBY-RACK-2848599
…e vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416
….json & test/acceptance/workspaces/large-mono-repo/npm-project-3/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416
…patches-for-version/package.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-UUID-16133035
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-UUID-16133035
….json to reduce vulnerabilities (#451)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-MONGOOSE-16425765

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
….json & test/acceptance/workspaces/large-mono-repo/npm-project-7/package-lock.json to reduce vulnerabilities (#447)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…e.json to reduce vulnerabilities (#446)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-QS-15268416

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…-version/package.json & test/acceptance/workspaces/npm-lock-v2-with-npm-prefixed-sub-dep-version/package-lock.json to reduce vulnerabilities (#445)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-GLOB-14040952
- https://snyk.io/vuln/SNYK-JS-TAR-6476909

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…package.json & test/acceptance/workspaces/npm-package-lockfile-v3-bundled-deps/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-AXIOS-15252993
…2a4ae3c8390c033068da977bc11d

[Snyk] Security upgrade qs from 0.6.6 to 6.14.2
…b311d5548bf6a746782baa9fc0d5

[Snyk] Security upgrade qs from 0.0.6 to 6.14.2
…c20dcee8813b5f63b1406f5fc8c8

[Snyk] Security upgrade qs from 0.0.6 to 6.14.2
…089bf6833aa28d1c5fff216e61b7

[Snyk] Security upgrade actionpack from 4.2.5 to 5.2.4.3
SherfeyInv and others added 4 commits August 12, 2026 21:48
…911a4ce710ece07342f70e461f57

[Snyk] Security upgrade rack from 1.6.5 to 2.0.9.1
…92cde9e35e2236aca67725397cad

[Snyk] Security upgrade tap from 11.1.3 to 18.0.0
@SherfeyInv
SherfeyInv requested a review from a team as a code owner August 24, 2026 01:02
@CLAassistant

CLAassistant commented Aug 24, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 3 committers have signed the CLA.

✅ SherfeyInv
❌ snyk-bot
❌ Ron Sherfey


Ron Sherfey seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@snyk-io

snyk-io Bot commented Aug 24, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.

Fix All in Cursor

Reviewed by Cursor Bugbot for commit 6f42919. Configure here.

-r base.txt
-r base2.txt
Django==1.6.1
Django==3.2.14

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixture Django version breaks fix test

Medium Severity

The pip-app acceptance workspace now pins Django==3.2.14, but the fixes multiple files that are included via -r test still supplies remediation for django@1.6.1 and expects an upgrade to 2.0.1. Upgrade matching keys off the installed version, so the Django fix is skipped and assertions on write count and change messages fail.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 6f42919. Configure here.

Comment thread package.json
"strip-ansi": "^6.0.1",
"tar": "^7.5.8",
"uuid": "^11.1.1",
"uuid": "^14.0.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile still pins old uuid

Medium Severity

Root package.json now requires uuid ^14.0.0, but this commit does not update package-lock.json, which still resolves uuid to 11.1.1. CI flows using npm ci continue installing the older package, so the intended vulnerability bump may not take effect in automated builds.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 6f42919. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants