Skip to content

fix(security): update dependencies for axios and image-size. - #6327

Merged
jbocce merged 1 commit into
masterfrom
fix/OHIF-2751-security
Sep 30, 2026
Merged

jbocce merged 1 commit into
masterfrom
fix/OHIF-2751-security

Conversation

@jbocce

@jbocce jbocce commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Context

The following vulnerabilities were addressed:

Changes & Results

Update dependencies via overrides.

Testing

All CI checks and tests must pass.

Summary by CodeRabbit

  • Security
    • Updated security protections for image processing and network request components. Known image-size advisories are no longer excluded from audit checks, and affected versions are pinned to a newer release.
    • Updated the version used for network requests.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.

Tip: disable this comment in your organization's Code Review settings.

@netlify

netlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for ohif-dev ready!

Name Link
🔨 Latest commit 7ea8ca9
🔍 Latest deploy log https://app.netlify.com/projects/ohif-dev/deploys/6abd5ef0d3afcf00086f7142
😎 Deploy Preview https://deploy-preview-6327--ohif-dev.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@jbocce
jbocce deployed to unrestricted September 30, 2026 19:11 — with GitHub Actions Active
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 0d2f53f4-3366-44f8-a2c7-6f4c3d8d2d25

📥 Commits

Reviewing files that changed from the base of the PR and between 119f997 and 7ea8ca9.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The workspace configuration removes two image-size advisory exemptions, updates the Axios override to 1.20.0, and adds an override that resolves specified image-size versions to 2.0.4.

Changes

Dependency overrides

Layer / File(s) Summary
Audit and package overrides
pnpm-workspace.yaml
The audit ignore list no longer exempts two image-size advisories. The Axios override changes to 1.20.0. A new override resolves image-size versions >=0.6.3 <2.0.4 to 2.0.4.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 7ea8c

The image-size override and frozen-install lockfile are consistent. No concrete compatibility failure is identified in the repository-visible Axios use; compatibility of external consumers remains unconfirmed.

Architecture Summary

Architecture risk: 🔵 Low · up to 7ea8c

The change affects 1 system.

Changed systems: pnpm-workspace.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — pnpm-workspace.yaml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in pnpm-workspace.yaml: The image-size risk comment and its two GHSA exemptions were removed from auditConfig.ignoreGhsas; the extract-zip comment now occupies this line.
  • observed — Modified behavior in pnpm-workspace.yaml: The Axios override changes from 1.18.1 to 1.20.0.
  • observed — Modified behavior in pnpm-workspace.yaml: Adds an override resolving image-size versions >=0.6.3 <2.0.4 to 2.0.4.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the vulnerabilities and dependency override changes, and it includes a testing section. It omits the required Checklist section and tested-environment details. Add the complete Checklist section from the repository template. Mark each applicable item, and provide the tested OS, Node version, and browser details.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the security dependency updates for Axios and image-size. It uses the expected semantic-release format and matches the main changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cypress

cypress Bot commented Sep 30, 2026

Copy link
Copy Markdown

Viewers    Run #6850

Run Properties:  status check passed Passed #6850  •  git commit 7ea8ca94aa: fix(security): update dependencies for axios and image-size.
Project Viewers
Branch Review fix/OHIF-2751-security
Run status status check passed Passed #6850
Run duration 01m 49s
Commit git commit 7ea8ca94aa: fix(security): update dependencies for axios and image-size.
Committer Joe Boccanfuso
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 28
View all changes introduced in this branch ↗︎

@jbocce
jbocce merged commit f401e15 into master Sep 30, 2026
14 checks passed

This branch was successfully deployed

1 active deployment
unrestricted — 7ea8ca94 Deployed Sep 30, 2026 by jbocce via playwright-tests (24.15.0) #5138
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant