Skip to content

fix: update vulnerable transitive dependencies - #332

Merged
simonswine merged 1 commit into
mainfrom
20261006_fix-cve
Oct 6, 2026
Merged

simonswine merged 1 commit into
mainfrom
20261006_fix-cve

Conversation

@simonswine

Copy link
Copy Markdown
Contributor

Summary

  • Update proxy-addr, qs, and undici resolutions to patched versions.

Validation

  • Generated /Users/christian/git/github.com/grafana/pyroscope-nodejs/main/src/version.ts with VERSION=0.6.4
    ▶ checkPyroscopeConfig
    ✔ accepts a valid config (1.374542ms)
    ✔ rejects appName containing "{" (0.226667ms)
    ✔ rejects tag key containing "{" (0.0855ms)
    ✔ rejects tag value containing "{" (0.061958ms)
    ✔ rejects appName containing "}" (0.046417ms)
    ✔ rejects tag key containing "}" (0.053125ms)
    ✔ rejects tag value containing "}" (0.044542ms)
    ✔ rejects appName containing "," (0.056292ms)
    ✔ rejects tag key containing "," (0.063125ms)
    ✔ rejects tag value containing "," (0.092375ms)
    ✔ rejects appName containing "=" (0.050708ms)
    ✔ rejects tag key containing "=" (0.046459ms)
    ✔ rejects tag value containing "=" (0.034709ms)
    ✔ rejects a tag value that is not a string or number (0.054625ms)
    ✔ checkPyroscopeConfig (3.019375ms)
    ▶ express middleware
    ✔ should be a function (0.281667ms)
    ✔ should respond to cpu calls (1061.619ms)
    ✔ should respond to repetitive cpu calls (1049.129667ms)
    ✔ should respond to heap profiling calls (7.500917ms)
    ✔ should respond to repetitive heap profiling calls (4.756041ms)
    ✔ should respond to simultaneous heap profiling calls (8.091875ms)
    ✔ should be fine using two middlewares at the same time (7.432458ms)
    ✔ express middleware (2139.841084ms)
    ▶ fastify middleware
    ✔ should be a function (0.418209ms)
    ✔ should respond to cpu calls (1095.453666ms)
    ✔ should respond to repetitive cpu calls (1048.169542ms)
    ✔ should respond to heap profiling calls (3.614458ms)
    ✔ should respond to repetitive heap profiling calls (2.448084ms)
    ✔ should respond to simultaneous heap profiling calls (2.178292ms)
    ✔ should be fine using two middlewares at the same time (3.319375ms)
    ✔ fastify middleware (2156.652083ms)
    ▶ typescript env
    ✔ has correct imports (0.498417ms)
    ✔ can process profile (1.430458ms)
    ✔ typescript env (2.694042ms)
    ▶ processProfile
    ✔ generates function names with cwd-relative paths by default (1.166917ms)
    ✔ uses package-relative paths with shortenPaths (0.179292ms)
    ✔ removes every filename with stripFilenames: all (0.240042ms)
    ✔ keeps first-party filenames with stripFilenames: dependencies (0.135459ms)
    ✔ handles Windows path separators (0.196667ms)
    ✔ remaps aliased value types only once when rebuilding (0.13875ms)
    ✔ remaps sample type names when rebuilding the string table (0.09875ms)
    ✔ processProfile (2.771292ms)
    ▶ common behaviour of profilers
    ✔ should call a server on startCpuProfiling and clear gracefully (173.857ms)
    ✔ should call a server on startHeapProfiling and clear gracefully (111.3315ms)
    ✔ should allow to call start profiling twice (0.278292ms)
    ✔ should have dynamic labels on wall profile (228.582083ms)
    ✔ should have extra samples for cpu time when enabled on wall profile (124.896084ms)
    ✔ should send bearer authentication header when configured (144.60425ms)
    ✔ should send basic authentication header when configured (146.3265ms)
    ✔ should send x-scope-orgid header when configured (147.029542ms)
    ✔ common behaviour of profilers (1077.769958ms)
    ▶ SourceMapper inline base64 sourcemap
    ✔ parses a single inline //# sourceMappingURL= directive (6.538292ms)
    ✔ parses inline sourceMappingURL when the file emits the directive twice (2.453833ms)
    ✔ parses inline sourceMappingURL with a trailing inline comment on the same line (2.065125ms)
    ✔ SourceMapper inline base64 sourcemap (11.843458ms)
    ℹ tests 48
    ℹ suites 7
    ℹ pass 48
    ℹ fail 0
    ℹ cancelled 0
    ℹ skipped 0
    ℹ todo 0
    ℹ duration_ms 2292.297125 (48 tests passed)
  • └─ @types/source-map
    ├─ ID: @types/source-map (deprecation)
    ├─ Issue: This is a stub types definition for source-map (https://github.com/mozilla/source-map). source-map provides its own type definitions, so you don't need @types/source-map installed!
    ├─ Severity: moderate
    ├─ Vulnerable Versions: 0.5.7
    │
    ├─ Tree Versions
    │ └─ 0.5.7
    │
    └─ Dependents
    └─ @pyroscope/nodejs@workspace:. reports the @types/source-map deprecation.

@cla-assistant

cla-assistant Bot commented Oct 6, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@simonswine
simonswine marked this pull request as ready for review October 6, 2026 09:45
@simonswine
simonswine requested review from a team as code owners October 6, 2026 09:45
@simonswine
simonswine merged commit 61d7d57 into main Oct 6, 2026
16 of 17 checks passed
@simonswine
simonswine deleted the 20261006_fix-cve branch October 6, 2026 10:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants