Skip to content

fix(middlewareNode): npm audit fix + require express ^4.22.3, clears the critical (Issue 4) - #240

Open
Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-middleware-audit-fix
Open

Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-middleware-audit-fix

Conversation

@Deepesh-Katudia

@Deepesh-Katudia Deepesh-Katudia commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Safe (no --force) npm audit fix for middlewareNode, plus raising the express floor. Takes npm audit from 38 findings (1 critical, 11 high) to 8 (0 critical). The remaining 8 are the breaking bumps handled by the stacked PRs on top of this one.

Part of a stacked series. Merge in order: audit-fix -> axios -> nodemailer -> googleapis -> uuid -> node-nlp. Each PR targets the previous branch, so its diff shows only its own bump; After merging each one, click "Delete branch" (this repo does not auto-delete merged branches). That makes GitHub retarget the next PR to main and run CI on it; if the branch is not deleted, the next PR must be retargeted to main by hand before merging, or it will merge into a dead branch. (1/6: base of the stack)

Type of Change

  • New feature
  • Bug fix
  • Refactor
  • Documentation update
  • Style/UI update
  • Performance improvement
  • Other (please specify): dependency / security update (Issue 4)

Key Changes

  • Lockfile refresh, re-run until stable. Note: the first pass alone leaves @azure/core-xml at 1.4.5 with fast-xml-parser 5.2.5 (critical); later passes move it to fast-xml-parser 5.11.1. Single-pass runs of npm audit fix miss this.
  • Clears the AWS SDK moderate cluster and the express / qs / body-parser cluster (express -> 4.22.3).
  • package.json: express floor ^4.17.1 -> ^4.22.3 (one-line change).

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed: npm audit after clean npm ci
  • All tests pass: 22/22 suites, 264/264 tests (same as main baseline)

Bugs Fixed (if applicable)

  • Critical fast-xml-parser (via @azure/storage-blob -> @azure/core-xml).
  • express / qs / body-parser, AWS SDK cluster, ip-address, mongoose, multer, js-yaml, form-data, brace-expansion.

TODO (Follow-up Work)

Additional Notes

Regenerated off current main rather than cherry-picked from dependancyFix.

sanjana1976 and others added 2 commits September 18, 2026 11:33
Safe, in-range lockfile refresh only; package.json is untouched. Run
until the lockfile stopped changing: the first pass leaves
@azure/core-xml at 1.4.5 (fast-xml-parser 5.2.5) and only the second
moves it to 1.6.x / fast-xml-parser 5.11.1.

Clears the critical fast-xml-parser finding, the AWS SDK moderate
cluster, and the express/qs/body-parser cluster (express resolves to
4.22.3, which ships patched qs).
Raises the declared floor (was ^4.17.1) to the first release that ships
the patched qs and path-to-regexp, so a regenerated lockfile cannot
resolve back to a vulnerable 4.x.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues; all supplied readiness assessments approve it.

Pull request overview

Updates middlewareNode dependencies to remediate security audit findings and raise the Express minimum version.

Changes:

  • Requires Express ^4.22.3.
  • Refreshes the lockfile with patched dependency versions.
  • Removes obsolete and vulnerable transitive packages.
File summaries
File Description
middlewareNode/package.json Raises the Express dependency floor.
middlewareNode/package-lock.json Records refreshed dependency resolutions and security fixes.
Review details

Files not reviewed (1)

  • middlewareNode/package-lock.json: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants