Skip to content

chore: fix some CVEs - #776

Closed
axi92 wants to merge 1 commit into
docker:mainfrom
axi92:fix/cves
Closed

axi92 wants to merge 1 commit into
docker:mainfrom
axi92:fix/cves

Conversation

@axi92

@axi92 axi92 commented Aug 28, 2025 •

Copy link
Copy Markdown

Goal of this PR: resolve as much CVEs as possible
Scan tool used: Trivy

Before
Report Summary

┌───────────┬──────┬─────────────────┬─────────┐
│  Target   │ Type │ Vulnerabilities │ Secrets │
├───────────┼──────┼─────────────────┼─────────┤
│ yarn.lock │ yarn │       10        │    -    │
└───────────┴──────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


yarn.lock (yarn)

Total: 10 (UNKNOWN: 0, LOW: 1, MEDIUM: 6, HIGH: 1, CRITICAL: 2)

┌───────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬──────────────────────────────────────────────────────────────┐
│            Library            │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                             │
├───────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ @octokit/plugin-paginate-rest │ CVE-2025-25288 │ MEDIUM   │ fixed  │ 2.21.3            │ 11.4.1, 9.2.2               │ octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest  │
│                               │                │          │        │                   │                             │ has a Regular Expression in iterator that Leads to ReDoS...  │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2025-25288                   │
├───────────────────────────────┼────────────────┤          │        ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ @octokit/request              │ CVE-2025-25290 │          │        │ 5.6.3             │ 9.2.1, 8.4.1                │ octokit/request: @octokit/request has a Regular Expression   │
│                               │                │          │        │                   │                             │ in fetchWrapper that Leads to ReDoS...                       │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2025-25290                   │
│                               │                │          │        ├───────────────────┤                             │                                                              │
│                               │                │          │        │ 8.1.1             │                             │                                                              │
│                               │                │          │        │                   │                             │                                                              │
│                               │                │          │        │                   │                             │                                                              │
├───────────────────────────────┼────────────────┤          │        ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ @octokit/request-error        │ CVE-2025-25289 │          │        │ 2.1.0             │ 5.1.1, 6.1.7                │ @octokit/request-error: @octokit/request-error has a Regular │
│                               │                │          │        │                   │                             │ Expression in index that Leads to ReDoS...                   │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2025-25289                   │
│                               │                │          │        ├───────────────────┤                             │                                                              │
│                               │                │          │        │ 5.0.0             │                             │                                                              │
│                               │                │          │        │                   │                             │                                                              │
│                               │                │          │        │                   │                             │                                                              │
├───────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ brace-expansion               │ CVE-2025-5889  │ LOW      │        │ 2.0.1             │ 2.0.2, 1.1.12, 3.0.1, 4.0.1 │ brace-expansion: juliangruber brace-expansion index.js       │
│                               │                │          │        │                   │                             │ expand redos                                                 │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2025-5889                    │
├───────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ form-data                     │ CVE-2025-7783  │ CRITICAL │        │ 3.0.1             │ 2.5.4, 3.0.4, 4.0.4         │ form-data: Unsafe random function in form-data               │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2025-7783                    │
│                               │                │          │        ├───────────────────┤                             │                                                              │
│                               │                │          │        │ 4.0.0             │                             │                                                              │
│                               │                │          │        │                   │                             │                                                              │
├───────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ semver                        │ CVE-2022-25883 │ HIGH     │        │ 6.3.0             │ 7.5.2, 6.3.1, 5.7.2         │ nodejs-semver: Regular expression denial of service          │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2022-25883                   │
├───────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ tough-cookie                  │ CVE-2023-26136 │ MEDIUM   │        │ 3.0.1             │ 4.1.3                       │ tough-cookie: prototype pollution in cookie memstore         │
│                               │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2023-26136                   │
└───────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴──────────────────────────────────────────────────────────────┘
After
Report Summary

┌───────────┬──────┬─────────────────┬─────────┐
│  Target   │ Type │ Vulnerabilities │ Secrets │
├───────────┼──────┼─────────────────┼─────────┤
│ yarn.lock │ yarn │        4        │    -    │
└───────────┴──────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


yarn.lock (yarn)

Total: 4 (UNKNOWN: 0, LOW: 0, MEDIUM: 4, HIGH: 0, CRITICAL: 0)

┌───────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────────┐
│            Library            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                            Title                             │
├───────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
│ @octokit/plugin-paginate-rest │ CVE-2025-25288 │ MEDIUM   │ fixed  │ 2.21.3            │ 11.4.1, 9.2.2 │ octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest  │
│                               │                │          │        │                   │               │ has a Regular Expression in iterator that Leads to ReDoS...  │
│                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2025-25288                   │
├───────────────────────────────┼────────────────┤          │        ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
│ @octokit/request              │ CVE-2025-25290 │          │        │ 5.6.3             │ 9.2.1, 8.4.1  │ octokit/request: @octokit/request has a Regular Expression   │
│                               │                │          │        │                   │               │ in fetchWrapper that Leads to ReDoS...                       │
│                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2025-25290                   │
├───────────────────────────────┼────────────────┤          │        ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
│ @octokit/request-error        │ CVE-2025-25289 │          │        │ 2.1.0             │ 5.1.1, 6.1.7  │ @octokit/request-error: @octokit/request-error has a Regular │
│                               │                │          │        │                   │               │ Expression in index that Leads to ReDoS...                   │
│                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2025-25289                   │
├───────────────────────────────┼────────────────┤          │        ├───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
│ tough-cookie                  │ CVE-2023-26136 │          │        │ 3.0.1             │ 4.1.3         │ tough-cookie: prototype pollution in cookie memstore         │
│                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2023-26136                   │
└───────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────────┘

I ran the tests: https://github.com/axi92/actions-toolkit/actions/runs/17286861753

I tried to patch with yarns resolutions as much as possible without breaking semver.

If this approach is not the desired one I am open to other changes.

Signed-off-by: axi92 <axi92@users.noreply.github.com>

@crazy-max crazy-max left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks but that's something that needs to be addressed upstream first as these are peer dependencies.

Comment thread package.json
"@actions/io": "^1.1.3",
"@actions/tool-cache": "^2.0.2",
"@azure/storage-blob": "^12.15.0",
"@azure/storage-blob": "^12.28.0",

@crazy-max crazy-max Aug 28, 2025 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We want to be aligned with upstream @actions/cache module: https://github.com/actions/toolkit/blob/f58042f9cc16bcaa87afaa86c2974a8c771ce1ea/packages/cache/package.json#L48. We already made the mistake to update to 12.15.0 while 12.13.0 is used by this module.

If updates are needed, open a PR on https://github.com/actions/toolkit first.

Comment thread package.json
Comment on lines +94 to +102
"form-data@^4.0.0": "4.0.4",
"form-data@^3.0.0": "3.0.4",
"semver@^6.3.0": "6.3.1",
"semver@^6.1.0": "6.3.1",
"brace-expansion@^2.0.1": "2.0.2",
"@octokit/request@^8.0.2": "8.4.1",
"@octokit/request@^8.0.1": "8.4.1",
"@octokit/request@^8.1.1": "8.4.1",
"@octokit/request-error@^5.0.0": "5.1.1"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here, these are peer dependencies that need to be addressed upstream first: https://github.com/actions/toolkit

See transitive dep in https://github.com/docker/actions-toolkit/security/dependabot/35 for example:

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants