Skip to content

fix(deps): fix trivy vulnerability findings - #132

Merged
a-ganguly merged 2 commits into
masterfrom
fix/trivy
Sep 10, 2026
Merged

a-ganguly merged 2 commits into
masterfrom
fix/trivy

Conversation

@piyushsinghgaur1

@piyushsinghgaur1 piyushsinghgaur1 commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Description

Refreshes package-lock.json to pull in patched versions of dependencies flagged by the Trivy scan (.github/workflows/trivy.yml, which gates on HIGH/CRITICAL with ignore-unfixed: true).

Against master: 113 distinct packages changed version (116 lockfile entries), 6 added, 9 removed.

One package.json change accompanies the lockfile — mocha added to root devDependencies — explained below. No existing dependency range was modified, so no direct dependency contract changes.

Why mocha was added to devDependencies

Regenerating the lockfile broke the test job on every service. This pin is the fix, not a new dependency.

What broke. Nothing in this repo declared mocha directly. It was only in the tree because npm auto-installs peer dependencies, and mochawesome declares mocha: ">=7". That left the hoisted copy free to float, and the regen moved it from 11.8.0 to 12.0.0.

mocha 12 replaced lib/utils.js with a lib/utils/ directory that contains no index. mochawesome@7.1.4 still does require('mocha/lib/utils') (src/utils.js:6), so the reporter fails to load and mocha aborts before running a single test:

Cannot find module 'mocha/lib/utils'
✖ ERROR: TypeError: Could not load reporter "mochawesome"

Both subscription-service and tenant-management-service set "reporter": "mochawesome" in .mocharc.json, so their suites never ran at all.

The fix. Declaring mocha: "^11.8.0" as a root devDependency pins it and re-dedupes @loopback/build (which wants ^11.8.0) back onto the single hoisted copy. The resolved version is 11.8.0 — identical to master, so this restores master's tree rather than changing it. It makes an already-load-bearing dependency explicit instead of leaving it to peer auto-install.

Two alternatives were tried and rejected:

  • An overrides entry does not work. npm ignores overrides for an auto-installed peer; the lock still resolved mocha 12.
  • Upgrading mochawesome does not help. The current 8.0.1 still contains the same require('mocha/lib/utils') line.

Notable bumps

Package From To
axios 1.19.0 1.20.0
body-parser 1.20.6 1.20.8
qs 6.15.3 6.16.0
undici 7.29.0 7.29.1
nanoid 3.3.17 3.3.18
socks 2.8.9 2.8.10
js-yaml 3.15.1 / 4.3.1 3.15.2 / 4.3.2
pg 8.22.0 8.23.0
fast-xml-parser 5.10.1 5.11.1
morgan 1.11.0 1.12.0
express-rate-limit 8.6.1 8.7.0
strong-error-handler 5.0.32 6.0.1
loopback-connector 7.0.6 8.0.2
@loopback/* 8.0.14 line 8.0.15 line
@aws-sdk/* / @smithy/* 3.1102.x / 3.31.x 3.1129.x / 3.33.x
nx / @nx/* 22.7.8 22.7.11

Two type-only downgrades appear in the diff and are worth flagging for reviewers: @types/node 26.1.2 → 22.20.2 and undici-types 8.3.0 → 6.21.0. @types/node 22.x is the correct line for this repo's "node": "22 || 24" engines; build and lint pass on it.

Type of change

  • Bug fix (non-breaking change which fixes an issue)

How Has This Been Tested?

  • npm run test --workspaces — 116 passing (4 orchestrator, 36 subscription, 76 tenant-management), 0 failing
  • npm run lint --workspaces — eslint + prettier clean
  • npm ls --depth=0 — dependency tree resolves cleanly against the new lockfile
  • Resolved mocha confirmed at 11.8.0, deduped to a single hoisted copy
  • npm audit reviewed before/after; remaining HIGH/CRITICAL items are dev-only and unfixed upstream
  • CI (build / test / Trivy / SonarCloud) to confirm on this PR

Checklist:

  • Performed a self-review of my own code
  • npm test passes on your machine
  • New tests added or existing tests modified to cover all changes — n/a, dependency-resolution change only
  • Code conforms with the style guide
  • API Documentation in code was updated — n/a
  • Any dependent changes have been merged and published in downstream modules

@piyushsinghgaur1 piyushsinghgaur1 self-assigned this Sep 9, 2026
Regenerating package-lock.json let the hoisted mocha float from 11.8.0 to
12.0.0. Nothing in the repo declared mocha directly — it was only present
because npm auto-installs mochawesome's `mocha: ">=7"` peer dependency.

mocha 12 replaced lib/utils.js with a lib/utils/ directory that has no
index, so mochawesome@7.1.4's `require('mocha/lib/utils')` fails and mocha
aborts before running a single test:

    Cannot find module 'mocha/lib/utils'
    ERROR: TypeError: Could not load reporter "mochawesome"

subscription-service and tenant-management-service both set
"reporter": "mochawesome" in .mocharc.json, so their suites never ran.

Declaring mocha as a root devDependency pins it and re-dedupes
@loopback/build back onto the single hoisted copy. An overrides entry does
not work here, as npm ignores it for an auto-installed peer. Upgrading
mochawesome does not help either — 8.0.1 still requires mocha/lib/utils.

npm run test --workspaces: 116 passing (4 orchestrator, 36 subscription,
76 tenant-management).

Refs GH-132
@sonarqubecloud

Copy link
Copy Markdown

@a-ganguly
a-ganguly merged commit 5950c3a into master Sep 10, 2026
6 checks passed
@a-ganguly
a-ganguly deleted the fix/trivy branch September 10, 2026 08:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants