Skip to content
This repository was archived by the owner on Aug 13, 2026. It is now read-only.

fix: override vulnerable dependencies (sha.js, Babel helpers/runtime) - #5255

Open
adeelahmad6834 wants to merge 1 commit into
FlowiseAI:mainfrom
adeelahmad6834:fix/security-overrides
Open

fix: override vulnerable dependencies (sha.js, Babel helpers/runtime)#5255
adeelahmad6834 wants to merge 1 commit into
FlowiseAI:mainfrom
adeelahmad6834:fix/security-overrides

Conversation

@adeelahmad6834

Copy link
Copy Markdown

Summary

This PR updates Flowise’s dependency resolution to patch known vulnerabilities flagged by OWASP Dependency-Check:

  • sha.js: upgraded via override to >= 2.4.12
  • @babel/helpers and @babel/runtime: upgraded via override to >= 7.26.10
    • Advisory: GHSA-23rh-42f3-5vmq (Moderate)

Changes:

  • Added overrides block in root package.json
  • Regenerated pnpm-lock.yaml with pnpm install --lockfile-only

Security Rationale

  • Before: Security scans flagged 1 Critical (sha.js) and multiple Moderates.
  • After: Critical reduced to 0 in Dependency-Check rollup.

ASVS Reference

  • ASVS 14.2.2: Ensure components (libraries, frameworks) are up-to-date and verified against known vulnerabilities.
  • ASVS 14.2.4: Use software composition analysis to manage third-party components.

Impact

  • No runtime code changes.
  • Safe, minimal modification; improves supply chain security.
  • Validated with DevSecOps pipeline (artifacts available).

dblagbro added a commit to dblagbro/flow-wiser that referenced this pull request Aug 12, 2026
upstream-archive/ preserves 347 open pull requests from FlowiseAI/Flowise,
captured 2026-08-05 before the 2026-08-10 archive lock, as git am-able patches
with original authorship intact. Three have been acted on -- FlowiseAI#6682 and FlowiseAI#6683
(CVEs, with anupamme preserved as commit author) and FlowiseAI#6706 (connect-sqlite3).
The other 344 have never been reviewed.

MANIFEST.md is explicit that the snapshot exists so the backlog stays
"reviewable and re-appliable". It was captured, not fulfilled. Nothing was lost;
nothing was gained either.

These are the last contributions the upstream community will ever make to this
codebase -- upstream is archived and will accept nothing further. They are
Apache-2.0, they carry their authors' names, and Flow-Wiser exists as a
continuation fork. They are also the cheapest fixes this project will ever get:
129 titles begin with "fix", already written and tested by someone else.

Records the shape (129 fix / 173 feat / 5 security / 7 chore / 21 draft), the age
skew toward 2026-06 and 2026-07 which suggests most still apply cleanly, and
names the three unadopted security PRs as the place to start: FlowiseAI#6672, FlowiseAI#5371 and
FlowiseAI#5255 -- contributor-authored hardening that the 116-advisory sweep would not
have caught.

Two constraints stated plainly. Fifteen patches are permanently incomplete: they
touched enterprise/ or IdentityManager.ts, and 196 hunk bodies totalling 14,224
lines were redacted on 2026-08-06 because diff context carries licensed file
fragments. They must not be reconstructed -- that is reading licensed content,
which ADR-0002 forbids. And apply with --keep-non-patch so authorship survives;
a contribution merged without its author's name is a contribution stolen.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

2 participants