Lockfile-level fix for the HIGH/CRITICAL advisories that the estate CI (trivy) reports on main @ 23f99f9. Only vulnerable packages were touched; every bump stays inside its current major.
Scanner: trivy fs --scanners vuln --severity HIGH,CRITICAL (trivy 0.73.0, vuln DB updated 2026-09-30 01:15 UTC, used offline with --skip-db-update), run in default mode and with --include-dev-deps. Cross-checked with npm audit --audit-level=high.
Note: the advisories named in the estate alert for other repos (fast-uri CVE-2026-84292, @xhmikosr/decompress CVE-2026-101894) are not in this repo's lockfile. brace-expansion CVE-2026-102276 is present, as a dev-only transitive.
Findings before -> after
Package
Before
After
Advisory
Kind
next
16.3.1
16.3.3
CVE-2026-75604 / GHSA-2xp9-vwfh-vxw4 (CRITICAL)
direct, exact pin, patch
js-yaml
4.3.1
4.3.2
CVE-2026-84375 (HIGH)
direct, exact pin, patch
nodemailer
9.0.5
9.1.1
GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj (HIGH)
direct, exact pin, minor
sharp
0.35.3
0.35.5
GHSA-rgj7-g3m4-5g8c (HIGH)
direct + override, in range (^0.35.3), lockfile only
undici
6.28.0
6.29.0
CVE-2026-19534 (HIGH)
transitive via @ai-sdk/provider-utils (^6.28.0), lockfile only
Companion lockfile movement that comes with the above and nothing else: sharp platform binaries and libvips (@img/sharp-* 0.35.5, @img/sharp-libvips-* 1.3.4), @emnapi/runtime 1.11.3, @next/env and @next/swc-* 16.3.3, and the nested @eslint/eslintrc/node_modules/js-yaml copy deduped into the top-level js-yaml.
Files
package.json: exact pins for next, js-yaml, nodemailer (they were exact-pinned, so an in-range update could not reach the fix).
package-lock.json: as above.
scripts/checks/no-new-antipatterns.mjs: PINNED_DEPS nodemailer 9.0.5 -> 9.1.1 with the reason updated. Without this, the pinned-dep guard in check:guards fails hard. The guard text asks for nodemailer bumps to be deliberate, reviewed PRs, so this is the explicit reviewed bump. Please review it on its own: nodemailer sits on the outbound-mail path (extensions/general/email/lib/smtp-service.ts). I diffed the published 9.0.5 and 9.1.1 tarballs; changes are security/bug fixes plus an opt-in maxRecipients option, no dependency changes.
Remaining finding (not fixed here, needs a decision)
nodemailer GHSA-v53p-9fqp-m79j (HIGH, addressparser quadratic backtracking DoS), plus GHSA-6vj9-mwq6-2f5v, GHSA-8vvx-rff5-p5rq, GHSA-g57g-f23g-4646 in npm audit. All are fixed only in nodemailer 10.x (trivy: 10.0.6, npm audit: 10.0.13). That is a major bump of a direct dependency, so it is out of scope for this lockfile PR. Suggested follow-up: a separate reviewed PR moving nodemailer to 10.x (mailparser already carries a nested nodemailer 10.0.10, which is not flagged) together with the PINNED_DEPS update.
npm audit also lists @babel/core <=7.29.0 (GHSA-4x5r-pxfx-6jf8), severity low, so below the HIGH/CRITICAL gate. Not touched.
Checks run locally
Node v26.10.0 / npm 11.19.1, on the branch head:
npm ci (frozen install): pass, lockfile unchanged afterwards.
npm run check:types: pass (533 errors, equal to the baseline of 533, no new).
npm run check:lint: pass (0, baseline 0).
npm run check:guards: pass (pinned-dep: 0); it failed before the PINNED_DEPS update.
npm run skills:check, taxonomy:check, apiskill:check, validate:packs, validate:registry: pass.
vitest run --project unit (full): started but stopped at my 10 minute cap, because the machine was at load average 30 to 54. About 22.3k tests had passed by then with no failures printed; it did not complete, so treat the full run as not verified locally (CI shards it 4 ways).
Targeted vitest runs over the code that uses the bumped packages: extensions/general/email/__tests__/smtp-service.test.ts (nodemailer), lib/packs (js-yaml), lib/invoices/__tests__/pdf-render-helpers.test.ts, lib/api/__tests__/content-disposition.test.ts, and the documents inline route test: 7 files, 95 tests, all pass.
trivy re-scan: 1 remaining finding (nodemailer, above), in both default and --include-dev-deps mode.
Not run: npm run build and the sharded test:pg / tool-pg projects (need Postgres). The Sonar job on main is red on a missing SONAR_TOKEN, unrelated and untouched.
## Summary
Lockfile-level fix for the HIGH/CRITICAL advisories that the estate CI (trivy) reports on `main` @ 23f99f9. Only vulnerable packages were touched; every bump stays inside its current major.
Scanner: `trivy fs --scanners vuln --severity HIGH,CRITICAL` (trivy 0.73.0, vuln DB updated 2026-09-30 01:15 UTC, used offline with `--skip-db-update`), run in default mode and with `--include-dev-deps`. Cross-checked with `npm audit --audit-level=high`.
Note: the advisories named in the estate alert for other repos (fast-uri CVE-2026-84292, @xhmikosr/decompress CVE-2026-101894) are not in this repo's lockfile. brace-expansion CVE-2026-102276 is present, as a dev-only transitive.
## Findings before -> after
| Package | Before | After | Advisory | Kind |
|---|---|---|---|---|
| next | 16.3.1 | 16.3.3 | CVE-2026-75604 / GHSA-2xp9-vwfh-vxw4 (CRITICAL) | direct, exact pin, patch |
| js-yaml | 4.3.1 | 4.3.2 | CVE-2026-84375 (HIGH) | direct, exact pin, patch |
| nodemailer | 9.0.5 | 9.1.1 | GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj (HIGH) | direct, exact pin, minor |
| sharp | 0.35.3 | 0.35.5 | GHSA-rgj7-g3m4-5g8c (HIGH) | direct + override, in range (`^0.35.3`), lockfile only |
| undici | 6.28.0 | 6.29.0 | CVE-2026-19534 (HIGH) | transitive via @ai-sdk/provider-utils (`^6.28.0`), lockfile only |
| brace-expansion | 1.1.18 / 2.1.4 | 1.1.21 / 2.1.7 | CVE-2026-102276, CVE-2026-102278 (HIGH) | dev-only transitive, lockfile only |
| minimatch | 9.0.5 (typescript-estree) | 9.0.9 | CVE-2026-26996, CVE-2026-27903, CVE-2026-27904 (HIGH) | dev-only transitive, lockfile only |
Trivy (default mode): 7 findings -> 1. Trivy (`--include-dev-deps`): 14 findings -> 1.
Companion lockfile movement that comes with the above and nothing else: sharp platform binaries and libvips (`@img/sharp-*` 0.35.5, `@img/sharp-libvips-*` 1.3.4), `@emnapi/runtime` 1.11.3, `@next/env` and `@next/swc-*` 16.3.3, and the nested `@eslint/eslintrc/node_modules/js-yaml` copy deduped into the top-level js-yaml.
## Files
- `package.json`: exact pins for next, js-yaml, nodemailer (they were exact-pinned, so an in-range update could not reach the fix).
- `package-lock.json`: as above.
- `scripts/checks/no-new-antipatterns.mjs`: `PINNED_DEPS` nodemailer 9.0.5 -> 9.1.1 with the reason updated. Without this, the `pinned-dep` guard in `check:guards` fails hard. The guard text asks for nodemailer bumps to be deliberate, reviewed PRs, so this is the explicit reviewed bump. Please review it on its own: nodemailer sits on the outbound-mail path (`extensions/general/email/lib/smtp-service.ts`). I diffed the published 9.0.5 and 9.1.1 tarballs; changes are security/bug fixes plus an opt-in `maxRecipients` option, no dependency changes.
## Remaining finding (not fixed here, needs a decision)
- **nodemailer GHSA-v53p-9fqp-m79j (HIGH, addressparser quadratic backtracking DoS)**, plus GHSA-6vj9-mwq6-2f5v, GHSA-8vvx-rff5-p5rq, GHSA-g57g-f23g-4646 in `npm audit`. All are fixed only in nodemailer 10.x (trivy: 10.0.6, npm audit: 10.0.13). That is a major bump of a direct dependency, so it is out of scope for this lockfile PR. Suggested follow-up: a separate reviewed PR moving nodemailer to 10.x (mailparser already carries a nested nodemailer 10.0.10, which is not flagged) together with the `PINNED_DEPS` update.
- `npm audit` also lists `@babel/core <=7.29.0` (GHSA-4x5r-pxfx-6jf8), severity low, so below the HIGH/CRITICAL gate. Not touched.
## Checks run locally
Node v26.10.0 / npm 11.19.1, on the branch head:
- `npm ci` (frozen install): pass, lockfile unchanged afterwards.
- `npm run check:types`: pass (533 errors, equal to the baseline of 533, no new).
- `npm run check:lint`: pass (0, baseline 0).
- `npm run check:guards`: pass (`pinned-dep: 0`); it failed before the `PINNED_DEPS` update.
- `npm run skills:check`, `taxonomy:check`, `apiskill:check`, `validate:packs`, `validate:registry`: pass.
- `vitest run --project unit` (full): started but stopped at my 10 minute cap, because the machine was at load average 30 to 54. About 22.3k tests had passed by then with no failures printed; it did not complete, so treat the full run as not verified locally (CI shards it 4 ways).
- Targeted vitest runs over the code that uses the bumped packages: `extensions/general/email/__tests__/smtp-service.test.ts` (nodemailer), `lib/packs` (js-yaml), `lib/invoices/__tests__/pdf-render-helpers.test.ts`, `lib/api/__tests__/content-disposition.test.ts`, and the documents inline route test: 7 files, 95 tests, all pass.
- trivy re-scan: 1 remaining finding (nodemailer, above), in both default and `--include-dev-deps` mode.
- `npm audit --audit-level=high`: 8 findings on main (1 low, 6 high, 1 critical) -> 2 (1 low, 1 high: nodemailer, above).
Not run: `npm run build` and the sharded `test:pg` / `tool-pg` projects (need Postgres). The Sonar job on main is red on a missing `SONAR_TOKEN`, unrelated and untouched.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Lockfile-level update of the packages trivy flags on main, all within
their current major:
- next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL)
- js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375)
- nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj)
- sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c)
- undici 6.28.0 -> 6.29.0 (CVE-2026-19534)
- brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev)
- minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev)
next, js-yaml and nodemailer were exact-pinned, so their pins move too.
PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without
it the pinned-dep guard fails.
Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major
bump of a direct dependency, left for a separate reviewed change).
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Remote code execution in next/og ImageResponse, fixed in 16.3.6.
Same minor line; the exact pin in package.json moves too and the
lockfile follows (next, @next/env, @next/swc-* platform binaries,
sharp optional range ^0.35.4).
Not fixed here (need a direct-dependency major bump or have no fix):
- nodemailer 9.1.1: GHSA-prgh-xp8r-p3m5 / GHSA-v53p-9fqp-m79j fixed only in 10.0.5/10.0.6 (major)
- xlsx 0.20.3: GHSA-4r6h-8v6p-xvw6 / GHSA-5pgg-2g8v-p4x9 have no published fix
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
OSV-svep (api.osv.dev) mot PR-grenen: before/after
Before (head 0250b4b): CRITICAL 1, HIGH 4
After (head ddc4cce): CRITICAL 0, HIGH 4
Fixat i ddc4cce (endast package.json + package-lock.json):
next 16.3.3 -> 16.3.6 (GHSA-vcvr-r3jv-pc5j, CRITICAL, RCE i next/og ImageResponse). Samma minor-linje, exakt pin flyttad. Lockfilen drog med @next/env, @next/swc-* och sharp-range ^0.35.4. 16.3.6 publicerades 2026-09-22 (> 7 dygn).
Kvarstår (ej fixbart inom reglerna):
nodemailer 9.1.1 (direkt dependency): GHSA-prgh-xp8r-p3m5 (fixed 10.0.5) och GHSA-v53p-9fqp-m79j (fixed 10.0.6), båda kräver major-bump till 10.x. Hela 9.x-serien är påverkad av v53p, så att gå tillbaka till 9.0.x ger ingen vinst.
xlsx 0.20.3 (direkt dependency, SheetJS CDN): GHSA-4r6h-8v6p-xvw6 och GHSA-5pgg-2g8v-p4x9, ingen publicerad fix.
npm test (vitest unit): 22336 passed, 3 failed med "timed out in 5000ms" under maskinlast ~30+; samma 3 filer kördes om isolerat: 13/13 passed
npm run build (next 16.3.6): "Compiled successfully" + TypeScript-steget klart, men "Collecting page data" hann inte klart inom tidsboxen (avbröts efter 560 s) — build är alltså INTE fullt verifierad
Ingen CI-workflow, test, lint-regel eller gate ändrad.
**OSV-svep (api.osv.dev) mot PR-grenen: before/after**
Before (head 0250b4b): CRITICAL 1, HIGH 4
After (head ddc4cce): CRITICAL 0, HIGH 4
Fixat i ddc4cce (endast `package.json` + `package-lock.json`):
- next 16.3.3 -> 16.3.6 (GHSA-vcvr-r3jv-pc5j, CRITICAL, RCE i next/og ImageResponse). Samma minor-linje, exakt pin flyttad. Lockfilen drog med @next/env, @next/swc-* och sharp-range ^0.35.4. 16.3.6 publicerades 2026-09-22 (> 7 dygn).
Kvarstår (ej fixbart inom reglerna):
- nodemailer 9.1.1 (direkt dependency): GHSA-prgh-xp8r-p3m5 (fixed 10.0.5) och GHSA-v53p-9fqp-m79j (fixed 10.0.6), båda kräver major-bump till 10.x. Hela 9.x-serien är påverkad av v53p, så att gå tillbaka till 9.0.x ger ingen vinst.
- xlsx 0.20.3 (direkt dependency, SheetJS CDN): GHSA-4r6h-8v6p-xvw6 och GHSA-5pgg-2g8v-p4x9, ingen publicerad fix.
Verifierat på ddc4cce:
- `npm ci` OK (frozen lockfile)
- `npm run check:guards` OK
- `npm run check:types` OK (533 fel, baseline 533)
- `npm run check:lint` OK (0 fel, baseline 0)
- `npm test` (vitest unit): 22336 passed, 3 failed med "timed out in 5000ms" under maskinlast ~30+; samma 3 filer kördes om isolerat: 13/13 passed
- `npm run build` (next 16.3.6): "Compiled successfully" + TypeScript-steget klart, men "Collecting page data" hann inte klart inom tidsboxen (avbröts efter 560 s) — build är alltså INTE fullt verifierad
Ingen CI-workflow, test, lint-regel eller gate ändrad.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Lockfile-level fix for the HIGH/CRITICAL advisories that the estate CI (trivy) reports on
main@23f99f9. Only vulnerable packages were touched; every bump stays inside its current major.Scanner:
trivy fs --scanners vuln --severity HIGH,CRITICAL(trivy 0.73.0, vuln DB updated 2026-09-30 01:15 UTC, used offline with--skip-db-update), run in default mode and with--include-dev-deps. Cross-checked withnpm audit --audit-level=high.Note: the advisories named in the estate alert for other repos (fast-uri CVE-2026-84292, @xhmikosr/decompress CVE-2026-101894) are not in this repo's lockfile. brace-expansion CVE-2026-102276 is present, as a dev-only transitive.
Findings before -> after
^0.35.3), lockfile only^6.28.0), lockfile onlyTrivy (default mode): 7 findings -> 1. Trivy (
--include-dev-deps): 14 findings -> 1.Companion lockfile movement that comes with the above and nothing else: sharp platform binaries and libvips (
@img/sharp-*0.35.5,@img/sharp-libvips-*1.3.4),@emnapi/runtime1.11.3,@next/envand@next/swc-*16.3.3, and the nested@eslint/eslintrc/node_modules/js-yamlcopy deduped into the top-level js-yaml.Files
package.json: exact pins for next, js-yaml, nodemailer (they were exact-pinned, so an in-range update could not reach the fix).package-lock.json: as above.scripts/checks/no-new-antipatterns.mjs:PINNED_DEPSnodemailer 9.0.5 -> 9.1.1 with the reason updated. Without this, thepinned-depguard incheck:guardsfails hard. The guard text asks for nodemailer bumps to be deliberate, reviewed PRs, so this is the explicit reviewed bump. Please review it on its own: nodemailer sits on the outbound-mail path (extensions/general/email/lib/smtp-service.ts). I diffed the published 9.0.5 and 9.1.1 tarballs; changes are security/bug fixes plus an opt-inmaxRecipientsoption, no dependency changes.Remaining finding (not fixed here, needs a decision)
npm audit. All are fixed only in nodemailer 10.x (trivy: 10.0.6, npm audit: 10.0.13). That is a major bump of a direct dependency, so it is out of scope for this lockfile PR. Suggested follow-up: a separate reviewed PR moving nodemailer to 10.x (mailparser already carries a nested nodemailer 10.0.10, which is not flagged) together with thePINNED_DEPSupdate.npm auditalso lists@babel/core <=7.29.0(GHSA-4x5r-pxfx-6jf8), severity low, so below the HIGH/CRITICAL gate. Not touched.Checks run locally
Node v26.10.0 / npm 11.19.1, on the branch head:
npm ci(frozen install): pass, lockfile unchanged afterwards.npm run check:types: pass (533 errors, equal to the baseline of 533, no new).npm run check:lint: pass (0, baseline 0).npm run check:guards: pass (pinned-dep: 0); it failed before thePINNED_DEPSupdate.npm run skills:check,taxonomy:check,apiskill:check,validate:packs,validate:registry: pass.vitest run --project unit(full): started but stopped at my 10 minute cap, because the machine was at load average 30 to 54. About 22.3k tests had passed by then with no failures printed; it did not complete, so treat the full run as not verified locally (CI shards it 4 ways).extensions/general/email/__tests__/smtp-service.test.ts(nodemailer),lib/packs(js-yaml),lib/invoices/__tests__/pdf-render-helpers.test.ts,lib/api/__tests__/content-disposition.test.ts, and the documents inline route test: 7 files, 95 tests, all pass.--include-dev-depsmode.npm audit --audit-level=high: 8 findings on main (1 low, 6 high, 1 critical) -> 2 (1 low, 1 high: nodemailer, above).Not run:
npm run buildand the shardedtest:pg/tool-pgprojects (need Postgres). The Sonar job on main is red on a missingSONAR_TOKEN, unrelated and untouched.🤖 Generated with Claude Code
OSV-svep (api.osv.dev) mot PR-grenen: before/after
Before (head
0250b4b): CRITICAL 1, HIGH 4After (head
ddc4cce): CRITICAL 0, HIGH 4Fixat i
ddc4cce(endastpackage.json+package-lock.json):Kvarstår (ej fixbart inom reglerna):
Verifierat på
ddc4cce:npm ciOK (frozen lockfile)npm run check:guardsOKnpm run check:typesOK (533 fel, baseline 533)npm run check:lintOK (0 fel, baseline 0)npm test(vitest unit): 22336 passed, 3 failed med "timed out in 5000ms" under maskinlast ~30+; samma 3 filer kördes om isolerat: 13/13 passednpm run build(next 16.3.6): "Compiled successfully" + TypeScript-steget klart, men "Collecting page data" hann inte klart inom tidsboxen (avbröts efter 560 s) — build är alltså INTE fullt verifieradIngen CI-workflow, test, lint-regel eller gate ändrad.
🤖 Generated with Claude Code
Approved via siax-bot (Simon decision: merge all)