From f300935de1e8269b0ece647d12f5262645513c64 Mon Sep 17 00:00:00 2001 From: Blake Bertuccelli-Booth <46652+bbertucc@users.noreply.github.com> Date: Tue, 6 Oct 2026 09:56:12 -0400 Subject: [PATCH] fix(deps): take proxy-addr 2.0.8 for CVE-2026-90711 (#514) The nightly image scan found CVE-2026-90711 (critical) in proxy-addr 2.0.7, which express 4.22.2 pulls in. 2.0.8 fixes it and is in express's range, so this is a lockfile-only update. Co-Authored-By: Claude Opus 5.5 --- package-lock.json | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9840c9c..1ee8c0c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -2231,9 +2231,9 @@ "license": "MIT" }, "node_modules/proxy-addr": { - "version": "2.0.7", - "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz", - "integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==", + "version": "2.0.8", + "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.8.tgz", + "integrity": "sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==", "license": "MIT", "dependencies": { "forwarded": "0.2.0", @@ -2241,6 +2241,10 @@ }, "engines": { "node": ">= 0.10" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/express" } }, "node_modules/punycode": {