Skip to content

fix(deps): take multer 2.4.0 and ip-address 10.7.3 for moderate advisories - #516

Merged
bbertucc merged 1 commit into
mainfrom
fix/moderate-advisories
Oct 6, 2026
Merged

bbertucc merged 1 commit into
mainfrom
fix/moderate-advisories

Conversation

@bbertucc

@bbertucc bbertucc commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Iris Maintainer Agent here.

Follow-up to #515: its review found two moderate advisories that the nightly scan doesn't block on. The scan only fails on high or critical. The owner asked for this directly.

  • multer 2.3.0 → 2.4.0: a DoS through orphaned disk writes on aborted uploads. Iris keeps uploads in memory (multer.memoryStorage()), so this advisory never reached it. This update clears npm audit and drops six packages.
  • ip-address 10.5.0 → 10.7.3: gaps in its SSRF classifiers. It comes in through express-rate-limit.

Both fixes are within the existing ranges, so only package-lock.json changes. multer 2.4.0 no longer depends on concat-stream, so six packages leave the lockfile: concat-stream, buffer-from, readable-stream, string_decoder, typedarray and util-deprecate.

npm audit now reports 0 vulnerabilities. npm test and bash test/e2e.sh pass, and e2e covers uploads.

🤖 Generated with Claude Code

…ories

npm audit reported two moderate advisories after #515:
- multer 2.3.0: DoS through orphaned disk writes on aborted uploads.
  Iris's upload path uses multer.
- ip-address 10.5.0 (via express-rate-limit): SSRF classifier gaps.

Both fixes are in the existing ranges, so this is a lockfile-only update.
multer 2.4.0 no longer needs concat-stream, so six packages leave the
lockfile. npm audit now reports 0 vulnerabilities.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile-only change; all six checks in the summary pass. I verified the parts a lockfile edit can get wrong:

  • Removal is complete and consistent. Nothing in src/, test/, .github/ or package.json references concat-stream, buffer-from, readable-stream, string_decoder, typedarray or util-deprecate. A reachability walk over package-lock.json from the root entry reports 0 unresolvable transitive deps and 0 orphaned entries across 210 packages, so no surviving package is left pointing at a tree node that this PR deleted.
  • Ranges still hold. "multer": "^2.1.1" (package.json:31) admits 2.4.0, and express-rate-limit@8.6.2's "ip-address": "^10.2.0" (package-lock.json:1660) admits 10.7.3. The installed multer@2.4.0 declares exactly the three deps the new lock entry lists (append-field, busboy, type-is), so the concat-stream drop is the package's own change, not a hand-edit of the lock.
  • The upload path's contract is unchanged. src/routes/sessions.ts:64 uses multer.memoryStorage(), and 2.4.0's memory engine still calls back with { buffer, size }, which is what req.files[].buffer downstream needs. Both packages stay MIT, and no runtime dependency is added.

Non-blocking notes

  • The PR body says the multer advisory is "a DoS through orphaned disk writes on aborted uploads" and then that "Iris's upload path uses multer." Both sentences are true separately, but read together they overstate the exposure: Iris configures multer.memoryStorage() (src/routes/sessions.ts:64) and never diskStorage, so a disk-write advisory does not reach this deployment. The bump is still worth taking to clear npm audit, and the concat-stream removal is a genuine six-package reduction in footprint — just not a fix for something Iris was running into. (I did not independently check the advisory text, so this note rests on the body's own description of it.)

Accessibility impact: none — no source, agent prompt, or output-path code changes, and the e2e suite that guards @source provenance and the content-disposition filename still passes.

@bbertucc
bbertucc merged commit 319f2aa into main Oct 6, 2026
7 checks passed
@bbertucc
bbertucc deleted the fix/moderate-advisories branch October 6, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant