Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security/fix UI vulnerabilities issue 4 - #3089

Open
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4
Open

Security/fix UI vulnerabilities issue 4#3089
swar00pduthks wants to merge 4 commits into
MarquezProject:mainfrom
swar00pduthks:security/fix-ui-vulnerabilities-issue-4

Conversation

@swar00pduthks

Copy link
Copy Markdown

Problem

This PR addresses security vulnerabilities identified in GitHub issue #4. The web UI dependencies contained 7 critical CVEs that needed to be resolved:

  • CVE-2024-21536 - http-proxy-middleware vulnerable to denial of service
  • CVE-2024-4067 - micromatch Regular Expression Denial of Service (ReDoS)
  • CVE-2024-45590 - body-parser denial of service vulnerability
  • CVE-2025-27789 - @babel/runtime and @babel/helpers prototype pollution
  • CVE-2024-55565 - nanoid predictable IDs (already mitigated in current version)
  • CVE-2021-3803 - nth-check inefficient regular expression complexity

Additionally, the project had missing peer dependencies that prevented successful builds.

Closes: #3040

Solution

Security Updates:

  • Updated http-proxy-middleware from 2.0.6 to 3.0.3
  • Updated micromatch to 4.0.8 via npm overrides
  • Updated body-parser to 1.20.3 via npm overrides
  • Updated @babel/runtime and @babel/helpers to 7.26.0 via npm overrides
  • Added overrides for 8 additional high-severity vulnerabilities: form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send

Build Fixes:

  • Added missing peer dependencies: @chakra-ui/react@^2, history@^5, framer-motion@^10
  • Fixed keyframes import in graph components to use @emotion/react instead of @chakra-ui/react
  • Installed graph workspace dependencies

Results:

  • Reduced total vulnerabilities from 38 to 30 (8 vulnerabilities resolved)
  • All 7 CVEs from issue Update pkg and job ownership field #4 are now resolved
  • Build passes successfully with 0 errors (only compatibility warnings remain)

One-line summary:
fix: resolve security vulnerabilities in UI dependencies (CVEs: 2024-21536, 2024-4067, 2024-45590, 2025-27789)

Checklist

  • You've signed-off your work
  • Your changes are accompanied by tests (if relevant) - N/A: dependency updates only
  • Your change contains a small diff and is self-contained
  • You've updated any relevant documentation (if relevant) - N/A: no documentation changes needed
  • You've included a one-line summary of your change for the CHANGELOG.md
  • You've versioned your .sql database schema migration according to Flyway's naming convention - N/A: no database changes
  • You've included a header in any source code files (if relevant) - N/A: only modified imports

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: Swaroop <swaroop@example.com>
Signed-off-by: Swaroop <swaroop@example.com>
@codecov

codecovBot commented Jan 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.18%. Comparing base (a89b89c) to head (9eb38d6).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #3089 +/- ##
=========================================
Coverage 81.18% 81.18% Complexity 1506 1506 =========================================
Files 268 268 Lines 7356 7356 Branches 325 325 =========================================
Hits 5972 5972 Misses 1226 1226 Partials 158 158 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Updated http-proxy-middleware from 2.0.6 to 3.0.3 (CVE-2024-21536)
- Updated micromatch to 4.0.8 (CVE-2024-4067)
- Updated body-parser to 1.20.3 (CVE-2024-45590)
- Updated @babel/runtime and @babel/helpers to 7.26.0 (CVE-2025-27789)
- Added overrides for form-data, @remix-run/router, cross-spawn, node-forge, path-to-regexp, qs, rollup, send
- Added missing dependencies: @chakra-ui/react, history, framer-motion
- Fixed keyframes import in graph components (use @emotion/react)
ResolvesMarquezProject#3040
Signed-off-by: swar00pduthks <swaroopduthks@gmail.com>
@merobi-hub

Copy link
Copy Markdown
Collaborator

@swar00pduthks thank you for this! Can you sign off to clear the failing DCO check? Also, let's wait for #3095 because there are some upgrades in it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities Fixes

2 participants

@swar00pduthks@merobi-hub