Repository navigation
chore(deps): bump @nestjs/platform-express from 12.0.1 to 12.0.3 - #364
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@nestjs/platform-express](https://github.com/nestjs/nest/tree/HEAD/packages/platform-express) from 12.0.1 to 12.0.3. - [Release notes](https://github.com/nestjs/nest/releases) - [Commits](https://github.com/nestjs/nest/commits/v12.0.3/packages/platform-express) --- updated-dependencies: - dependency-name: "@nestjs/platform-express" dependency-version: 12.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
clestons
left a comment
There was a problem hiding this comment.
Verdict: REQUEST_CHANGES
Dependabot bump: @nestjs/platform-express ^12.0.1 → ^12.0.3. Build and full test suite (40 suites, 526 tests) pass clean on PR head. The diff's lockfile hunk shows multer moving from 2.2.0 to 2.4.0 inside platform-express's own dependency metadata, which reads like it finally clears the known audit debt (multer <=2.2.0, High, 4 CVEs — the long-standing root cause of this repo's merge freeze, per project history). It doesn't — and I traced exactly why.
Blocking
package.json's overrides block hard-pins "multer": "2.2.0", silently defeating this bump. npm ci/npm install on this PR's actual lockfile still resolves node_modules/multer to 2.2.0 — confirmed by reading the installed node_modules/multer/package.json directly, not just the diff. npm audit on PR head:
multer <=2.2.0 — Severity: high (4 advisories, incl. DoS via crafted multipart field names)
2 high severity vulnerabilities
I verified the actual fix and it's a one-line change: editing package.json's overrides.multer from "2.2.0" to "2.4.0" (in a scratch copy of this worktree, then discarded — not committed anywhere), running npm install, and re-auditing:
found 0 vulnerabilities
So the real fix isn't "bump platform-express" (this PR) — it's also updating the overrides.multer pin in the same PR, or removing it if it was only ever there to force a version that's no longer needed. This Dependabot PR alone ships green CI and a clean-looking lockfile diff while leaving the actual vulnerable package installed, because the override reasserts 2.2.0 after resolution regardless of what any dependency asks for. This is very likely also why npm audit fix "doesn't fix it" — it would try to bump multer and the override would just pin it back down.
Recommended fix, in this PR or a fast follow-up: bump overrides.multer to 2.4.0+ alongside this dependency change, then confirm npm audit reports 0 vulnerabilities (not just that CI is green — CI doesn't gate on npm audit here).
Verified, not just read
- Installed on PR head, confirmed
node_modules/multerresolves to2.2.0despite the lockfile's nesteddependencies.multer: "2.4.0"entry under@nestjs/platform-express. - Traced the cause to
package.json'soverridesblock, not a lockfile bug or an npm resolution quirk. - Reproduced the fix in an isolated scratch copy: corrected the override, reinstalled,
npm audit→ 0 vulnerabilities. Discarded the change afterward (git checkout -- package.json package-lock.json, confirmedgit status --porcelainempty) — this PR's own diff is unmodified. npm run buildandnpm testboth pass clean on the actual, unmodified PR head (40/40 suites, 526/526 tests).
[2-round] R1a/R1b: both read the diff as a clean fix (neither runs npm install/npm audit, so neither could see the override defeating it) — this is exactly the kind of gap only running the actual install catches.
Self-assessment
- DeepSeek 0/2 useful on the real finding (both assumed the lockfile diff meant multer was actually patched; R1b even flagged it as worth checking "verify multer 2.4.0 changelog" without realizing 2.4.0 never actually gets installed).
- Given dvt's B6 merge freeze is specifically about this audit debt, this is a high-value finding: the concrete, verified fix (bump the override, not just the direct dependency) can plausibly end the freeze once applied.
clestons
left a comment
There was a problem hiding this comment.
PR Review — #364
变更:@nestjs/platform-express 12.0.1 → 12.0.3 (devDependency),仅 package.json/package-lock.json 版本号改动,无源码/逻辑/API 变更。
R1 (DeepSeek, 2-round):无 finding。api_compat unchanged,无并发/状态/安全面改动。
CI:Build / Code Quality / CodeQL / Smart Contracts / Tests / Type Check / cla-check 全绿。Security Audit / CI Success 失败 — 这是仓库级预存问题(multer 2.2.0 npm audit 欠账,见 B6 阻塞记录),与本次版本号改动无关,不构成本 PR 的阻塞项。
结论:APPROVE。代码可以合,但本仓库当前处于 B6 零合并冻结期,实际合并需等待冻结解除。
Bumps @nestjs/platform-express from 12.0.1 to 12.0.3.
Release notes
Sourced from @nestjs/platform-express's releases.
... (truncated)
Commits
1415179chore(release): publish v12.0.3 release873e8d9fix(deps): update dependency multer to v2.4.0 (#17762)ee168a5chore(release): publish v12.0.2 releaseab64da7fix(express): normalize error and not-found prefixes (#17648)1eeccd3fix(deps): update dependency multer to v2.3.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)