Skip to content

Chore: ip-address vulnerability fix - #183

Draft
rojasTob wants to merge 1 commit into
mainfrom
chore/ip-address-vulnerability
Draft

rojasTob wants to merge 1 commit into
mainfrom
chore/ip-address-vulnerability

Conversation

@rojasTob

@rojasTob rojasTob commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

This PR fixes the high severity issue #146 (GHSA-mwp4-54f8-5fhr) in ip-address <= 10.3.0.

ip-address is not a direct dependency. The vulnerable ip-address@9.0.5 was pulled in through @assertive-ts/native dev tooling:

react-native-testing-mocks → rewiremock → node-libs-browser → crypto-browserify → … → evp_bytestokey
  → node-gyp@10.0.1 → make-fetch-happen@13 → @npmcli/agent@2 → socks-proxy-agent@8.0.2
    → socks@2.8.0 → ip-address@9.0.5

Changes:

  • Add a socks: ^2.8.3 resolution in the root package.json, so socks@2.8.0 becomes socks@2.8.9, which depends on the patched ip-address@10.5.0.
  • yarn.lock drops ip-address@9.0.5, socks@2.8.0, jsbn@1.1.0 and sprintf-js@1.1.3.

I resolved socks instead of forcing ip-address because socks@2.8.0 was written against the ip-address 9.x API.

Verified locally: yarn build, yarn check and yarn test pass.

🤖 Generated with Claude Code

Add a `socks` resolution (^2.8.3) so the transitive `socks@2.8.0` is
replaced by `socks@2.8.9`, which depends on patched `ip-address@10.x`
instead of vulnerable `ip-address@9.0.5` (GHSA-mwp4-54f8-5fhr).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@rojasTob rojasTob self-assigned this Oct 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant