Skip to content

fix: dependency security vulnerabilities (DELO-6206, DELO-6187, DELO-6185, DELO-6184, DELO-6183, DELO-6182, DELO-6181, DELO-6179, DELO-6178, DELO-6177, DELO-6176, DELO-6175, DELO-6174, DELO-6173)#219

Merged
lukaszczerpak-cloudinary merged 2 commits into
masterfrom
DELO-6206/security-fixes
May 26, 2026
Merged

Conversation

@ikrascloudinary
Copy link
Copy Markdown
Contributor

Summary

Vulnerabilities resolved

  • @opentelemetry/exporter-prometheus: 0.57.20.218.0 (minimum required: 0.217.0, from DELO-6206)
  • qs: 6.14.2 / 6.15.16.15.2 (minimum required: 6.15.2, from DELO-6187)
  • protobufjs: 7.5.57.6.1 (minimum required: 7.5.8 from DELO-6185; 7.5.6 from DELO-6184, DELO-6183, DELO-6182, DELO-6179, DELO-6176, DELO-6175, DELO-6174, DELO-6173)
  • @protobufjs/utf8: 1.1.01.1.1 (minimum required: 1.1.1, from DELO-6181, DELO-6178)
  • @protobufjs/codegen: 2.0.42.0.5 (minimum required: 2.0.5, from DELO-6177)

Dependencies updated

  • @opentelemetry/exporter-prometheus: ^0.57.2^0.218.0
  • @opentelemetry/instrumentation-express: ^0.49.0^0.66.0
  • @opentelemetry/instrumentation-http: ^0.57.2^0.218.0
  • @opentelemetry/resources: ^1.30.1^2.7.1
  • @opentelemetry/sdk-node: ^0.57.2^0.218.0
  • @opentelemetry/sdk-trace-base: ^1.30.1^2.7.1
  • @opentelemetry/semantic-conventions: ^1.40.0^1.41.1
  • @opentelemetry/instrumentation: added as direct dep (^0.218.0) — was previously only transitive; instrumentation.js imports registerInstrumentations from it
  • mocha: ^11.7.5^11.7.6
  • nock: ^14.0.13^14.0.15

Code changes

  • instrumentation.js: migrated from new Resource({...}) to resourceFromAttributes({...}) — required by the OpenTelemetry JS 2.x Resource API change pulled in by exporter-prometheus 0.218.0.

Overrides

  • None added — all transitive vulnerabilities were resolved by upgrading the parent direct dependencies. There were no pre-existing overrides/resolutions to restore.

Chrome/chromedriver

  • N/A — this project does not install Chrome/chromedriver.

Package version

  • 1.3.111.3.12

Test results

  • Validation suite passed: 13 passing, no hard crashes or module errors.
  • OpenTelemetry SDK boot smoke-tested successfully with the v2 Resource API.

Test plan

  • Validation test suite passes (npm test)
  • App boots cleanly with node --require ./instrumentation.js start.js (Prometheus exporter on :6060)

…O-6181, DELO-6179, DELO-6178, DELO-6177, DELO-6176, DELO-6175, DELO-6174, DELO-6173: fix dependency security vulnerabilities

Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
@lukaszczerpak-cloudinary lukaszczerpak-cloudinary changed the title DELO-6206, DELO-6187, DELO-6185, DELO-6184, DELO-6183, DELO-6182, DELO-6181, DELO-6179, DELO-6178, DELO-6177, DELO-6176, DELO-6175, DELO-6174, DELO-6173: fix dependency security vulnerabilities fix dependency security vulnerabilities (DELO-6206, DELO-6187, DELO-6185, DELO-6184, DELO-6183, DELO-6182, DELO-6181, DELO-6179, DELO-6178, DELO-6177, DELO-6176, DELO-6175, DELO-6174, DELO-6173) May 26, 2026
Copy link
Copy Markdown
Contributor

@lukaszczerpak-cloudinary lukaszczerpak-cloudinary left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good

@lukaszczerpak-cloudinary lukaszczerpak-cloudinary changed the title fix dependency security vulnerabilities (DELO-6206, DELO-6187, DELO-6185, DELO-6184, DELO-6183, DELO-6182, DELO-6181, DELO-6179, DELO-6178, DELO-6177, DELO-6176, DELO-6175, DELO-6174, DELO-6173) fix: dependency security vulnerabilities (DELO-6206, DELO-6187, DELO-6185, DELO-6184, DELO-6183, DELO-6182, DELO-6181, DELO-6179, DELO-6178, DELO-6177, DELO-6176, DELO-6175, DELO-6174, DELO-6173) May 26, 2026
@lukaszczerpak-cloudinary lukaszczerpak-cloudinary merged commit 76c2257 into master May 26, 2026
4 checks passed
@lukaszczerpak-cloudinary lukaszczerpak-cloudinary deleted the DELO-6206/security-fixes branch May 26, 2026 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants