Skip to content

fix: upgrade semver to patched version (CVE-2022-25883) - #1156

Open
anupamme wants to merge 1 commit into
vtex-apps:masterfrom
anupamme:fix-repo-store-components-cve-2022-25883-semver
Open

anupamme wants to merge 1 commit into
vtex-apps:masterfrom
anupamme:fix-repo-store-components-cve-2022-25883-semver

Conversation

@anupamme

@anupamme anupamme commented Sep 9, 2026

Copy link
Copy Markdown

Summary

Upgrade semver from 7.3.7 to 7.5.2, 6.3.1, 5.7.2 to fix CVE-2022-25883.

Vulnerability

Field Value
ID CVE-2022-25883
Severity HIGH
Scanner trivy
Rule CVE-2022-25883
File react/yarn.lock (dependency: semver)
Assessment Present in dependency tree, not confirmed reachable

Description: nodejs-semver: Regular expression denial of service

Evidence

Scanner confirmation: trivy rule CVE-2022-25883 flagged this pattern.

Changes

  • react/package.json

Behavior Preservation

This change touches only dependency manifest (react/package.json); no source file in the repository is modified.


This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.


Automated security fix by OrbisAI Security

Automated dependency upgrade by OrbisAI Security
@anupamme
anupamme requested a review from a team as a code owner September 9, 2026 19:42
@vtex-io-ci-cd

vtex-io-ci-cd Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Hi! I'm VTEX IO CI/CD Bot and I'll be helping you to publish your app! 🤖

Please select which version do you want to release:

  • Patch (backwards-compatible bug fixes)

  • Minor (backwards-compatible functionality)

  • Major (incompatible API changes)

And then you just need to merge your PR when you are ready! There is no need to create a release commit/tag.

  • No thanks, I would rather do it manually 😞

@vtex-io-docs-bot

Copy link
Copy Markdown

Beep boop 🤖

I noticed you didn't make any changes at the docs/ folder

  • There's nothing new to document 🤔
  • I'll do it later 😞

In order to keep track, I'll create an issue if you decide now is not a good time

  • I just updated 🎉🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant