Bump vulnerable dependencies flagged by ECR image scanning (#23813)

## Context

The Oneleet monitor **"AWS ECR repository image vulnerabilities are
remediated"** is alerting on `prod-twenty` images: 1 CRITICAL + 6 HIGH
advisories breach their SLA in 7 days, plus a set of MEDIUMs. All of
them are npm packages baked into the image.

## Changes

| Package | Before | After | How | Advisories |
|---|---|---|---|---|
| undici | 7.28.0 / 6.27.0 | 8.9.0 | jsdom `^30` bump + node-gyp
refresh; global `undici: ^8.9.0` resolution for
@module-federation/dts-plugin, e2b and miniflare, which still pin 7.28.0
at latest (replaces the old scoped dts-plugin resolution) |
CVE-2026-13697 (critical), CVE-2026-14643, CVE-2026-15157/16728/16729 |
| sharp | 0.34.5 | 0.35.3 | direct bump in twenty-sdk; @argos-ci
refresh; `next/sharp` resolution (next 16.3.0 with the fix is still
quarantined by yarn's minimal-age gate) | GHSA-f88m-g3jw-g9cj |
| axios | 1.17.0 | 1.19.0 | lockfile refresh | GHSA-gcfj-64vw-6mp9 + 10
medium |
| ip-address | 10.2.0 | 10.4.0 | lockfile refresh | CVE-2026-69192,
CVE-2026-54272, CVE-2026-69198 |
| brace-expansion | 2.1.2 | 2.1.4 | lockfile refresh (backport exists;
Inspector only lists 5.x) | CVE-2026-69152, CVE-2026-14257,
CVE-2026-13149 |
| typeorm | 0.3.29 | 0.3.31 | pin bump; the local yarn patch applies
unchanged | GHSA-2rp8-mm9q-fp49 |

## Validation

- `yarn.lock` contains no remaining vulnerable versions (undici resolves
only to 8.9.0)
- `yarn npm audit`: no remaining advisories among the bumped packages
- `nx build` green for twenty-server, twenty-front (exercises
module-federation dts-plugin on undici 8), twenty-sdk, twenty-website;
twenty-server typecheck green (typeorm patch is type-level)
- Runtime smoke: jsdom 30 DOM parse, sharp 0.35.3 png encode, undici
8.9.0 load

## Not covered

- **react-router / react-router-dom 6.30.4** (medium, 1–3 month SLA):
react-router-dom 6.x has **no fixed release**; the fix is the v7
migration (~225 files) — separate effort.
- `prod-business-dash` body-parser 2.2.2 → 2.3.0 lives in its own repo.

<!-- This is an auto-generated description by cubic. -->
<a
href="https://cubic.dev/pr/twentyhq/twenty/pull/23813?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>
<!-- End of auto-generated description by cubic. -->
This commit is contained in:
Charles Bochet
2026-08-05 16:42:43 +02:00
committed by GitHub
parent 198ffbb6bd
commit 6e30405489
5 changed files with 903 additions and 467 deletions
+5 -2
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -81,7 +81,7 @@
"react": "^19.2.0",
"react-dom": "^19.2.0",
"semver": "7.6.3",
"sharp": "^0.34.5",
"sharp": "^0.35.3",
"tinyglobby": "^0.2.15",
"twenty-client-sdk": "workspace:*",
"typescript": "^5.9.3",
+2 -2
View File
@@ -120,7 +120,7 @@
"ical-generator": "^11.0.0",
"imapflow": "1.4.2",
"ioredis": "5.10.1",
"jsdom": "^29.1.1",
"jsdom": "^30.0.1",
"json-schema": "0.4.0",
"jsonwebtoken": "9.0.2",
"libphonenumber-js": "1.11.5",
@@ -171,7 +171,7 @@
"tsdav": "^2.2.0",
"tslib": "2.8.1",
"type-fest": "4.10.1",
"typeorm": "patch:typeorm@0.3.29#./patches/typeorm+0.3.29.patch",
"typeorm": "patch:typeorm@0.3.31#./patches/typeorm+0.3.31.patch",
"unzipper": "^0.12.3",
"uuid": "^11.1.1",
"zod": "^4.1.11"
+895 -462
View File
File diff suppressed because it is too large Load Diff