chore(deps): update dependency uuid to v11 [security] - #139
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #139 +/- ##
=======================================
Coverage 97.15% 97.15%
=======================================
Files 19 19
Lines 1197 1197
Branches 309 309
=======================================
Hits 1163 1163
Misses 34 34 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
e4ffd35 to
a17dd64
Compare
a17dd64 to
5ab956f
Compare
5ab956f to
da964f1
Compare
da964f1 to
a297e5b
Compare
a297e5b to
44fa4cd
Compare
44fa4cd to
6a493fa
Compare
6a493fa to
c2bf3a5
Compare
c2bf3a5 to
ceaec34
Compare
ceaec34 to
762cec9
Compare
f5f689a to
7a28a08
Compare
7a28a08 to
0bf81e4
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
0bf81e4 to
0d8fc50
Compare
0d8fc50 to
a0ad6ef
Compare
|
Closing in favor of #143, which removes the uuid dependency entirely by using Node's built-in crypto.randomUUID(). |
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
The uuid package was a devDependency only used to generate temp file names in tests. Node's built-in crypto.randomUUID() covers this since Node 14.17 and the package requires Node >= 18, so this drops the dependency entirely. This also resolves the CVE-2026-41907 advisory flagged by Renovate, making #139 obsolete. Verified with npm run lint and npm run test:js (171 passing, 3 pending). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Removed the unused UUID development dependency. * Updated temporary test file and directory generation to use Node.js’s built-in UUID support. * **Tests** * Preserved existing archive, extraction, streaming, and security test behavior while improving temporary path isolation. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
[skip ci] ## <small>2.1.2 (2026-08-05)</small> * test: use node:crypto randomUUID instead of uuid dependency (#143) ([c0d269f](c0d269f)), closes [#143](#143) [#139](#139) * ci: add Node.js 26 to the test matrix (#141) ([5c725e6](5c725e6)), closes [#141](#141) [#140](#140) * fix: resolve symlink chains fully when extracting (#140) ([72a3c84](72a3c84)), closes [#140](#140)
This PR contains the following updates:
^3.0.1→^11.1.1uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41907 / GHSA-w5hq-g745-h8pq
More information
Details
Summary
The
v3(),v5(), andv6()API methods (notuuidrelease versions) accept external output buffers but do not reject out-of-range writes (smallbufor largeoffset).By contrast,
v4(),v1(), andv7()API methods explicitly throwRangeErroron invalid bounds.This inconsistency allows silent partial writes into caller-provided buffers.
Affected code
src/v35.ts(v3()/v5()path) writesbuf[offset + i]without bounds validation.src/v6.tswritesbuf[offset + i]without bounds validation.Reproducible PoC
Observed:
v4() THREW RangeErrorv5() NO_THROWv6() NO_THROWExample partial overwrite evidence captured during audit:
Security impact
Suggested fix
Add the same guard used by
v4()/v1()/v7():Apply to:
src/v35.ts(coversv3()andv5())src/v6.tsSeverity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
uuidjs/uuid (uuid)
v11.1.1Compare Source
Bug Fixes
v11.1.0Compare Source
Features
Uint8Arraysubtypes forbufferoption (#865) (a5231e7)v11.0.5Compare Source
Bug Fixes
v11.0.4Compare Source
Bug Fixes
v1(),v4(), andv7()(#845) (e0ee900)v11.0.3Compare Source
Bug Fixes
v11.0.2Compare Source
Bug Fixes
v11.0.1Compare Source
Bug Fixes
v11.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
v10.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
v9.0.1Compare Source
build
v9.0.0Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.3.2Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.3.1Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.3.0Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.2.0Compare Source
Features
Bug Fixes
v8.1.0Compare Source
Features
Bug Fixes
v8.0.0Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.3Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.2Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.1Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.0Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v3.4.0Compare Source
Features
v3.3.3Compare Source
Bug Fixes
v3.3.2Compare Source
Bug Fixes
v3.3.0Compare Source
Bug Fixes
Features
3.2.1 (2018-01-16)
Bug Fixes
v3.2.1Compare Source
Bug Fixes
Features
3.2.1 (2018-01-16)
Bug Fixes
v3.2.0Compare Source
Bug Fixes
Features
3.2.1 (2018-01-16)
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.