Dependabot reports one open HIGH severity alert on main (alert 161).
- Package:
adm-zip
- Installed:
0.5.18 (package-lock.json)
- Vulnerable range:
< 0.6.0
- First patched:
0.6.0
- Source: transitive —
dcmjs declares "adm-zip": "^0.5.10", so it is not a direct dependency and cannot be bumped by updating our own package.json alone.
Options
- Wait for / request an upstream
dcmjs release that relaxes the adm-zip constraint to ^0.6.0.
- Force the resolution locally with an npm
overrides entry, then verify the upload flow still works (dcmjs is used by the client-side upload/anonymisation path).
Option 2 unblocks us immediately but pins a version dcmjs has not tested against, so the upload path should be exercised before it ships.
Exposure
dcmjs runs client-side in the upload app. Whether the vulnerable adm-zip code path is actually reachable from our usage should be confirmed before deciding urgency — the alert is on the dependency, not on a demonstrated exploit path here.
Dependabot reports one open HIGH severity alert on
main(alert 161).adm-zip0.5.18(package-lock.json)< 0.6.00.6.0dcmjsdeclares"adm-zip": "^0.5.10", so it is not a direct dependency and cannot be bumped by updating our ownpackage.jsonalone.Options
dcmjsrelease that relaxes theadm-zipconstraint to^0.6.0.overridesentry, then verify the upload flow still works (dcmjsis used by the client-side upload/anonymisation path).Option 2 unblocks us immediately but pins a version
dcmjshas not tested against, so the upload path should be exercised before it ships.Exposure
dcmjsruns client-side in the upload app. Whether the vulnerableadm-zipcode path is actually reachable from our usage should be confirmed before deciding urgency — the alert is on the dependency, not on a demonstrated exploit path here.