@shopify/shopify_function@2.0.1 pulls vulnerable lodash chain via @graphql-codegen/cli@5.0.6 (Dependabot PR #87 already exists)
還沒有人認領這個 Issue。
評估
- 難度
- 1/5
- 預估耗時
- 1 小時以內
- 新手友好度
- 25/100
- Issue 類型
- 缺陷
- 描述清晰度
- 描述清楚
- 活躍度
- 停滯
- 技術堆疊
- node.js, typescript
研究方向
Start by reviewing Dependabot PR #87, which bumps @graphql-codegen/cli from 5.0.6 to 6.1.1, and compare it with the package dependency declaration. Run npm install and npm audit against the affected package; done means the lodash dependency chain and its reported advisories are cleared after the update is merged.
由索引模型根據 Issue 內容生成。
描述
Summary
@shopify/shopify_function@2.0.1 exact-pins @graphql-codegen/cli@5.0.6, which transitively pulls @graphql-codegen/plugin-helpers@5.1.1, which depends on lodash@~4.17.0. Newer versions of plugin-helpers (6.2.1+, released 2026-04-04) drop the lodash dependency entirely. Bumping @graphql-codegen/cli to a current 6.x or 7.x release transitively resolves all 13 lodash-chain advisories that consuming projects see in npm audit.
PR #87 (Bump @graphql-codegen/cli from 5.0.6 to 6.1.1) has been open since 2026-01-12 and would fix this. It just needs review and merge.
Reproduction
In any project that depends on @shopify/shopify_function@2.0.1 (e.g. a Shopify Function extension generated via shopify app generate extension):
npm install
npm audit
Output (captured 2026-05-08):
13 high severity vulnerabilities
npm ls lodash confirms the chain:
└─┬ @shopify/shopify_function@2.0.1
└─┬ @graphql-codegen/cli@5.0.6
├─┬ @graphql-codegen/plugin-helpers@5.1.1
│ └── lodash@4.17.23
├─┬ @graphql-tools/prisma-loader@8.0.17
│ └── lodash@4.17.23 deduped
└─┬ inquirer@8.2.7
└── lodash@4.17.23 deduped
npm audit flags both GHSA-r5fr-rjxr-66jc (CVSS 8.1, code injection via _.template) and GHSA-f23m-r3pf-42rh (CVSS 6.5, prototype pollution in _.unset / _.omit). All 13 advisories report fixAvailable: false because @shopify/shopify_function@2.0.1 is the latest published version and exact-pins the codegen versions, so consuming npm install cannot bump the chain on its own.
Why this is awkward to work around downstream
Consumers can apply an npm overrides block to force lodash: "^4.18.1", which we did in our project. But every consuming Shopify Function project has to repeat the workaround. And each Dependabot scan still re-flags the chain because the override is invisible to the advisory database walker.
Proposed fix
Merge PR #87 (Bump @graphql-codegen/cli from 5.0.6 to 6.1.1), or open a fresh PR bumping @graphql-codegen/cli to ^7.0.0.
Why this works:
@graphql-codegen/cli@6.1.1declares@graphql-codegen/plugin-helpers: "^6.1.0". Caret resolution floats to the latest 6.x, currently6.3.0, which dropped the lodash dependency.@graphql-codegen/cli@7.0.0declares@graphql-codegen/plugin-helpers: "^7.0.0", also lodash-free.
Either path fully clears the 13 lodash-chain advisories without further dependency edits.
Severity (honest)
The deployed Wasm function does not include lodash or any @graphql-codegen/* package, so this is not a runtime exploit. The risk is dev-time only: developer machines and CI runners load the vulnerable lodash code when running npx graphql-codegen or shopify app function typegen. The actual exploit primitives in both advisories (_.template injection, _.unset / _.omit prototype pollution) are not reached by plugin-helpers@5.1.1, which calls lodash/merge.js only. So the realistic risk is "noise in npm audit output and Dependabot triage burden across every consuming project," not "active CVE in production."
Filing this anyway because:
- The fix is one Dependabot PR merge. Mechanical, low risk.
- A 4-month-old open Dependabot PR (#87) shouldn't be the bottleneck.
- Every consuming extension currently has to apply the same
overridesworkaround.
Versions
@shopify/shopify_function@2.0.1(latest, published 2026-01-30)- npm 10.x
- Reproduced on macOS 14.x, Node.js 22.x
Related
- Issue #23 (closed 2025-01-31): same package, different transitive vuln (ws chain). Maintainer fixed it in 1.0.4 within 2 days. Citing here to confirm the issue template / response loop works.
- Open PRs already addressing this: #87 (cli), #86 (typescript), #85 (typescript-operations).
- 主要語言
- TypeScript
- 星號
- 35
- 分支
- 9
- PR 合併指標
- 30 天內沒有已合併 PR
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
Shopify/shopify-function-javascript 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 48/100
-
難度 4/5 3-5 天 新手友好度 45/100
Shopify/shopify-function-javascript#127 · 1 則留言 ·
查看 Shopify/shopify-function-javascript 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 70/100
-
難度 2/5 1-3 小時 新手友好度 75/100
mksglu/context-mode#1200 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
jaegertracing/jaeger-ui#4506 ·
-
area:desktop area:ui bug platform:macos
難度 2/5 1-3 小時 新手友好度 75/100
anthropics/claude-code#96687 ·
-
good first issue
難度 1/5 1 小時以內 新手友好度 95/100
AOSSIE-Org/DebateAI#582 · 2 則留言 ·