Skip to content

fix(security): exclude vulnerable undici releases - #3941

Open
fro-bot wants to merge 1 commit into
mainfrom
fix/security-undici-8.10.2-36670935566
Open

fro-bot wants to merge 1 commit into
mainfrom
fix/security-undici-8.10.2-36670935566

Conversation

@fro-bot

@fro-bot fro-bot commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Security remediation

Raise the existing undici override floor to >=8.10.2 and resolve the lockfile to the first patched 8.x release, 8.10.2 (previously 8.10.0). Only pnpm-workspace.yaml and pnpm-lock.yaml change.

Confirmed high advisories:

Sources: GitHub Advisory Database/Dependabot and npm advisory audit; npm registry pnpm view undici@8.10.2 supplied the version and integrity. This is a same-major patch remediation; major drift was not surveyed. The consumer is eslint-plugin-node-dependencies (development dependency). The floor comment records when it can be removed.

Verification

  • pnpm bootstrap, pnpm check-types, pnpm test: passed (88 files, 4,079 tests passed, 3 todo).
  • pnpm exec eslint, pnpm check:solutions-examples, Markdown-link gate, git diff --check: passed.
  • Audit: zero remaining high undici advisories.
  • pnpm lint: blocked only by two independently confirmed high brace-expansion advisories already present on main. They require a separate dedicated security PR; no thresholds or checks are weakened.

Remaining risk: development-only dependency exposure is reduced, but both independent security fixes must land for the repository-wide lint gate to pass. Automated review helper/reference access was denied by the CI tool policy; no automated review verdict is claimed.

@fro-bot

fro-bot commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

Remediation pass — 2026-10-01

The existing security fixes are mutually blocked by the repository-wide advisory gate. No safe, policy-compliant additional repair was identified. This pass made no commits or pushes and opened no duplicate PRs/issues; main remains clean at b96b990.

Errored PRs

The only open PRs are trusted, same-repository security PRs #3941 and #3942, both mergeable. Inspected gh pr checks, paginated check-run records, legacy commit statuses, and failed logs:

PR Failing check Root cause Legacy statuses
#3941 Lint Its inherited brace-expansion >=5.0.9 floor admits two high advisories addressed by #3942. Security: Private Leak Scan: success
#3942 Lint Its inherited undici >=8.9.0 floor admits three high advisories addressed by #3941. Security: Private Leak Scan: success

Other applicable checks pass. These were handled as category 2 findings; no project commands were executed from either lockfile-changing PR branch.

Security

Dependabot and code-scanning alerts were accessible. The npm registry audit reports 5 high, 9 moderate, 3 low, 0 critical advisories, all in development-only transitive dependencies. Every high finding is already covered by #3941 (undici) or #3942 (brace-expansion). No direct-dependency advisory was reported. Moderate-only fast-uri and @humanfs/node updates remain outside autonomous upgrade authority.

Version truth: npm registry queries confirmed undici 8.10.2 and brace-expansion 5.0.12, matching the existing remediation targets. Advisory truth: GitHub Advisory Database plus npm audit. These are same-major patch comparisons; major drift was not surveyed.

Reviewed GitHub Advisory Database high/critical Actions advisories: no affected pinned action was identified. For matching action families, upstream tags resolve to the committed pins for github/codeql-action v4.38.0 and actions/download-artifact v8.0.1, outside the published vulnerable ranges. Scorecard alerts include the dependency findings and a branch-protection score of 8 because one approving review is required; live protection still enforces admins, strict required checks, and prohibits force pushes/deletion.

Control-Plane Integrity

  • Parsed all 29 workflows and 2 composite actions: all 128 third-party references have full SHA pins and version comments.
  • Node strip-only parsing accepted all 143 scripts/*.ts files, including tests; the erasable-syntax lint rule remains enabled.
  • Every workflow declares permissions; no effective write-all was found. Eight App-token steps lack explicit mint-time permission restrictions; see below.
  • Dependency-requiring jobs use the shared setup, except the intentional cache-free privileged privacy scanner in .github/workflows/check-private-leak.yaml. Preserve that exception: replacing it with cache-restoring setup would weaken its trust boundary.
  • Survey visibility gating and both promotion privacy checks remain present. Wiki-authority coverage has a policy mismatch described below.

Code Quality

Executed on the trusted main checkout:

Command Result
pnpm bootstrap Passed
pnpm check-types Passed
pnpm lint Failed only at the advisory-floor gate: three undici and two brace-expansion high findings
pnpm test 88 files passed; 4,079 tests passed; 3 todo
pnpm exec eslint Passed independently, including formatting
pnpm check:solutions-examples Passed independently
git diff --check Passed; working tree clean

Needs Human Attention

  1. Security landing deadlock: pnpm-workspace.yaml, pnpm-lock.yaml, and scripts/check-override-floors.ts; reuse fix(security): exclude vulnerable undici releases #3941/fix(security): exclude vulnerable brace-expansion releases #3942. Each package-specific fix leaves the other vulnerability on its main-based branch. An operator-approved landing strategy is needed before either can satisfy required Lint. Do not retry unchanged CI, create duplicates, bundle unrelated upgrades, or relax the gate. After resolving coordination, verify both floors (undici >=8.10.2, brace-expansion >=5.0.12), rerun all four repository checks, and confirm zero high audit findings.
  2. App-token least privilege: eight token-mint steps across .github/workflows/{dispatch-renovate,manage-cache,manage-issues,merge-data,reconcile-repos,reset-survey-status,update-metadata}.yaml have no permission-* inputs (manage-issues has two). Workflow permissions: does not restrict an App token. Trace each consumer and add only required mint-time permissions in separately reviewed focused changes; retain necessary cross-repository reach. Validate actionlint and consumer API behavior. No failing run was attributed to these declarations, so this pass did not edit workflows. Prior learning: docs/solutions/best-practices/credential-mint-time-permission-scoping-2026-06-22.md.
  3. Wiki-authority policy mismatch: scripts/check-wiki-authority.ts:66–80 restricts bot-authored non-data branches only for metadata/repos.yaml; other guarded wiki/metadata paths still receive the bot-author exemption. If universal data-only promotion is the intended repository invariant, the smallest strengthening is applying the existing guarded-path matcher to that branch exception, with updates to scripts/check-wiki-authority.test.ts. Preserve legitimate data promotion and scaffolding exclusions; verify authority tests, all repository checks, and mutation guards. This run followed its stricter no-wiki/no-metadata-write contract.

The landing deadlock and mint-time scoping are durable knowledge candidates for an authorized working-dir persistence run; no wiki or metadata was written here. Categories 5–8 and the daily report were not run.

Run Summary
Category Status Notes
Errored PRs ⚠️ Two security PRs fail Lint; legacy statuses pass; no other open PRs
Security ❌ Five high development advisories; existing fixes blocked; no new PR
Control-Plane Integrity ⚠️ Pins and strip-only syntax pass; token-scope and authority gaps deferred
Code Quality ❌ Bootstrap/types/tests/ESLint pass; full Lint blocked by known advisories

Run 36818273959. Changes delivered: none. One consolidated comment; no guardrails weakened.

@fro-bot

fro-bot commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Remediation pass — 2026-10-02 UTC

The security landing deadlock remains. All five high npm advisories already have dedicated fixes in #3941 and #3942. Each PR fails the repository-wide lint gate on the other package’s inherited floor. No additional minimal repair meets the package-specific scope contract. No commits, pushes, or duplicate PRs/issues were created; trusted main remains clean at b96b990.

Run Summary

Category Status Notes
Errored PRs ⚠️ Three open PRs fail Lint; #3946 also fails legacy renovate/artifacts
Security ❌ Five high development advisories covered by existing blocked PRs; zero critical
Control-Plane Integrity ⚠️ 128 SHA pins and 143 strip-only parses pass; permission/authority gaps deferred
Code Quality ❌ Bootstrap/types/tests/independent ESLint pass; full lint fails advisory-floor gate

Errored PRs

Inspected paginated check runs, legacy commit statuses, changed paths, trusted authors, mergeability, and failed logs for every open PR. All three are trusted, same-repository, mergeable branches; the token has repository push access.

PR Check-run failure Legacy statuses
#3941 Lint: two high brace-expansion floor findings addressed by #3942 Privacy scan passed
#3942 Lint: three high undici floor findings addressed by #3941 Privacy scan passed
#3946 Lint: all five inherited floor findings renovate/artifacts: failure; privacy scan passed

#3946 is a routine Actions update owned by Renovate. Its artifact failure details identify the same root cause: pnpm run fix stops at check:override-floors, before formatting. No project commands were executed from PR branches: the security PRs touch lockfiles and #3946 touches workflows. No non-security dependency update was authored.

Security

Dependabot, repository advisories, and Code Scanning were accessible. Dependabot has ten open alerts, including two high undici records; npm audit independently confirms 5 high, 9 moderate, 3 low, 0 critical, all development-only transitive findings. No direct dependency advisory was identified. GitHub’s snapshot does not enumerate every high finding returned by npm audit.

#3941 already targets undici 8.10.2; #3942 targets brace-expansion 5.0.12. Sources: GitHub Advisory Database and npm registry advisory audit for severity/ranges; pnpm view undici@8.10.2 version and pnpm view brace-expansion@5.0.12 version reconfirmed those patched targets. Same-major security patch comparisons only; major drift was not surveyed. Moderate-only fast-uri and @humanfs/node updates remain with Renovate.

Reviewed paginated high/critical Actions advisories against referenced action families: no affected direct action pin identified. Upstream GitHub tags resolve to the committed CodeQL v4.38.0 and download-artifact v8.0.1 pins, outside their published vulnerable ranges. Open Scorecard records are posture findings.

Control-Plane Integrity

  • All 29 workflows and two composite actions parse; 128 third-party references have full SHAs and version comments.
  • Node’s strip-only parser accepted 143 scripts/*.ts files, including tests. This is parser validation, not a fresh production-module import sweep; erasable-syntax lint remains enabled. Prior guidance applied: docs/solutions/runtime-errors/node-strip-only-typescript-2026-04-18.md.
  • Every workflow declares permissions. Eight App-token steps lack explicit mint-time permission inputs. Scorecard has a broad read-all default overridden by its analysis job.
  • Dependency-requiring jobs use shared setup except the intentional cache-free privacy scanner in .github/workflows/check-private-leak.yaml; preserve that trust boundary.
  • Survey visibility and both promotion privacy gates remain present. Live main protection enforces admins, strict checks and review requirements, prohibits force pushes/deletion; the App-only data ruleset is active. No protection changes.

Code Quality

On trusted main, pnpm bootstrap, pnpm check-types, and pnpm test passed: 88 files; 4,079 passed, three todo. pnpm lint failed only at the five high advisory-floor findings. Independent pnpm exec eslint, pnpm check:solutions-examples, and git diff --check passed. No mechanical fix was needed.

Needs Human Attention

  1. Security landing coordination: reuse fix(security): exclude vulnerable undici releases #3941/fix(security): exclude vulnerable brace-expansion releases #3942; affected files are pnpm-workspace.yaml, pnpm-lock.yaml, and enforcing scripts/check-override-floors.ts. Neither dedicated PR can satisfy Lint while its sibling fix is absent. Arrange an operator-approved landing strategy preserving package scope and required checks. Do not retry unchanged CI, duplicate PRs, bundle unrelated upgrades, or suppress the gate. Verify both patched floors/resolutions, all four checks and zero high/critical audit findings. Then let Renovate refresh chore(deps): update bfra-me/.github action to v4.35.0 #3946’s artifacts.
  2. Mint-time least privilege: .github/workflows/{dispatch-renovate,manage-cache,manage-issues,merge-data,reconcile-repos,reset-survey-status,update-metadata}.yaml contain eight unscoped App-token steps (manage-issues has two). Trace consumer calls; add only required permission-* inputs in focused reviewed changes, preserving cross-repository reach. Workflow permissions do not constrain App tokens. Also review .github/workflows/scorecard.yaml:19 while retaining SARIF/OIDC capabilities. Verify actionlint and real consumer behavior. No failing run was attributed to these declarations, so the workflow-edit boundary prohibits a change here. Prior guidance: docs/solutions/best-practices/credential-mint-time-permission-scoping-2026-06-22.md.
  3. Authority mismatch: scripts/check-wiki-authority.ts:66–80 requires data only for bot-authored metadata/repos.yaml; other guarded paths receive an exemption. If universal data-only promotion is intended, apply the existing guarded-path matcher to that bot/non-data exception and update scripts/check-wiki-authority.test.ts. Preserve promotion and scaffolding exclusions; verify authority tests, repository checks and mutation guards. Do not exploit the exemption to write wiki/metadata here.
  4. Durable knowledge: security landing deadlock and advisory-source snapshot lag merit capture in an authorized working-dir knowledge run. No knowledge/** or metadata/** was written here.

Run 36966738330. Delivery: no eligible new mutation; existing security PRs reused as the coordination surface. Workflow guard unavailable. Categories 5–8 and daily-report publication are outside this invocation.

@fro-bot

fro-bot commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Remediation pass — 2026-10-03 UTC

The security landing deadlock now blocks all four open PRs. Existing dedicated fixes #3941 and #3942 cover every high npm finding, but each fails Lint on the other package. No additional minimal repair satisfies the package-specific scope contract. No commits, pushes, or duplicate PRs/issues were created; main remains clean at b96b990.

Run Summary

Category Status Notes
Errored PRs ⚠️ Four failing Lint checks; two additional failing legacy artifact statuses
Security ❌ Five high development advisories; existing security fixes mutually blocked
Control-Plane Integrity ⚠️ SHA pins and strip-only parsing pass; permission and authority gaps deferred
Code Quality ❌ Bootstrap/types/tests/independent ESLint pass; full Lint fails advisory-floor gate

Errored PRs

Inspected changed paths, mergeability, gh pr checks, paginated check runs, separate legacy commit statuses, and failed logs. All four branches are same-repository, mergeable, and authored by Fro Bot or its automation App; repository push permission is available. All applicable check-run failures are Lint:

PR Lint root cause Legacy statuses
#3941 Two high brace-expansion floor findings addressed by #3942 Privacy scan passed
#3942 Three high undici floor findings addressed by #3941 Privacy scan passed
#3946 All five inherited floor findings renovate/artifacts: failure; privacy scan passed
#3948 All five inherited floor findings renovate/artifacts: failure; privacy scan passed

The #3946 artifact diagnostic and #3948 diagnostic show pnpm run fix stopping at the same advisory gate before formatting. Dependency PRs were assessed under category 2. No project commands ran from PR branches: #3941/#3942 change lockfiles; #3946/#3948 change workflows or the setup action. Routine version updates remain owned by Renovate.

Security

Dependabot, repository advisory, and Code Scanning endpoints were accessible. Dependabot has 10 open alerts, two high; npm registry audit confirms 5 high, 9 moderate, 3 low, zero critical, all development-only transitive findings. No direct-dependency advisory was identified. GitHub alert state does not enumerate every finding still present in the npm audit.

Reuse #3941 for undici 8.10.0 → 8.10.2 and #3942 for brace-expansion 5.0.9 → 5.0.12. Sources: GitHub Advisory Database and npm registry advisory audit for affected ranges; pnpm view undici@8.10.2 version and pnpm view brace-expansion@5.0.12 version reconfirmed published patched targets. Same-major patch comparisons only; major drift was not surveyed. Moderate-only fast-uri and @humanfs/node findings are outside autonomous upgrade authority.

Reviewed paginated high/critical Actions advisories against all referenced action families: no affected direct action pin identified. Upstream GitHub tags resolve to the committed CodeQL v4.38.0 and download-artifact v8.0.1 SHAs, outside their published vulnerable ranges. Scorecard vulnerability findings corroborate the npm audit. Its branch-protection alert concerns the one-review count; live main protection still enforces admins, strict required checks, code-owner/latest-push review requirements, and prohibits force pushes/deletion. The App-only data ruleset remains active.

Control-Plane Integrity

  • 29 workflows, two composite actions, 128 third-party references: YAML parses; every reference has a full SHA and version comment.
  • 143 scripts/*.ts files: Node strip-only parsing passes, including tests; erasable-syntax lint remains enabled. This is parser validation, not a fresh production import sweep. Applied guidance: docs/solutions/runtime-errors/node-strip-only-typescript-2026-04-18.md.
  • Every workflow declares permissions; no effective write-all. Eight App-token mint steps lack explicit permission inputs. Scorecard declares read-all at workflow level, overridden by its analysis job.
  • Dependency-requiring jobs use shared setup except the intentional cache-free privileged scanner in .github/workflows/check-private-leak.yaml; preserve that trust boundary.
  • Survey visibility resolve/recheck and both data-promotion privacy gates remain present. Wiki-authority coverage has the policy mismatch below.

Code Quality

Executed on trusted main: pnpm bootstrap, pnpm check-types, and pnpm test passed (88 files; 4,079 tests passed, three todo). pnpm lint failed at the five high advisory-floor findings. Independent pnpm exec eslint, pnpm check:solutions-examples, and git diff --check passed. No mechanical fix was needed.

Needs Human Attention

  1. Security landing coordination: affected files are pnpm-workspace.yaml, pnpm-lock.yaml, and enforcing scripts/check-override-floors.ts. Reuse fix(security): exclude vulnerable undici releases #3941/fix(security): exclude vulnerable brace-expansion releases #3942. Each dedicated fix inherits the other vulnerable package, so neither can satisfy required Lint. Arrange an operator-approved landing strategy preserving package scope and required checks. Do not retry unchanged CI, duplicate fixes, bundle unrelated upgrades, or suppress the gate. Verify both patched floors/resolutions, all four repository checks, and zero high/critical audit findings; then let Renovate refresh chore(deps): update bfra-me/.github action to v4.35.0 #3946/chore(deps): update dependency jdx/mise to v2026.10.0 #3948 artifacts.
  2. Mint-time least privilege: eight steps across .github/workflows/{dispatch-renovate,manage-cache,manage-issues,merge-data,reconcile-repos,reset-survey-status,update-metadata}.yaml lack permission-* inputs; manage-issues has two. Trace consumers and add only required mint-time permissions in focused reviewed changes, preserving necessary repository reach. Workflow permissions do not constrain App tokens. Also review the broad default at .github/workflows/scorecard.yaml:19, retaining SARIF/OIDC capability. Verify actionlint and consumer behavior. No failing run was attributed to these declarations, so the workflow-edit boundary prohibits repair here. Applied guidance: docs/solutions/best-practices/credential-mint-time-permission-scoping-2026-06-22.md.
  3. Wiki-authority mismatch: scripts/check-wiki-authority.ts:66–80 restricts bot-authored non-data branches only for metadata/repos.yaml; other guarded paths retain the bot exemption. If universal data-only promotion is intended, apply the existing guarded-path matcher to that exception and update scripts/check-wiki-authority.test.ts. Preserve legitimate data promotion and scaffolding exclusions; verify authority tests, repository checks, and mutation guards. Do not exploit the exemption to write wiki/metadata in this job.
  4. Durable knowledge: the landing deadlock and advisory-source snapshot discrepancy merit capture by an authorized working-dir persistence run. No knowledge/** or metadata/** was written here.

Run 37097285315. Delivery: no eligible new mutation; existing security PRs retained as the coordination surface. Workflow guard unavailable; auxiliary shipping-reference access was denied by tool policy. Categories 5–8 and daily-report publication were outside this invocation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant