Skip to content

fix(security): exclude vulnerable brace-expansion releases - #3942

Open
fro-bot wants to merge 1 commit into
mainfrom
fix/security-brace-expansion-5.0.12-36670935566
Open

fro-bot wants to merge 1 commit into
mainfrom
fix/security-brace-expansion-5.0.12-36670935566

Conversation

@fro-bot

@fro-bot fro-bot commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Security remediation

Raise the existing brace-expansion override floor to >=5.0.12 and resolve only that package from 5.0.9 → 5.0.12. Only pnpm-workspace.yaml and pnpm-lock.yaml change.

Confirmed high advisories:

  • GHSA-qhr7-859c-m2p7: uncontrolled nested-brace recursion exhausts the stack (patched in 5.0.11).
  • GHSA-6j4f-fj2g-mc7p: uncontrolled parseCommaParts recursion exhausts the stack (patched in 5.0.10).

5.0.12 also resolves the same package's medium advisory GHSA-q2hr-2g5m-vwhr. No unrelated dependency updates are included. The consumer is minimatch, used by development tooling.

Sources: GitHub Advisory Database and npm advisory audit confirmed severity/ranges; npm registry pnpm view brace-expansion@5.0.12 confirmed the version/integrity. This is a same-major patch remediation; major drift was not surveyed. The floor comment records when it can be removed.

Verification

  • pnpm bootstrap, pnpm check-types, pnpm test: passed (88 files, 4,079 tests passed, 3 todo).
  • pnpm exec eslint, pnpm check:solutions-examples, Markdown-link gate, git diff --check: passed.
  • Audit: zero remaining brace-expansion advisories.
  • pnpm lint: blocked only by the three independently confirmed high undici advisories already present on main, addressed separately in fix(security): exclude vulnerable undici releases #3941. No guardrails are weakened.

Both independent security PRs must land for the repository-wide lint gate to pass. They touch disjoint lockfile sections; refresh against main after the first lands to satisfy strict branch protection. Automated review helper/reference access was denied by CI tool policy; no automated review verdict is claimed.

@fro-bot

fro-bot commented Sep 30, 2026

Copy link
Copy Markdown
Owner Author

Run Summary — remediation pass, 2026-09-30 UTC

Delivered two dedicated security fixes: #3941 (undici) and #3942 (brace-expansion). Together they remove all five confirmed high-severity npm advisories and restore the lint gate. Neither PR is merged.

Category Result
Errored PRs No open PRs at the initial scan. The two PRs created here now fail Lint solely on the other package's pre-existing advisories. Both legacy Security: Private Leak Scan statuses succeeded; types, tests, workflow validation, strip-only load, dependency review and wiki authority checks succeeded. Mutation checks were still running at readback.
Security #3941 raises the undici floor to >=8.10.2 and locks 8.10.2; #3942 raises brace-expansion to >=5.0.12 and locks 5.0.12. Each changes only pnpm-workspace.yaml and pnpm-lock.yaml, with no unrelated upgrades. Alerts, published repository advisories, Code Scanning and secret scanning were accessible; zero open secret alerts. Remaining npm advisories after both fixes: three moderate advisories across @humanfs/node and fast-uri, left to Renovate.
Control-plane integrity 29 workflows and two composite actions parsed successfully; all 128 third-party references have full SHA pins and version comments. All 143 scripts/*.ts files passed Node's strip-only parser. Scorecard's broad read grant and a pre-existing wiki-authority policy mismatch need review below. Main branch protections and the active App-only data ruleset were inspected without changes.
Code quality On each dedicated branch, bootstrap, types and tests passed; full lint was blocked only by the sibling security finding. With both exact PR diffs applied locally on an unpushed verification branch, pnpm bootstrap, pnpm check-types, pnpm lint, pnpm test all passed: 88 test files, 4,079 tests passed, three todo. Combined audit: zero high/critical. Verification changes were removed and checkout returned to clean main.

Security evidence

  • undici high advisories: GHSA-w293-vg96-wgc3, GHSA-vp8m-p9jh-q5pm, GHSA-rfgv-xxqx-mfg5. Consumer: development dependency eslint-plugin-node-dependencies.
  • brace-expansion high advisories: GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p. Consumer: minimatch in development tooling. 5.0.12 also fixes that package's medium advisory.
  • Severity/range truth came from the GitHub Advisory Database and npm advisory audit, with the npm registry (pnpm view <package>@<version>) confirming patched versions and integrity. Comparisons were same-major patch remediation only; major drift was not surveyed. GitHub's Dependabot snapshot had not yet listed every high advisory returned by npm audit, so the individual GHSA records were verified before editing.
  • Open bot-authored PRs/issues were searched before each creation. No existing dedicated remediation matched either root cause. Commits/pushes/PR creation were completed serially.

Needs Human Attention

  • Delivery coordination: fix(security): exclude vulnerable undici releases #3941 and fix(security): exclude vulnerable brace-expansion releases #3942 each still fail required Lint because the other independent fix is absent. Strict branch protection means neither can merge as-is. Review both dedicated changes and arrange an approved integration containing both before expecting green required checks; combined local verification already passed. Do not disable the audit gate, lower its threshold, bypass required checks, or repeatedly rerun unchanged PRs. No combined remediation PR was opened because this run forbids bundling unrelated dependency changes.
  • Wiki-authority policy mismatch: scripts/check-wiki-authority.ts:66–79 requires a data head only for metadata/repos.yaml; bot identities otherwise bypass guarded-path checks. scripts/check-wiki-authority.test.ts:105–114 explicitly allows bot-authored metadata/allowlist.yaml edits from non-data branches. This does not enforce the task's broader data-only writer contract. Smallest policy-aligned fix: require the authorized promotion head for all guarded paths, retain authorized data promotion, and update the paired behavior tests; verify with the four standard commands plus pnpm check:mutation-guards. This is a pre-existing policy decision, deferred rather than changed here. Do not use the permissive branch rule to write wiki/metadata from remediation runs.
  • Scorecard permissions: .github/workflows/scorecard.yaml:19 declares permissions: read-all. Review the action's actual permission needs, then narrow defaults while preserving analysis/publication and security-events/OIDC capabilities. Verify with actionlint and a real Scorecard run. No demonstrated failing-run bug justified changing that security workflow in this pass. Its existing BranchProtection alert reflects one required reviewer (score 8), not disabled protection; do not alter branch settings from remediation.
  • Authoritative wiki repair: existing Wiki lint: broken-markdown-link in knowledge/wiki/repos/marcusrbrown--marcusrbrown-com.md #3903 concerns a broken link in knowledge/wiki/repos/marcusrbrown--marcusrbrown-com.md. Repair only through the established data-branch wiki writer and verify with wiki lint; do not retry a main-targeted wiki PR.
  • Review tooling limitation: CI tool policy denied the loaded review workflow's reference/helper access, so no automated review verdict is claimed. Exact dependency-only diffs and registry integrity were inspected; all combined repository quality gates passed. Workflow guard was also unavailable.
  • Durable learning: the data-only policy/guard mismatch and GitHub-versus-npm advisory snapshot lag merit capture in a permitted working-dir knowledge run. This run wrote no knowledge/** or metadata/**. Relevant prior guidance applied: docs/solutions/best-practices/dependency-holds-need-lift-conditions-2026-08-31.md for override removal conditions, and docs/solutions/runtime-errors/node-strip-only-typescript-2026-04-18.md for real strip-only verification. The privacy workflow's no-cache setup exception remains intact, consistent with its documented trust boundary.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant