Repository navigation
chore(deps): resolve dependency vulnerabilities (2026-10-06) - #551
Conversation
`npx better-npm-audit audit` (audit-all) and `--production` (audit-prod) were red with 42 new advisories (51 npm audit entries) across 16 root packages. Each package was assessed separately against the decision ladder earlier audit fixes used (94b07cc, 2481e2b, eab374b, f16fb4b): lockfile-only where nothing pins the package, delete an override that has become a stale ceiling, bump or add an override only where a consumer floors a vulnerable range, and an .nsprc exception only where no patched release exists. Lockfile-only (no override key, every consumer range admits the fix): - axios 1.18.1 -> 1.20.0 (12 advisories; via posthog-node ^1.8.2) - fast-uri 3.1.7 -> 3.1.8 (GHSA-hrr3-gc8f-f4qj; ajv ^3.0.1) - http-cache-semantics 4.2.0 -> 4.3.0 (GHSA-ch52-4w7c-c8xp). The advisory is disputed upstream (issue #56 closed not_planned, withdrawal requested in github/advisory-database#10139) and 4.3.0 leaves the max-stale path unchanged; it only falls outside the `<=4.2.0` range. Unreachable here: make-fetch-happen builds its CachePolicy with `shared: false`. 4.3.0 does carry the merged Vary fix. - markdown-it 14.2.0 -> 14.3.2 (GHSA-253c-mchw-3w2r; vsce ^14.1.0). 14.3.2 rather than 14.3.1 because it backports a further smartquotes DoS fix. - probe-image-size 7.3.0 -> 7.4.0 (GHSA-gjj5-9665-rwrc; less ^7.2.3) - proxy-addr 2.0.7 -> 2.0.8 (GHSA-jqcg-44mw-7w3h, critical; express ^2.0.7). Not reachable: both express apps keep `trust proxy` false, so proxy-addr compiles to trustNone and the patched trustSingle/trustMulti matchers never run. - source-map-js 1.2.1 -> 1.2.2 (GHSA-68fv-2mgg-jv7q; postcss ^1.2.1) Deleted overrides that had become stale ceilings (94b07cc: "the lockfile is the floor; the drift check enforces it"). Every consumer range admits the patched release, so only our own key held the tree down: - brace-expansion: all three ranged keys. 1.1.18/2.1.4/5.0.9 -> 1.1.21/2.1.7/5.0.12 across all 11 copies (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p). - dompurify 3.4.15 -> 3.4.16 (GHSA-p98j-92pf-mc4p, GHSA-6688-9rhm-gjv2; mermaid ^3.3.3). - morgan 1.12.0 -> 1.12.1 (GHSA-9f6g-j8ch-79g4; koa-morgan ^1.6.1). - smol-toml 1.8.0 -> 1.9.0 (GHSA-r4xh-jqrq-34v2; cspell-config-lib ^1.6.1). - undici: both ranged keys. 6.28.0/7.29.0 -> 6.29.0/7.30.0 (10 advisories; @actions/* ^6.23.0, cheerio ^7.19.0). Deleting a key alone leaves the lockfile untouched, because the locked version still satisfies the consumer range, so each package was re-resolved with `npm update`. npm 10.9.4 kept the root brace-expansion 1.1.18 and @vscode/test-cli's 5.0.9 even then, so those two lockfile entries were dropped and re-resolved. Bumped override: - ip-address 10.4.0 -> 10.7.3 (GHSA-rpw4-54j3-4h4q, GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw; 10.7.1 is the minimum fix). Kept rather than deleted: build.ts propagates this key into dist/sql-lsp-modules, an isolated install with no lockfile, where removing the pin leaves a reused tree on 10.4.0. 10.7.3 is the latest patch and what an unpinned resolve picks. Correction to eab374b: that copy is reached only via sqlite3 -> node-gyp -> make-fetch-happen -> socks, not by the SQL LSP's host resolution. New override: - katex "0.18.2" (GHSA-238p-pmpm-9mq7, low). mermaid declares ^0.16.45 and every mermaid up to 12.1.0 declares ^0.16.x, a line with no backport, so the consumer itself floors a vulnerable range. 0.16 -> 0.18 only renames internal CSS classes and the private __defineFunction API; mermaid makes a single renderToString call and its CSS targets only `.katex`. katex ships in no bundle. .nsprc accepted risk (no patched release on any line), expiry 2026-11-06: - braces GHSA-vfj7-8cjw-p6xm (high): <=3.0.3, and 3.0.3 is latest. - sprintf-js GHSA-hp3w-g68c-fv3c (moderate): <=1.1.3, and 1.1.3 is latest. Both are in the production tree only because @deepnote/sql-language-server lists jest under `dependencies`. Neither reaches any esbuild metafile, dist/sqlLanguageServer.cjs or dist/sql-lsp-modules. Verified: `better-npm-audit audit` and `--production` both exit 0 with only the elliptic, braces and sprintf-js exceptions applied; exactly the 25 intended lockfile entries move and none are added or removed; a second `npm install` leaves package-lock.json byte-identical; a clean build writes ip-address 10.7.3 into dist/sql-lsp-modules, whose own audit reports 0 vulnerabilities; typecheck, lint and 2826 unit tests pass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthrough
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The inspected dependency versions are consistent with the changed overrides. No actionable merge-blocking risk remains after normal checks. 🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #551 +/- ##
=====================================
Coverage 37% 37%
=====================================
Files 820 820
Lines 40939 40939
Branches 9010 9010
=====================================
Hits 15411 15411
Misses 23460 23460
Partials 2068 2068 🚀 New features to boost your workflow:
|
…rialize-javascript Qlty Check's osv-scanner step (`qlty check --all --filter=osv-scanner`) gates src/test/vscode-notebook-perf/package-lock.json, the fixture's own lockfile that root `npm ci` and better-npm-audit never see (#497). It failed on the same brace-expansion advisories fixed in the root tree, plus one fixture-only finding: - brace-expansion 2.1.4 -> 2.1.7 and 5.0.9 -> 5.0.12 (GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7) - serialize-javascript 7.1.1 -> 7.1.2 under mocha@12 (GHSA-gfhx-hw2g-v5hg, low, >=7.1.1 <7.1.2) Lockfile-only, as in #497. The fixture has no override for either package and every consumer range admits the fix (minimatch ^2.0.2 / ^5.0.8, mocha ^7.1.1). The other serialize-javascript copy (7.0.5, held by the existing `serialize-javascript@<7.0.5` override for mocha 11's ^6.0.2) is outside the advisory range. npm 10.9.4's `npm update` kept the hoisted brace-expansion 2.1.4, so that one lockfile entry was dropped and re-resolved. Verified: a local `qlty check --all --filter=osv-scanner` reports the same 7 issues as CI against the old lockfile and none against the new one; `npm ci` installs the fixture cleanly; a second `npm install --package-lock-only` leaves the lockfile byte-identical. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
Two advisories published after 2be57dd turned Audit - All red again. Both packages are dev-only, so Audit - Production stayed green. - shell-quote 1.9.0 -> 1.12.0 (GHSA-pqg4-j6r4-53mv, critical, >=1.8.4 <1.11.0). Deleted the `shell-quote@<1.9.0` override, which had become a stale ceiling: the only consumer, concurrently@8.2.2, declares ^1.8.1. Same reasoning as the overrides deleted in 2be57dd. 1.12.0 is what the re-resolve picks; its only change past the 1.11.0 fix is extra parse() syntax and quote() operator support. Not reachable here: concurrently calls quote() only for --passthrough-arguments, which no script uses. Every concurrently release from 9.2.1 on pins a vulnerable shell-quote exactly, so a future concurrently major will need an override again. - pbkdf2 3.1.5 -> 3.1.7 (GHSA-477h-4r7f-fvrx, moderate, <=3.1.6). Lockfile-only: no override, and both consumers (crypto-browserify ^3.1.2, parse-asn1 ^3.1.5) admit it. Pulls to-buffer 1.2.1 -> 1.2.2, which 3.1.7 requires. Reached only through node-stdlib-browser in the web test bundle, whose browser mapping uses lib/sync-browser.js rather than the vulnerable lib/sync.js. Verified: `better-npm-audit audit` and `--production` both exit 0 with only the elliptic, braces and sprintf-js exceptions applied; only those three lockfile entries move; a second `npm install` leaves the lockfile byte-identical; `npm run compile` (driven by concurrently) and 2826 unit tests pass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
npx better-npm-audit audit(Audit - All) and--production(Audit - Production) were failing onmainwith 42 new advisories (51 npm audit entries) across 16 root packages, plus two more (shell-quote, pbkdf2) published while this PR was open.Each package was assessed separately against the decision ladder that earlier audit fixes established (#493 / 94b07cc, 2481e2b, eab374b, #469 / f16fb4b):
.nsprcexception only if no patched release exists.None of the 16 is a direct dependency, so rung 1 never applied.
Decisions
.nsprc(no fix exists).nsprc(no fix exists)Details
Lockfile-only: 7 packages
No override key touches these packages, and every consumer's declared range already admits the patched version. This is the browserslist (2481e2b) / fast-uri (#493) shape. In #493's words, "the lockfile is the floor; the drift check enforces it".
^1.8.2. It is bundled intoextension.node.js, but posthog-node onlyrequires axios when globalfetchis missing.^2.0.7; express@latest (5.2.1) declares the same range. Not reachable. Both express apps (oauthLoopbackFlow.node.ts,userpodApiEndpoints.node.ts) keeptrust proxyatfalse, so proxy-addr compiles totrustNone. The fix only touchestrustSingle/trustMulti.^14.1.0. We take 14.3.2 rather than 14.3.1 because 14.3.2 backports a further smartquotes DoS fix that isn't in the advisory DB yet (same reasoning as fast-uri 3.1.7 in chore(deps): resolve fast-uri and qs vulnerabilities #493).^3.0.1), probe-image-size (less^7.2.3), source-map-js (postcss^1.2.1): straightforward patch bumps.not_planned, and withdrawal was requested in GHSA-ch52-4w7c-c8xp (CVE-2026-93748) claim of bogus report by repo owner github/advisory-database#10139.max-stalelogic byte-identical. It only falls outside the<=4.2.0range.CachePolicywithshared: false..nsprcentry.Deleted stale override ceilings: 5 packages, 8 keys
Each key had become the only thing holding the tree on a vulnerable version, because every consumer range admits the fix. This follows #493: rewriting the keys (e.g.
undici@<6.28.1) would resolve identically and then go stale again. The undici keys were on their fourth round of going stale.^1.1.7/^2.0.1/^2.0.2/^5.0.5/^5.0.8^3.3.3^1.6.1(it never pinned morgan; our override caused thefixAvailable: false)^1.6.1(npm's suggested cspell@10 would not fix it)^6.23.0, cheerio^7.19.0How the lockfile was regenerated (this is the non-obvious part):
npm update <pkg>.@vscode/test-cli's 5.0.9. Their two lockfile entries were dropped and re-resolved, and all 11 copies are now patched.Bumped override: ip-address
build/esbuild/build.tspropagates this key intodist/sql-lsp-modules. That directory is installed in isolation with no lockfile, so removing the pin leaves a reused tree on 10.4.0. This is the failure mode measured for mysql2 in 2481e2b.New override: katex
katex: ^0.16.45, and every mermaid release up to 12.1.0 declares^0.16.x. The 0.16 line has no backport, so the consumer itself floors a vulnerable range.__defineFunctionAPI, and 0.18 only prefixed internal CSS classes.renderToStringcall and its CSS targets only.katex.mathmloutput is byte-identical across both versions.^0.18.0with no source change.^0.18, delete this key..nsprcaccepted risk: braces, sprintf-js (expiry 2026-11-06)There is no patched release on any line for either package:
<=3.0.3, and 3.0.3 (2024-05-21) is the latest.<=1.1.3, and 1.1.3 (2023-09-11) is the latest.Both show up in the production tree only because
@deepnote/sql-language-serverlistsjestunderdependencies. Neither reaches any esbuild metafile,dist/sqlLanguageServer.cjsordist/sql-lsp-modules, andnode_modules/**is excluded from the VSIX. The notes record the exact chains and the upgrade path..nsprckey clears the whole chained set (micromatch, chokidar, fast-glob, jest-*, gulp, mocha, vsce…), because better-npm-audit only rows root advisories. Upstream fix PRs (feat: add an opt-in nesting depth limit micromatch/braces#77–feat: Package the extension. #79) are open. When 3.0.4 ships, raise or delete the exactbracesoverride and remove this entry."argparse@1": "2.0.1"would remove sprintf-js entirely, since js-yaml 3'sload()never touches argparse. The.nsprcnote records it as the remediation path.Added after the first CI run: shell-quote, pbkdf2
These two advisories were published after the first commit and turned Audit - All red again. Both packages are dev-only.
"shell-quote@<1.9.0": "1.9.0", which had become a stale ceiling. The only consumer, concurrently@8.2.2, declares^1.8.1.quote()only for--passthrough-arguments, which no script uses.^3.1.2, parse-asn1^3.1.5). It pulls to-buffer 1.2.1 → 1.2.2.lib/sync.js."sanitize-html": "2.17.7", - "shell-quote@<1.9.0": "1.9.0", "@babel/core@<7.29.6": "7.29.6",Perf-fixture lockfile (Qlty Check)
Qlty Check's
osv-scannerstep gatessrc/test/vscode-notebook-perf/package-lock.json. That is the fixture's own lockfile, which rootnpm ciand better-npm-audit never see (#497). It failed on the same brace-expansion advisories, plus one fixture-only finding.The fix is lockfile-only, as in #497. The fixture has no override for these packages, and every consumer range admits the fix:
^2.0.2/^5.0.8>=7.1.1 <7.1.2)^7.1.1The other serialize-javascript copy (7.0.5, held by the existing override for mocha 11) is outside the advisory range.
Verification
npx better-npm-audit auditandnpx better-npm-audit audit --productionboth exit 0. Only the elliptic, braces and sprintf-js exceptions are applied. Production mode prints the existing "unused exception" notice for dev-only elliptic, as before.npm install(npm 10.9.4, Node 22.21.1) leavespackage-lock.jsonunchanged, and a second install in the work tree is byte-identical.npm run compile(withdist/sql-lsp-modulesremoved first) writesip-address: 10.7.3into the generated manifest.npm auditof that shipped tree reports 0 vulnerabilities, and it also resolves http-cache-semantics 4.3.0 and brace-expansion 1.1.21.qlty check --all --filter=osv-scannerreports the same 7 issues as CI against the old fixture lockfile and none against the new one.npm ciinstalls the fixture cleanly, and the lockfile is stable on re-install.npm run typecheck✅,npm run lint✅ (only existing warnings),npm test: 2826 passing, 0 failing.Follow-ups (not in this PR)
@deepnote/sql-language-serverlistsjestindependenciesas well asdevDependencies. Removing it there would drop the whole jest/micromatch/braces/sprintf-js chain fromaudit-prod, for this and every future jest-tree advisory.^5drops axios entirely, which would remove ~173 KB of dead fallback code fromextension.node.js. That is a semver-major change to the telemetry client.🤖 Generated with Claude Code
https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
Summary by CodeRabbit