Repository navigation
Conversation
got-fetch is not imported anywhere in the repository. Releases 5.1.11 and 5.1.12 are affected by GHSA-f29h-pxvx-f335, and the ^5.1.1 range resolves to 5.1.12 on installs without a lockfile.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Remove the unused
got-fetchdependency from@openapi-codegen/cli.Why
got-fetchis not imported anywhere in this repository (src, tests, docs).gotitself is still used directly ingetOpenAPISourceFile.tsand is kept.got-fetch@5.1.11and5.1.12are affected by GHSA-f29h-pxvx-f335 (malicious release, fixed in 6.0.0+).cli/package.jsondeclares"got-fetch": "^5.1.1", so an install without a lockfile (e.g. a consumer installing@openapi-codegen/cli) resolves to the compromised5.1.12. The lockfile in this repository pins5.1.10, which is not affected.Removing the unused dependency eliminates that exposure.
Verification
pnpm install --frozen-lockfilepnpm buildpnpm check(tsc / eslint / prettier)pnpm test(27 files, 241 tests passed)Follow-up: replacing
gotwith nativefetchWhile looking into this, I noticed that
gotis only used incli/src/core/getOpenAPISourceFile.ts(a plain GET/POST with headers, plus 401/404 handling for the GitHub source). This looks easy to replace with Node's nativefetch(the repo already requires Node >= 20), which would also drop the wholegotdependency tree.A few things to take care of:
fetchdoes not throw on non-2xx responses (so theHTTPErrorhandling needsres.ok/res.statuschecks),got's default retry behavior goes away, and the URL tests would neednockv14+ (v13 cannot intercept nativefetch).I kept this PR focused on the security fix. If you are interested, I'm happy to open a separate PR for that.