Skip to content

fix(deps): pin webpack and diff, scope npm pins per lockfile - #917

Merged
michalharakal merged 1 commit into
developfrom
fix/npm-webpack-diff-cves
Aug 10, 2026
Merged

michalharakal merged 1 commit into
developfrom
fix/npm-webpack-diff-cves

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

Closes the three Scorecard Vulnerabilities warnings left open by #913:

Follows #913, which is now merged — this branch is a single commit on top of it.

The two pins

Package Was Now Advisories
diff 7.0.0 8.0.3 GHSA-73rr-hh4g-fpgx
webpack 5.101.3 5.104.1 GHSA-8fgc-7cc6-rx7x (needs 5.104.0), GHSA-38r7-794h-5758 (needs 5.104.1)

Both are overrides that Yarn warns about and applies:

  • webpack overrides KGP's own exact pin. The Kotlin Gradle plugin pins webpack@5.101.3 for Kotlin 2.4.10, so this deliberately runs the bundler ahead of the version the Kotlin toolchain was tested against. The catalog entry carries a note to re-check the pin on every Kotlin upgrade and drop it once KGP's own webpack passes 5.104.1, rather than silently holding the bundler back.
  • diff 7 → 8 is a semver-major override of what mocha@11.7.5 requests. diff is a mocha-only dependency used for assertion output.

jsTest, wasmJsTest and wasmWasiTest all pass on both, which is what makes these safe rather than merely plausible.

Why this also changes the npm-pins plugin

Pinning webpack unscoped grew kotlin-js-store/wasm/yarn.lock by 520 lines / 76 packages — webpack's entire tree (@webassemblyjs/*, acorn, ajv, terser, browserslist, …) landing in a lockfile that bundles nothing with webpack. Yarn writes an entry for every resolutions key whether or not that graph requests the package, and npmPins applied every pin to both Yarn roots.

That was tolerable at #913's scale (~10 phantom packages); at 76 it means the wasm CI job downloads and installs a bundler it never runs, and Dependabot starts reporting those packages against a lockfile that never uses them.

So pin() now takes an optional target:

pin("ws", libs.versions.npm.ws)                             // both lockfiles (default)
pin("webpack", libs.versions.npm.webpack, NpmPinTarget.JS)  // JS lockfile only
  • New NpmPinTarget enum (JS, WASM); no target means both, so every existing call keeps its meaning.
  • NpmPinsExtension now exposes jsPins / wasmPins instead of one flat pins map.
  • NpmPinsPlugin feeds each Yarn root only the pins scoped to it.
  • VerifyNpmPinsTask checks each lockfile against its own pin map, so a scoped pin is never reported as missing from a lockfile it was never meant to reach.

Net effect on the wasm lockfile: kotlin-js-store/wasm/yarn.lock goes back to its single ws entry — identical to what it held before #913. That PR added 59 phantom lines to it as a documented, accepted tradeoff; this one removes them, so the tradeoff no longer has to be accepted.

ws is the only pinned package present in both graphs and stays unscoped; the other seven are JS-only.

Docs

docs/modules/ROOT/pages/contributing/build-from-source.adoc gains a "Scoping a pin to one lockfile" subsection under the existing Pinning npm Packages section, including the grep -c '^webpack@' … check for deciding whether a pin needs a scope.

Verification

./gradlew kotlinUpgradeYarnLock kotlinWasmUpgradeYarnLock
./gradlew verifyNpmPins jsTest wasmJsTest wasmWasiTest      # green

git diff --stat develop -- kotlin-js-store/wasm/yarn.lock   # empty

Closes the three Scorecard vulnerability warnings left open by the previous
npm pin pass:

  GHSA-73rr-hh4g-fpgx  diff     7.0.0    -> 8.0.3
  GHSA-8fgc-7cc6-rx7x  webpack  5.101.3  -> 5.104.1
  GHSA-38r7-794h-5758  webpack  5.101.3  -> 5.104.1

Both are overrides Yarn warns about and applies. webpack overrides KGP's own
exact pin, so the bundler now runs ahead of the version the Kotlin toolchain
was tested against; the catalog entry says to re-check on every Kotlin upgrade
and drop the pin once KGP passes 5.104.1. diff 7 -> 8 is a semver-major
override of a mocha-only dependency.

Pinning webpack unscoped grew kotlin-js-store/wasm/yarn.lock by 520 lines --
webpack's whole tree landing in a lockfile that bundles nothing with webpack.
Yarn writes an entry for every resolutions key whether or not the graph
requests the package, and npmPins applied every pin to both Yarn roots.

So pin() now takes an optional NpmPinTarget:

    pin("ws", libs.versions.npm.ws)                             // both
    pin("webpack", libs.versions.npm.webpack, NpmPinTarget.JS)  // JS only

No target still means both, so existing declarations keep their meaning. The
extension exposes jsPins/wasmPins instead of one flat map, the plugin feeds
each Yarn root only its own pins, and verifyNpmPins checks each lockfile
against its own pin map so a scoped pin is never reported missing from a
lockfile it was never meant to reach.

kotlin-js-store/wasm/yarn.lock is now byte-identical to develop again, which
also retires the phantom entries the previous pass added to it.

Verified with kotlinUpgradeYarnLock, kotlinWasmUpgradeYarnLock, verifyNpmPins,
jsTest, wasmJsTest and wasmWasiTest.
@michalharakal
michalharakal requested a review from aharakal August 9, 2026 18:50
@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown

📖 Documentation Preview

The documentation has been built successfully for this PR.

Generated Files:

  • Operator documentation: docs/modules/operators/_generated_/
  • JSON schema output: operators.json

Artifacts:

  • Download the documentation-preview-917 artifact to view the complete documentation locally.

This comment will be updated automatically when the PR is updated.

@michalharakal
michalharakal merged commit e77e96a into develop Aug 10, 2026
15 checks passed
@michalharakal
michalharakal deleted the fix/npm-webpack-diff-cves branch August 10, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants