Skip to content

docs(security): document the braces/chokidar DoS finding as an accepted risk - #85

Open
mattglory wants to merge 1 commit into
mainfrom
docs-accept-braces-dos-finding
Open

mattglory wants to merge 1 commit into
mainfrom
docs-accept-braces-dos-finding

Conversation

@mattglory

Copy link
Copy Markdown
Owner

Summary

PR #81's Dependency Audit re-run (after rebasing to pick up #80's Next.js fix) surfaced a new, different failure -- not the stale one Hillary's review called out. Confirmed independently:

  • GHSA-vfj7-8cjw-p6xm (braces, stack-exhaustion DoS via deeply nested patterns), pulled in via @clarigen/cli -> chokidar -> braces.
  • No upstream fix exists: braces' latest release (3.0.3) is still inside the vulnerable range.
  • npm audit fix --force's only suggestion is downgrading @clarigen/cli (devDependency, our Clarity-to-TS codegen tool) to 0.2.4 -- years old, a real regression, to dodge a DoS this project's own usage can't trigger (chokidar only ever watches our own contracts/ tree here, never attacker-supplied input).
  • Dependency Audit is explicitly non-blocking by design (see the existing comment this one sits next to, from the PR feat(contracts): commit crosspool-ststx-receiver draft (not deployed) #61 fix) -- this didn't block docs: write the interim no-apply-mainnet rule into deployments/ #81 and isn't blocking anything now.

Documents the finding and the reasoning inline in security.yml, next to where it'll actually be seen, rather than leaving it as an unexplained red check someone has to re-investigate from scratch. Says explicitly to re-check once a real patch lands.

Test plan

  • Comment-only change to a workflow file -- no behavior change, nothing to test.
  • Re-run npm audit --audit-level=high next time this step goes red, per the comment, to confirm whether this is still the same finding.

🤖 Generated with Claude Code

GHSA-vfj7-8cjw-p6xm, surfaced by PR #81's Dependency Audit re-run after
rebasing against main. New since Hillary's review on that PR, not the
stale pre-#80 failure he was characterizing -- confirmed via npm audit
directly: braces' latest release (3.0.3) is still in the vulnerable
range, so there's no upgrade path yet. The only `npm audit fix --force`
suggestion is downgrading @clarigen/cli (a devDependency, the Clarity
codegen tool) to 0.2.4 -- a multi-major regression to dodge a DoS this
project's own usage can't trigger (chokidar only ever watches our own
contracts/ tree, never attacker-supplied globs).

Documented inline rather than silently left red, so the next person
who sees this check fail doesn't have to re-derive the same
investigation -- and so it gets re-checked once a real patch exists.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
web Ready Ready Preview Oct 3, 2026 3:11pm UTC

Request Review

@unixwhisperer unixwhisperer left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified independently, not just read the summary:

  • Root npm audit --audit-level=high reproduces exactly: GHSA-vfj7-8cjw-p6xm (braces), path is @clarigen/cli@4.1.7 -> chokidar@3.6.0 -> braces@3.0.3.
  • @clarigen/cli is a devDependency (package.json), used only via npm run gen (clarigen generate) — confirmed it's not in dependencies.
  • braces 3.0.3 is npm's latest published version (npm view braces versions) — confirmed no upstream fix exists yet.
  • npm audit fix --force here does suggest @clarigen/cli@0.2.4 against current ^4.0.1 — that's the multi-major regression described.

Reasoning holds: chokidar's only use here is watching this repo's own contracts/ tree for codegen, not attacker-controlled input, so the DoS vector isn't reachable through our own usage. Good call documenting it inline where the red check actually gets looked at instead of leaving unexplained noise. Approving.

This branch was successfully deployed

1 active deployment
Preview — 5afc4f31 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants