From 5afc4f31632323e70317c0f5fa177aa21e584b96 Mon Sep 17 00:00:00 2001 From: Glory Matthew Date: Sat, 3 Oct 2026 16:11:28 +0100 Subject: [PATCH] docs(security): document the braces/chokidar DoS finding as accepted GHSA-vfj7-8cjw-p6xm, surfaced by PR #81's Dependency Audit re-run after rebasing against main. New since Hillary's review on that PR, not the stale pre-#80 failure he was characterizing -- confirmed via npm audit directly: braces' latest release (3.0.3) is still in the vulnerable range, so there's no upgrade path yet. The only `npm audit fix --force` suggestion is downgrading @clarigen/cli (a devDependency, the Clarity codegen tool) to 0.2.4 -- a multi-major regression to dodge a DoS this project's own usage can't trigger (chokidar only ever watches our own contracts/ tree, never attacker-supplied globs). Documented inline rather than silently left red, so the next person who sees this check fail doesn't have to re-derive the same investigation -- and so it gets re-checked once a real patch exists. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/security.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index babc3a3..a9576ab 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -24,6 +24,20 @@ jobs: # "Severity: high" findings and the job still concluded success. A check that # can't go red isn't evidence of anything. Dependency Audit is not a required # status check, so a red run here never blocks a merge; it is a signal. + # + # Known accepted finding as of 2026-10-03: GHSA-vfj7-8cjw-p6xm (braces, + # stack-exhaustion DoS via deeply nested patterns), pulled in transitively via + # @clarigen/cli -> chokidar -> braces. @clarigen/cli is a devDependency (the + # Clarity-to-TypeScript codegen tool, `npm run gen`) -- never shipped, never + # reachable by anyone outside this repo's own `contracts/` tree, which is the + # only glob chokidar ever watches here. No upstream fix exists yet: braces' + # latest release (3.0.3) is still inside the advisory's vulnerable range, and + # `npm audit fix --force`'s only suggested remediation is downgrading + # @clarigen/cli to 0.2.4 -- a multi-major-version regression of an actively + # used dev tool to dodge a DoS risk this project's own usage can't trigger. + # Accepted deliberately, not silently: re-check `npm audit --audit-level=high` + # next time this step goes red, since a real upstream patch (or a new, + # unrelated finding worth acting on) would change this call. - name: Audit root dependencies run: npm audit --audit-level=high