docs+fix(security): resolve web/ decode-uri-component chain, document braces/elliptic as accepted risk - #87
Open
unixwhisperer wants to merge 3 commits into
Open
unixwhisperer wants to merge 3 commits into
unixwhisperer wants to merge 3 commits into
Conversation
…risk npm audit flags braces@3.0.3 (GHSA-vfj7-8cjw-p6xm, via @clarigen/cli -> chokidar) as high severity. Investigated rather than silently bumped: braces has never published a patched version (3.0.3 is its latest ever release), and the only suggested remediation downgrades @clarigen/cli to 0.2.4 -- four major versions back, API-incompatible with this repo's test harness (tests/clarigen-setup.ts uses the 4.x projectFactory/TestProvider API). The vulnerable path is only reachable through clarigen's own local dev-time file-watching, never external input, so exploitability here is negligible. Recorded as DEP-1 in FINDINGS_REGISTER.md instead of leaving the CI signal unexplained.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…e findings web/'s npm audit reports 26 vulnerabilities across three independent chains: braces (via tailwindcss/eslint-config-next, same unfixable upstream shape as DEP-1), decode-uri-component (via query-string -> @WalletConnect -> @reown/ appkit -> @stacks/connect), and elliptic (via bip322-js/bitcoinjs-message/ secp256k1, same chain). Unlike braces, decode-uri-component has a patched 0.5.0 release upstream -- query-string's own package.json just still declares ^0.4.1, so it never resolves there naturally. Forced via the overrides block already used in this file for @types/react and viem. Verified: 26 vulnerabilities (4 low, 15 moderate, 7 high) -> 15 (8 low, 7 high); every moderate finding in this chain cleared, including the @reown/appkit*/@walletconnect/* entries that were only flagged transitively. npm run build and lint both still pass. elliptic itself has no patched release to move to (6.6.1 is latest ever, same unfixable-upstream shape as braces) and @stacks/connect@8.2.7 (latest available) pins @reown/appkit at an exact 1.7.17, so that sub-chain stays open -- documented as DEP-2 in FINDINGS_REGISTER.md alongside DEP-1, which this commit also extends to cover web/'s copy of the braces chain (same root cause reached through a second package.json, not a separate issue). Note: web/package-lock.json's diff includes ~90 lines of npm-version-churn (optional-dependency "libc" platform hints disappearing) unrelated to this override -- a side effect of regenerating the lockfile with a locally installed npm different from whatever produced the committed one. Content- wise this is a one-line override addition; verified functionally via a clean npm ci + npm run build + npm run lint.
…t-braces-fix # Conflicts: # docs/security/FINDINGS_REGISTER.md
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Started as a root-only
braces/@clarigen/cliinvestigation (triggered by #86's CI); expanded once checkingweb/'s ownnpm auditsurfaced 26 findings that had never run in CI (the root audit step failing halted the job before the web step ran).Root (
DEP-1, unfixed, accepted risk):braces@3.0.3is the latest version ever published — the advisory covers its entire release history, so there's no patched version for@clarigen/clito move to. The only suggested remediation is a 4-major-version downgrade that's API-incompatible withtests/clarigen-setup.ts. Not applied.web/(DEP-1extended + newDEP-2): samebracesroot cause reachesweb/a second way (tailwindcss,eslint-config-next→fast-glob/micromatch) — same accepted-risk conclusion, all dev/build-time tooling, never shipped to users. Separately,web/'s wallet-connect stack (@stacks/connect→@reown/appkit→@walletconnect/*→query-string→decode-uri-component, and →bip322-js/bitcoinjs-message→secp256k1→elliptic) does ship to the browser, so it got a real look rather than a shrug:decode-uri-component@0.2.2(moderate, ReDoS) is fixable —0.5.0exists upstream;query-stringjust hasn't bumped its own declared range yet. Forced viaoverridesinweb/package.json(same mechanism already used there for@types/react/viem).elliptic@6.6.1(low, risky crypto primitive) is not fixable the same way — it's the latest version ever published, same shape asbraces.@stacks/connect@8.2.7(latest available) pins@reown/appkitat an exact1.7.17, so there's no newer@stacks/connectrelease to move to either. Left open, documented asDEP-2.Result
web/npm audit: 26 vulnerabilities (4 low, 15 moderate, 7 high) → 15 (8 low, 7 high). Every moderate-severity finding is cleared, including all the@reown/appkit*/@walletconnect/*entries that were only flagged transitively throughdecode-uri-component. Remaining 15 are the two unfixable-upstream chains (bracesdevtools,ellipticcrypto primitive), both now documented rather than silently red.Test plan
npm ci(web/) +npm auditbefore/after confirms the count dropnpm run build— compiles and generates all 6 static pages successfullynpm run lint— pre-existing, unrelated failure confirmed present on main too (not a regression from this change)decode-uri-component@0.5.0is zero-dependency and a drop-in security patch, not an API rewrite🤖 Generated with Claude Code