Skip to content

docs+fix(security): resolve web/ decode-uri-component chain, document braces/elliptic as accepted risk - #87

Open
unixwhisperer wants to merge 3 commits into
mainfrom
chore/dependency-audit-braces-fix
Open

unixwhisperer wants to merge 3 commits into
mainfrom
chore/dependency-audit-braces-fix

Conversation

@unixwhisperer

@unixwhisperer unixwhisperer commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Started as a root-only braces/@clarigen/cli investigation (triggered by #86's CI); expanded once checking web/'s own npm audit surfaced 26 findings that had never run in CI (the root audit step failing halted the job before the web step ran).

Root (DEP-1, unfixed, accepted risk): braces@3.0.3 is the latest version ever published — the advisory covers its entire release history, so there's no patched version for @clarigen/cli to move to. The only suggested remediation is a 4-major-version downgrade that's API-incompatible with tests/clarigen-setup.ts. Not applied.

web/ (DEP-1 extended + new DEP-2): same braces root cause reaches web/ a second way (tailwindcss, eslint-config-next → fast-glob/micromatch) — same accepted-risk conclusion, all dev/build-time tooling, never shipped to users. Separately, web/'s wallet-connect stack (@stacks/connect → @reown/appkit → @walletconnect/* → query-string → decode-uri-component, and → bip322-js/bitcoinjs-message → secp256k1 → elliptic) does ship to the browser, so it got a real look rather than a shrug:

  • decode-uri-component@0.2.2 (moderate, ReDoS) is fixable — 0.5.0 exists upstream; query-string just hasn't bumped its own declared range yet. Forced via overrides in web/package.json (same mechanism already used there for @types/react/viem).
  • elliptic@6.6.1 (low, risky crypto primitive) is not fixable the same way — it's the latest version ever published, same shape as braces. @stacks/connect@8.2.7 (latest available) pins @reown/appkit at an exact 1.7.17, so there's no newer @stacks/connect release to move to either. Left open, documented as DEP-2.

Result

web/npm audit: 26 vulnerabilities (4 low, 15 moderate, 7 high) → 15 (8 low, 7 high). Every moderate-severity finding is cleared, including all the @reown/appkit*/@walletconnect/* entries that were only flagged transitively through decode-uri-component. Remaining 15 are the two unfixable-upstream chains (braces devtools, elliptic crypto primitive), both now documented rather than silently red.

Test plan

  • npm ci (web/) + npm audit before/after confirms the count drop
  • npm run build — compiles and generates all 6 static pages successfully
  • npm run lint — pre-existing, unrelated failure confirmed present on main too (not a regression from this change)
  • Confirmed decode-uri-component@0.5.0 is zero-dependency and a drop-in security patch, not an API rewrite
  • Manual wallet-connect UI smoke test (connect flow) — not run here (needs a browser + wallet extension); recommend before merge if the team wants extra confidence beyond the build passing

🤖 Generated with Claude Code

…risk

npm audit flags braces@3.0.3 (GHSA-vfj7-8cjw-p6xm, via @clarigen/cli ->
chokidar) as high severity. Investigated rather than silently bumped:
braces has never published a patched version (3.0.3 is its latest ever
release), and the only suggested remediation downgrades @clarigen/cli to
0.2.4 -- four major versions back, API-incompatible with this repo's test
harness (tests/clarigen-setup.ts uses the 4.x projectFactory/TestProvider
API). The vulnerable path is only reachable through clarigen's own local
dev-time file-watching, never external input, so exploitability here is
negligible. Recorded as DEP-1 in FINDINGS_REGISTER.md instead of leaving
the CI signal unexplained.
@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
web Ready Ready Preview Oct 5, 2026 1:25am UTC

Request Review

…e findings

web/'s npm audit reports 26 vulnerabilities across three independent chains:
braces (via tailwindcss/eslint-config-next, same unfixable upstream shape as
DEP-1), decode-uri-component (via query-string -> @WalletConnect -> @reown/
appkit -> @stacks/connect), and elliptic (via bip322-js/bitcoinjs-message/
secp256k1, same chain).

Unlike braces, decode-uri-component has a patched 0.5.0 release upstream --
query-string's own package.json just still declares ^0.4.1, so it never
resolves there naturally. Forced via the overrides block already used in
this file for @types/react and viem. Verified: 26 vulnerabilities (4 low, 15
moderate, 7 high) -> 15 (8 low, 7 high); every moderate finding in this chain
cleared, including the @reown/appkit*/@walletconnect/* entries that were
only flagged transitively. npm run build and lint both still pass.

elliptic itself has no patched release to move to (6.6.1 is latest ever,
same unfixable-upstream shape as braces) and @stacks/connect@8.2.7 (latest
available) pins @reown/appkit at an exact 1.7.17, so that sub-chain stays
open -- documented as DEP-2 in FINDINGS_REGISTER.md alongside DEP-1, which
this commit also extends to cover web/'s copy of the braces chain (same root
cause reached through a second package.json, not a separate issue).

Note: web/package-lock.json's diff includes ~90 lines of npm-version-churn
(optional-dependency "libc" platform hints disappearing) unrelated to this
override -- a side effect of regenerating the lockfile with a locally
installed npm different from whatever produced the committed one. Content-
wise this is a one-line override addition; verified functionally via a clean
npm ci + npm run build + npm run lint.
@unixwhisperer unixwhisperer changed the title docs(security): record braces/@clarigen DoS advisory as accepted risk (DEP-1) docs+fix(security): resolve web/ decode-uri-component chain, document braces/elliptic as accepted risk Oct 4, 2026
…t-braces-fix

# Conflicts:
#	docs/security/FINDINGS_REGISTER.md

This branch was successfully deployed

1 active deployment
Preview — 268c47a1 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants