Skip to content

chore(audit): accept the unfixed braces advisory GHSA-vfj7-8cjw-p6xm - #1496

Merged
xiaolai merged 1 commit into
mainfrom
chore/accept-braces-advisory
Oct 3, 2026
Merged

xiaolai merged 1 commit into
mainfrom
chore/accept-braces-advisory

Conversation

@xiaolai

@xiaolai xiaolai commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Summary

The npm-audit gate (scripts/check-npm-audit.mjs, in fe-static) fails every PR, main included, on a braces advisory published 2026-09-18: GHSA-vfj7-8cjw-p6xm (high, stack-exhaustion DoS through deeply nested patterns). It affects braces <= 3.0.3, the latest release, and lists no patched version, so no dependency upgrade can clear it. This adds it to the reviewed baseline with its reachability written down.

Blocks #1495 (its frontend check is red only on this step).

Policy Gates (Required)

  • This PR is single-focus (one issue, one problem, one objective).
  • This PR includes 100% test coverage for changed behavior and changed code paths.
  • If this is a bug fix, the linked issue contains detailed reproduction context.

Linked Issue

  • None. CI-gate unblock; the context is above.

Type of Change

  • Bug fix
  • Feature
  • Docs
  • Refactor
  • Test-only
  • Other (dependency-advisory review)

What Changed

  • scripts/npm-audit-baseline.json: accept GHSA-vfj7-8cjw-p6xm with a reason.

Reachability (pnpm why braces -r --prod):

  • The only shipped path is server/content > @slidev/cli > vite-plugin-static-copy > chokidar@3, and fast-glob > micromatch. Those glob Slidev's own patterns.
  • The content server's own watcher (server/content/src/index/watch.ts) uses chokidar@5, which does not depend on braces.
  • The other paths (globby, markdownlint-cli2) are dev tooling.
  • Worst case: a stack-overflow crash of the local Slidev preview process for a deck the user opened. Not code execution.

Same shape as the existing GHSA-w3rx-r6r6-pgpr entry (unfixed, same Slidev chain). The gate is two-way, so this entry fails CI once the advisory is withdrawn or fixed, and must be removed then.

Validation

  • I ran pnpm check:all locally.
  • I added or updated tests to fully cover behavior changes.
  • I manually verified critical flows.

node scripts/check-npm-audit.mjs exits 1 before the change and 0 after; scripts/check-baseline-ratchet.mjs holds. No app behavior changes.

UI Evidence (if applicable)

N/A

PR Checklist

  • The PR avoids unrelated refactors or cleanup.
  • The issue context is clear (linked issue or explanation above).
  • Docs/changelog were updated if behavior or usage changed.
  • I am ready to address review feedback.

The npm-audit gate fails every PR on a braces advisory published
2026-09-18. It affects braces <=3.0.3, the latest release, and lists
no patched version, so no upgrade can clear it.

braces reaches the shipped tree only through the content server's
@slidev/cli (vite-plugin-static-copy>chokidar@3 and
fast-glob>micromatch), which globs Slidev's own patterns. The content
server's watcher uses chokidar@5, which does not depend on braces.
The worst case is a stack-overflow crash of the local Slidev preview
for a deck the user opened.
@xiaolai
xiaolai merged commit ab947c6 into main Oct 3, 2026
16 checks passed
@xiaolai
xiaolai deleted the chore/accept-braces-advisory branch October 3, 2026 15:50
newhdr pushed a commit to newhdr/vmark that referenced this pull request Oct 5, 2026
# Conflicts:
#	scripts/npm-audit-baseline.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant