Repository navigation
security: clear open Dependabot + CodeQL alerts - #6
Merged
Merged
Conversation
- Bump postcss 8.5.19 -> 8.5.26 in lockfile (GHSA-fxqj-rqcc-2cmp, Dependabot #2) - Rewrite trailing-slash strip in CongressClient constructor as a linear loop; the /\/+$/ regex backtracks polynomially on adversarial baseUrl input (CodeQL js/polynomial-redos, alert #1) - Add top-level 'permissions: contents: read' to ci.yml (CodeQL actions/missing-workflow-permissions, alert #2) The remaining open Dependabot alert (esbuild GHSA-g7r4-m6w7-qqqr, low) is dismissed as not_used: tsup pins esbuild ^0.27.0 so 0.28.1 is unreachable without an override, and the advisory concerns esbuild's dev-server serve mode which this repo never runs (bundler + vitest transform only). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears 3 of the 4 open security alerts on this repo (the 4th is dismissed with rationale, see below).
Changes
sourceMappingURLreads arbitrary.mapfiles whenfromis unset. Dev-scope, patch-range bump vianpm update postcss./\/+$/regex with a linearendsWithloop. CodeQL flags the regex as polynomial ReDoS (js/polynomial-redos, high). Practical exposure is low (baseUrlis a constructor option, not runtime attacker input), but this is a published SDK and the linear rewrite is free. Behavior identical; 60/60 tests pass.permissions: contents: read(CodeQLactions/missing-workflow-permissions). CI only checks out, installs, tests, builds — read is sufficient.Dismissed (not merged away)
esbuild ^0.27.0, so the patched 0.28.1 is unreachable without a forcedoverridesentry. The advisory concerns esbuild's dev-server (serve) mode, which this repo never invokes — esbuild runs only as tsup's bundler and vitest's transform. Dismissing asnot_used; clears naturally whenever tsup widens its range.Verification
npm run typecheckclean,npm test60/60,npm run build(tsup + DTS) success on node 26.🤖 Generated with Claude Code