Skip to content

security: clear open Dependabot + CodeQL alerts - #6

Merged
just-shane merged 1 commit into
mainfrom
security/alert-sweep
Aug 9, 2026
Merged

just-shane merged 1 commit into
mainfrom
security/alert-sweep

Conversation

@just-shane

Copy link
Copy Markdown
Contributor

Clears 3 of the 4 open security alerts on this repo (the 4th is dismissed with rationale, see below).

Changes

  • postcss 8.5.19 → 8.5.26 (lockfile-only): GHSA-fxqj-rqcc-2cmp — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset. Dev-scope, patch-range bump via npm update postcss.
  • CongressClient baseUrl normalization: replace /\/+$/ regex with a linear endsWith loop. CodeQL flags the regex as polynomial ReDoS (js/polynomial-redos, high). Practical exposure is low (baseUrl is a constructor option, not runtime attacker input), but this is a published SDK and the linear rewrite is free. Behavior identical; 60/60 tests pass.
  • ci.yml: add top-level permissions: contents: read (CodeQL actions/missing-workflow-permissions). CI only checks out, installs, tests, builds — read is sufficient.

Dismissed (not merged away)

  • Dependabot v0.1.0: core client with bills, members, and House votes #1, esbuild ≥0.27.3 <0.28.1 (GHSA-g7r4-m6w7-qqqr, low): tsup pins esbuild ^0.27.0, so the patched 0.28.1 is unreachable without a forced overrides entry. The advisory concerns esbuild's dev-server (serve) mode, which this repo never invokes — esbuild runs only as tsup's bundler and vitest's transform. Dismissing as not_used; clears naturally whenever tsup widens its range.

Verification

npm run typecheck clean, npm test 60/60, npm run build (tsup + DTS) success on node 26.

🤖 Generated with Claude Code

- Bump postcss 8.5.19 -> 8.5.26 in lockfile (GHSA-fxqj-rqcc-2cmp, Dependabot #2)
- Rewrite trailing-slash strip in CongressClient constructor as a linear
  loop; the /\/+$/ regex backtracks polynomially on adversarial baseUrl
  input (CodeQL js/polynomial-redos, alert #1)
- Add top-level 'permissions: contents: read' to ci.yml (CodeQL
  actions/missing-workflow-permissions, alert #2)

The remaining open Dependabot alert (esbuild GHSA-g7r4-m6w7-qqqr, low) is
dismissed as not_used: tsup pins esbuild ^0.27.0 so 0.28.1 is unreachable
without an override, and the advisory concerns esbuild's dev-server serve
mode which this repo never runs (bundler + vitest transform only).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@just-shane
just-shane merged commit 0ee1ed3 into main Aug 9, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant