Security Finding
Severity: medium
Type: CVE / unapplied dependency patch + stale security documentation
SECURITY.md tells readers that no patched version exists for either of the
two advisories behind the npm audit findings, and that both packages are
"already at their newest published version, so there is no upgrade to apply".
That is no longer true for one of them. http-cache-semantics@4.3.0 is
published, and GHSA-ch52-4w7c-c8xp
("max-stale handling can disclose cross-user cached responses") has the
vulnerable range <= 4.2.0. 4.3.0 falls outside that range. The lockfile
is still pinned to the vulnerable 4.2.0.
Verified at main 900592b
$ npm audit --package-lock-only
29 high severity vulnerabilities
http-cache-semantics is the only entry npm can already fix — it is a leaf with
no dependents constraining it ("effects": [], "fixAvailable": true), unlike
the 28 braces-derived entries which all report fixAvailable: false:
$ npm audit --package-lock-only --json | jq '.vulnerabilities
| to_entries[] | select(.value.fixAvailable != false) | .key'
"http-cache-semantics"
After npm update http-cache-semantics --package-lock-only the lockfile moves
4.2.0 -> 4.3.0 (a 3-line, lockfile-only change — no package.json edit,
no @docusaurus/* version moves) and the advisory clears:
$ npm audit --package-lock-only
28 high severity vulnerabilities
braces is genuinely still unpatched: 3.0.3 remains the newest published
version and GHSA-vfj7-8cjw-p6xm's range is <= 3.0.3. That row of the table
stays accurate and must not be touched.
Provenance limitation
The GitHub advisory API still reports first_patched_version: null for
GHSA-ch52-4w7c-c8xp, so the "4.3.0 is the fix" claim rests on the advisory's own
vulnerable_version_range (<= 4.2.0) plus npm's resolution against it, not on
an upstream patch note. I could not read the 4.2.0...4.3.0 commit range — the
upstream repo path in the package manifest
(kornelski/http-cache-semantics) returns 404 for the compare API.
Impact
Low direct exposure, but a real one:
- This is build-time only.
update-notifier reaches http-cache-semantics from
@docusaurus/core's version check, it is not bundled into the static output,
and the npm-registry request it caches carries no repository secret. So a
visitor to the published site is not reachable through it.
- The documentation defect is the larger problem.
SECURITY.md currently
instructs readers that there is nothing to apply and tells them to stop
looking ("Remove this section once upstream publishes fixes"). Upstream has
published a fix, so that standing instruction now actively suppresses the
remediation it was written to wait for — for however long nobody re-checks.
- It also keeps a known-vulnerable version resolved in CI for every
npm ci, and keeps the audit count inflated, which erodes the signal that is
supposed to make a new advisory visible.
Recommendation
One mechanical change, both parts in a single PR:
-
Bump the lockfile only:
npm update http-cache-semantics --package-lock-only
yielding exactly:
"node_modules/http-cache-semantics": {
- "version": "4.2.0",
- "resolved": "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.2.0.tgz",
- "integrity": "sha512-dTxcvPXqPvXBQpq5dUr6mEMJX4oIEFv6bwom3FDwKRDsuIjjJGANqhBuoAn9c1RQJIdAKav33ED65E2ys+87QQ=="
+ "version": "4.3.0",
+ "resolved": "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.3.0.tgz",
+ "integrity": "sha512-M5t5LlJpS1UHMjvwRQVdFHvPISGeLAxNcrWuJkeGh0KxsqCHZ1O3NXZU/8x7cD0BDcGW8kapxMKTvwlqrNkHkA==",
+ "license": "BSD-2-Clause"
},
-
Correct the Known unpatched dependency advisories section of SECURITY.md
so it describes one remaining advisory rather than two: drop the
http-cache-semantics table row, update the count, and reword the
"Both"/"either package" claims to refer to braces alone. The
npm audit fix --force warning should be kept — it is still correct for
braces.
Completion criteria
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode)
🐝 Hive Agent: security | Instance: hosted-available-lke648397-260827-5n31 | SHA: 900592b
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88
Security Finding
Severity: medium
Type: CVE / unapplied dependency patch + stale security documentation
SECURITY.mdtells readers that no patched version exists for either of thetwo advisories behind the
npm auditfindings, and that both packages are"already at their newest published version, so there is no upgrade to apply".
That is no longer true for one of them.
http-cache-semantics@4.3.0ispublished, and GHSA-ch52-4w7c-c8xp
("max-stale handling can disclose cross-user cached responses") has the
vulnerable range
<= 4.2.0.4.3.0falls outside that range. The lockfileis still pinned to the vulnerable
4.2.0.Verified at
main900592bhttp-cache-semanticsis the only entry npm can already fix — it is a leaf withno dependents constraining it (
"effects": [],"fixAvailable": true), unlikethe 28
braces-derived entries which all reportfixAvailable: false:After
npm update http-cache-semantics --package-lock-onlythe lockfile moves4.2.0 -> 4.3.0(a 3-line, lockfile-only change — nopackage.jsonedit,no
@docusaurus/*version moves) and the advisory clears:bracesis genuinely still unpatched:3.0.3remains the newest publishedversion and GHSA-vfj7-8cjw-p6xm's range is
<= 3.0.3. That row of the tablestays accurate and must not be touched.
Provenance limitation
The GitHub advisory API still reports
first_patched_version: nullforGHSA-ch52-4w7c-c8xp, so the "4.3.0 is the fix" claim rests on the advisory's own
vulnerable_version_range(<= 4.2.0) plus npm's resolution against it, not onan upstream patch note. I could not read the 4.2.0...4.3.0 commit range — the
upstream repo path in the package manifest
(
kornelski/http-cache-semantics) returns 404 for the compare API.Impact
Low direct exposure, but a real one:
update-notifierreacheshttp-cache-semanticsfrom@docusaurus/core's version check, it is not bundled into the static output,and the npm-registry request it caches carries no repository secret. So a
visitor to the published site is not reachable through it.
SECURITY.mdcurrentlyinstructs readers that there is nothing to apply and tells them to stop
looking ("Remove this section once upstream publishes fixes"). Upstream has
published a fix, so that standing instruction now actively suppresses the
remediation it was written to wait for — for however long nobody re-checks.
npm ci, and keeps the audit count inflated, which erodes the signal that issupposed to make a new advisory visible.
Recommendation
One mechanical change, both parts in a single PR:
Bump the lockfile only:
yielding exactly:
"node_modules/http-cache-semantics": { - "version": "4.2.0", - "resolved": "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.2.0.tgz", - "integrity": "sha512-dTxcvPXqPvXBQpq5dUr6mEMJX4oIEFv6bwom3FDwKRDsuIjjJGANqhBuoAn9c1RQJIdAKav33ED65E2ys+87QQ==" + "version": "4.3.0", + "resolved": "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.3.0.tgz", + "integrity": "sha512-M5t5LlJpS1UHMjvwRQVdFHvPISGeLAxNcrWuJkeGh0KxsqCHZ1O3NXZU/8x7cD0BDcGW8kapxMKTvwlqrNkHkA==", + "license": "BSD-2-Clause" },Correct the
Known unpatched dependency advisoriessection ofSECURITY.mdso it describes one remaining advisory rather than two: drop the
http-cache-semanticstable row, update the count, and reword the"Both"/"either package" claims to refer to
bracesalone. Thenpm audit fix --forcewarning should be kept — it is still correct forbraces.Completion criteria
package-lock.jsonresolveshttp-cache-semanticsat4.3.0npm audit --package-lock-onlyreports 28 high, with noGHSA-ch52-4w7c-c8xp entry
SECURITY.mdno longer claims a patched version is unavailable forhttp-cache-semantics, and still documentsbracesas unpatchedpackage.jsondependency range changed and no@docusaurus/*version movedFiled by sec-check agent (ACMM L4/L5 — hold-gated mode)
🐝 Hive Agent:
security| Instance:hosted-available-lke648397-260827-5n31| SHA:900592b— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88