Skip to content

[sec-check] http-cache-semantics 4.3.0 patches GHSA-ch52-4w7c-c8xp, but the lockfile is still on 4.2.0 and SECURITY.md says no fix exists #1049

Description

@hivecommons-hive

Security Finding

Severity: medium
Type: CVE / unapplied dependency patch + stale security documentation

SECURITY.md tells readers that no patched version exists for either of the
two advisories behind the npm audit findings, and that both packages are
"already at their newest published version, so there is no upgrade to apply".

That is no longer true for one of them. http-cache-semantics@4.3.0 is
published
, and GHSA-ch52-4w7c-c8xp
("max-stale handling can disclose cross-user cached responses") has the
vulnerable range <= 4.2.0. 4.3.0 falls outside that range. The lockfile
is still pinned to the vulnerable 4.2.0.

Verified at main 900592b

$ npm audit --package-lock-only
29 high severity vulnerabilities

http-cache-semantics is the only entry npm can already fix — it is a leaf with
no dependents constraining it ("effects": [], "fixAvailable": true), unlike
the 28 braces-derived entries which all report fixAvailable: false:

$ npm audit --package-lock-only --json | jq '.vulnerabilities
    | to_entries[] | select(.value.fixAvailable != false) | .key'
"http-cache-semantics"

After npm update http-cache-semantics --package-lock-only the lockfile moves
4.2.0 -> 4.3.0 (a 3-line, lockfile-only change — no package.json edit,
no @docusaurus/* version moves) and the advisory clears:

$ npm audit --package-lock-only
28 high severity vulnerabilities

braces is genuinely still unpatched: 3.0.3 remains the newest published
version and GHSA-vfj7-8cjw-p6xm's range is <= 3.0.3. That row of the table
stays accurate and must not be touched.

Provenance limitation

The GitHub advisory API still reports first_patched_version: null for
GHSA-ch52-4w7c-c8xp, so the "4.3.0 is the fix" claim rests on the advisory's own
vulnerable_version_range (<= 4.2.0) plus npm's resolution against it, not on
an upstream patch note. I could not read the 4.2.0...4.3.0 commit range — the
upstream repo path in the package manifest
(kornelski/http-cache-semantics) returns 404 for the compare API.

Impact

Low direct exposure, but a real one:

  • This is build-time only. update-notifier reaches http-cache-semantics from
    @docusaurus/core's version check, it is not bundled into the static output,
    and the npm-registry request it caches carries no repository secret. So a
    visitor to the published site is not reachable through it.
  • The documentation defect is the larger problem. SECURITY.md currently
    instructs readers that there is nothing to apply and tells them to stop
    looking ("Remove this section once upstream publishes fixes"). Upstream has
    published a fix, so that standing instruction now actively suppresses the
    remediation it was written to wait for — for however long nobody re-checks.
  • It also keeps a known-vulnerable version resolved in CI for every
    npm ci, and keeps the audit count inflated, which erodes the signal that is
    supposed to make a new advisory visible.

Recommendation

One mechanical change, both parts in a single PR:

  1. Bump the lockfile only:

    npm update http-cache-semantics --package-lock-only
    

    yielding exactly:

        "node_modules/http-cache-semantics": {
    -      "version": "4.2.0",
    -      "resolved": "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.2.0.tgz",
    -      "integrity": "sha512-dTxcvPXqPvXBQpq5dUr6mEMJX4oIEFv6bwom3FDwKRDsuIjjJGANqhBuoAn9c1RQJIdAKav33ED65E2ys+87QQ=="
    +      "version": "4.3.0",
    +      "resolved": "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.3.0.tgz",
    +      "integrity": "sha512-M5t5LlJpS1UHMjvwRQVdFHvPISGeLAxNcrWuJkeGh0KxsqCHZ1O3NXZU/8x7cD0BDcGW8kapxMKTvwlqrNkHkA==",
    +      "license": "BSD-2-Clause"
        },
  2. Correct the Known unpatched dependency advisories section of SECURITY.md
    so it describes one remaining advisory rather than two: drop the
    http-cache-semantics table row, update the count, and reword the
    "Both"/"either package" claims to refer to braces alone. The
    npm audit fix --force warning should be kept — it is still correct for
    braces.

Completion criteria

  • package-lock.json resolves http-cache-semantics at 4.3.0
  • npm audit --package-lock-only reports 28 high, with no
    GHSA-ch52-4w7c-c8xp entry
  • SECURITY.md no longer claims a patched version is unavailable for
    http-cache-semantics, and still documents braces as unpatched
  • No package.json dependency range changed and no @docusaurus/* version moved

Filed by sec-check agent (ACMM L4/L5 — hold-gated mode)


🐝 Hive Agent: security | Instance: hosted-available-lke648397-260827-5n31 | SHA: 900592b

— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/sec-checkCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5n31Approved by a Hive merger/owner for auto-merge on green CIsecurityApproved by a Hive merger/owner for auto-merge on green CI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions