Skip to content

fix(security): apply the published http-cache-semantics patch and correct SECURITY.md - #1050

Merged
mrbobbytables merged 1 commit into
mainfrom
sec/fix-http-cache-semantics
Oct 5, 2026
Merged

mrbobbytables merged 1 commit into
mainfrom
sec/fix-http-cache-semantics

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Security Fix

GHSA-ch52-4w7c-c8xp
("http-cache-semantics max-stale handling can disclose cross-user cached
responses") has the vulnerable range <= 4.2.0. Upstream has published
4.3.0, which falls outside it — but the lockfile was still pinned to the
vulnerable 4.2.0, and SECURITY.md told readers that no patched version
existed
for it and that there was "no upgrade to apply".

What this changes

package-lock.json — a lockfile-only bump produced by
npm update http-cache-semantics --package-lock-only. No package.json
dependency range is changed and no @docusaurus/* version moves:

node_modules/http-cache-semantics: 4.2.0 -> 4.3.0

http-cache-semantics is a leaf with no dependents constraining it
("effects": []), which is why it was the only one of the 29 audit entries npm
reported as "fixAvailable": true.

SECURITY.md — the Known unpatched dependency advisories section claimed
two advisories with no fix. Only braces is still genuinely unpatched
(3.0.3 remains the newest published release and GHSA-vfj7-8cjw-p6xm's range is
<= 3.0.3), so the section now describes one advisory instead of two, with the
count corrected from 34 to 28. The npm audit fix --force warning is kept — it
is still correct for braces. A short note records why the second row went
away, so the next reader does not re-add it.

Verification

Run in this worktree at the committed tree:

  • npm audit → 28 high, down from 29, with no GHSA-ch52-4w7c-c8xp entry
  • npm ci resolves node_modules/http-cache-semantics at 4.3.0
  • npm run test:unit → 1912 pass, 0 fail
  • npm run check:spelling, npm run check:markdown, npm run check:format all pass

Honest limitation

The GitHub advisory API still reports first_patched_version: null for
GHSA-ch52-4w7c-c8xp, so "4.3.0 is the fix" rests on the advisory's own
vulnerable_version_range (<= 4.2.0) plus npm's resolution against it, rather
than on an upstream patch note. The upstream repo path in the package manifest
(kornelski/http-cache-semantics) returns 404 for the compare API, so the
4.2.0...4.3.0 commit range could not be read. The observable effect — npm no
longer reports the advisory against the installed tree — is what is claimed here.

The exposure was build-time only (update-notifier reaches this package from
@docusaurus/core's version check; it is not bundled into the static output),
so the documentation defect was the larger problem: SECURITY.md was actively
instructing readers to stop looking for the fix that had already shipped.

Closes #1049


Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.

— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88

…rect SECURITY.md

GHSA-ch52-4w7c-c8xp has the vulnerable range <= 4.2.0, and upstream has
published 4.3.0. The lockfile was still pinned to 4.2.0 while SECURITY.md
told readers no patched version existed for it and that there was nothing
to apply.

Bump the lockfile only (no package.json range changed, no @docusaurus/*
version moved) and rewrite the advisory section to describe the one
advisory that is still genuinely unpatched, braces, whose 3.0.3 remains
the newest release.

npm audit goes from 29 high to 28, with no GHSA-ch52-4w7c-c8xp entry.

Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
@hivecommons-hive hivecommons-hive Bot added the hold label Oct 4, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will automatically remove the hold label once current policy no longer requires a level hold for "sec-check". If this is an outreach PR, a human must review it and remove the label.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] http-cache-semantics 4.3.0 patches GHSA-ch52-4w7c-c8xp, but the lockfile is still on 4.2.0 and SECURITY.md says no fix exists

1 participant