Repository navigation
fix(security): apply the published http-cache-semantics patch and correct SECURITY.md - #1050
Merged
Merged
Conversation
…rect SECURITY.md GHSA-ch52-4w7c-c8xp has the vulnerable range <= 4.2.0, and upstream has published 4.3.0. The lockfile was still pinned to 4.2.0 while SECURITY.md told readers no patched version existed for it and that there was nothing to apply. Bump the lockfile only (no package.json range changed, no @docusaurus/* version moved) and rewrite the advisory section to describe the one advisory that is still genuinely unpatched, braces, whose 3.0.3 remains the newest release. npm audit goes from 29 high to 28, with no GHSA-ch52-4w7c-c8xp entry. Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
This was referenced Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
GHSA-ch52-4w7c-c8xp
("
http-cache-semanticsmax-stale handling can disclose cross-user cachedresponses") has the vulnerable range
<= 4.2.0. Upstream has published4.3.0, which falls outside it — but the lockfile was still pinned to thevulnerable
4.2.0, andSECURITY.mdtold readers that no patched versionexisted for it and that there was "no upgrade to apply".
What this changes
package-lock.json— a lockfile-only bump produced bynpm update http-cache-semantics --package-lock-only. Nopackage.jsondependency range is changed and no
@docusaurus/*version moves:http-cache-semanticsis a leaf with no dependents constraining it(
"effects": []), which is why it was the only one of the 29 audit entries npmreported as
"fixAvailable": true.SECURITY.md— theKnown unpatched dependency advisoriessection claimedtwo advisories with no fix. Only
bracesis still genuinely unpatched(
3.0.3remains the newest published release and GHSA-vfj7-8cjw-p6xm's range is<= 3.0.3), so the section now describes one advisory instead of two, with thecount corrected from 34 to 28. The
npm audit fix --forcewarning is kept — itis still correct for
braces. A short note records why the second row wentaway, so the next reader does not re-add it.
Verification
Run in this worktree at the committed tree:
npm audit→ 28 high, down from 29, with no GHSA-ch52-4w7c-c8xp entrynpm ciresolvesnode_modules/http-cache-semanticsat4.3.0npm run test:unit→ 1912 pass, 0 failnpm run check:spelling,npm run check:markdown,npm run check:formatall passHonest limitation
The GitHub advisory API still reports
first_patched_version: nullforGHSA-ch52-4w7c-c8xp, so "4.3.0 is the fix" rests on the advisory's own
vulnerable_version_range(<= 4.2.0) plus npm's resolution against it, ratherthan on an upstream patch note. The upstream repo path in the package manifest
(
kornelski/http-cache-semantics) returns 404 for the compare API, so the4.2.0...4.3.0 commit range could not be read. The observable effect — npm no
longer reports the advisory against the installed tree — is what is claimed here.
The exposure was build-time only (
update-notifierreaches this package from@docusaurus/core's version check; it is not bundled into the static output),so the documentation defect was the larger problem:
SECURITY.mdwas activelyinstructing readers to stop looking for the fix that had already shipped.
Closes #1049
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88