Repository navigation
docs+fix(security): resolve web/ decode-uri-component chain, document braces/elliptic as accepted risk - #87
Merged
Conversation
…risk npm audit flags braces@3.0.3 (GHSA-vfj7-8cjw-p6xm, via @clarigen/cli -> chokidar) as high severity. Investigated rather than silently bumped: braces has never published a patched version (3.0.3 is its latest ever release), and the only suggested remediation downgrades @clarigen/cli to 0.2.4 -- four major versions back, API-incompatible with this repo's test harness (tests/clarigen-setup.ts uses the 4.x projectFactory/TestProvider API). The vulnerable path is only reachable through clarigen's own local dev-time file-watching, never external input, so exploitability here is negligible. Recorded as DEP-1 in FINDINGS_REGISTER.md instead of leaving the CI signal unexplained.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…e findings web/'s npm audit reports 26 vulnerabilities across three independent chains: braces (via tailwindcss/eslint-config-next, same unfixable upstream shape as DEP-1), decode-uri-component (via query-string -> @WalletConnect -> @reown/ appkit -> @stacks/connect), and elliptic (via bip322-js/bitcoinjs-message/ secp256k1, same chain). Unlike braces, decode-uri-component has a patched 0.5.0 release upstream -- query-string's own package.json just still declares ^0.4.1, so it never resolves there naturally. Forced via the overrides block already used in this file for @types/react and viem. Verified: 26 vulnerabilities (4 low, 15 moderate, 7 high) -> 15 (8 low, 7 high); every moderate finding in this chain cleared, including the @reown/appkit*/@walletconnect/* entries that were only flagged transitively. npm run build and lint both still pass. elliptic itself has no patched release to move to (6.6.1 is latest ever, same unfixable-upstream shape as braces) and @stacks/connect@8.2.7 (latest available) pins @reown/appkit at an exact 1.7.17, so that sub-chain stays open -- documented as DEP-2 in FINDINGS_REGISTER.md alongside DEP-1, which this commit also extends to cover web/'s copy of the braces chain (same root cause reached through a second package.json, not a separate issue). Note: web/package-lock.json's diff includes ~90 lines of npm-version-churn (optional-dependency "libc" platform hints disappearing) unrelated to this override -- a side effect of regenerating the lockfile with a locally installed npm different from whatever produced the committed one. Content- wise this is a one-line override addition; verified functionally via a clean npm ci + npm run build + npm run lint.
…t-braces-fix # Conflicts: # docs/security/FINDINGS_REGISTER.md
Resolves the FINDINGS_REGISTER.md conflict with #88 (keeps both the updated F-9 row and DEP-1/DEP-2). Also applies Hillary's fix: the root Dependency Audit step can fail by design, which skipped "Audit web dependencies" in the same job for every red root run -- web/'s own 26 findings went unsurfaced in CI the whole time. if: always() on the web step fixes it; Hillary flagged this but couldn't push it himself (no workflow scope on his token). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
npm audit checks live advisory data, not a snapshot -- re-running it a day after the original DEP-1/DEP-2 investigation surfaced 3 advisories published since: source-map-js (high, GHSA-68fv-2mgg-jv7q) and postcss-nested/postcss-selector-parser (moderate, same tailwindcss@3.4.19 chain as DEP-1 already covers). source-map-js has a clean, non-major patched release (1.2.2) reachable via the same overrides mechanism as decode-uri-component -- fixed. Verified: web/npm audit 18 -> 17, build still produces all 6 pages. The two PostCSS findings fold into DEP-1's existing story, not a new item. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Another advisory published after DEP-1/DEP-2 were scoped: sharp <0.35.5 (high, librsvg CVE-2026-96889). sharp is an optional dependency of next (^0.35.4), so 0.35.5 is in range -- lockfile-only update via `npm update sharp --package-lock-only`, no override needed. Only sharp and its @img/* platform packages change. Verified: web/ npm audit 18 -> 17; the remaining highs are all the accepted braces chain (tailwindcss / eslint-config-next, DEP-1). `npm ci && npm run build` still produces all 6 pages.
mattglory
approved these changes
Oct 7, 2026
mattglory
left a comment
Owner
There was a problem hiding this comment.
Re-verified after merging main (picks up #90/#91) and the sharp fix (10dd953):
- source-map-js/decode-uri-component web overrides still correct post-merge, no conflict with root's own independent fix via #91 (confirmed these are two separate instances of the advisory, different dependency chains).
- Full suite: 279 passed + 1 expected fail. web/ build: all 6 pages generate.
- web/ npm audit: confirmed sharp's GHSA-wq5f-xc86-pv6w no longer appears.
Approving.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Started as a root-only
braces/@clarigen/cliinvestigation (triggered by #86's CI); expanded once checkingweb/'s ownnpm auditsurfaced 26 findings that had never run in CI (the root audit step failing halted the job before the web step ran).Root (
DEP-1, unfixed, accepted risk):braces@3.0.3is the latest version ever published — the advisory covers its entire release history, so there's no patched version for@clarigen/clito move to. The only suggested remediation is a 4-major-version downgrade that's API-incompatible withtests/clarigen-setup.ts. Not applied.web/(DEP-1extended + newDEP-2): samebracesroot cause reachesweb/a second way (tailwindcss,eslint-config-next→fast-glob/micromatch) — same accepted-risk conclusion, all dev/build-time tooling, never shipped to users. Separately,web/'s wallet-connect stack (@stacks/connect→@reown/appkit→@walletconnect/*→query-string→decode-uri-component, and →bip322-js/bitcoinjs-message→secp256k1→elliptic) does ship to the browser, so it got a real look rather than a shrug:decode-uri-component@0.2.2(moderate, ReDoS) is fixable —0.5.0exists upstream;query-stringjust hasn't bumped its own declared range yet. Forced viaoverridesinweb/package.json(same mechanism already used there for@types/react/viem).elliptic@6.6.1(low, risky crypto primitive) is not fixable the same way — it's the latest version ever published, same shape asbraces.@stacks/connect@8.2.7(latest available) pins@reown/appkitat an exact1.7.17, so there's no newer@stacks/connectrelease to move to either. Left open, documented asDEP-2.Result
web/npm audit: 26 vulnerabilities (4 low, 15 moderate, 7 high) → 15 (8 low, 7 high). Every moderate-severity finding is cleared, including all the@reown/appkit*/@walletconnect/*entries that were only flagged transitively throughdecode-uri-component. Remaining 15 are the two unfixable-upstream chains (bracesdevtools,ellipticcrypto primitive), both now documented rather than silently red.Test plan
npm ci(web/) +npm auditbefore/after confirms the count dropnpm run build— compiles and generates all 6 static pages successfullynpm run lint— pre-existing, unrelated failure confirmed present on main too (not a regression from this change)decode-uri-component@0.5.0is zero-dependency and a drop-in security patch, not an API rewrite🤖 Generated with Claude Code