diff --git a/.changeset/brave-orcas-rest.md b/.changeset/brave-orcas-rest.md new file mode 100644 index 000000000..f1057edd3 --- /dev/null +++ b/.changeset/brave-orcas-rest.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 2888 +--- +**Dev-dependency `brace-expansion` bumped to patched versions (1.1.18 / 5.0.9), resolving the high-severity DoS/OOM advisories** — the lockfile now pins the 2026-07-30 patch backports reachable via eslint and stryker. A non-breaking in-range bump (no overrides, no major bumps); production `npm audit --omit=dev` is unaffected (devDependency only). (#2765) diff --git a/package-lock.json b/package-lock.json index 230d9d369..027e5b418 100644 --- a/package-lock.json +++ b/package-lock.json @@ -815,9 +815,9 @@ "license": "MIT" }, "node_modules/@eslint/config-array/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -913,9 +913,9 @@ "license": "MIT" }, "node_modules/@eslint/eslintrc/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -2198,16 +2198,16 @@ } }, "node_modules/brace-expansion": { - "version": "5.0.6", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz", - "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==", + "version": "5.0.9", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", + "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", "dev": true, "license": "MIT", "dependencies": { "balanced-match": "^4.0.2" }, "engines": { - "node": "18 || 20 || >=22" + "node": "20 || >=22" } }, "node_modules/browserslist": { @@ -2887,9 +2887,9 @@ "license": "MIT" }, "node_modules/eslint/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { diff --git a/tests/issue-2765-brace-expansion-lockfile.test.cjs b/tests/issue-2765-brace-expansion-lockfile.test.cjs new file mode 100644 index 000000000..8f04a9584 --- /dev/null +++ b/tests/issue-2765-brace-expansion-lockfile.test.cjs @@ -0,0 +1,48 @@ +// allow-test-rule: structural-implementation-guard (#2765) +'use strict'; + +// Regression guard for #2765: the lockfile must pin the patched brace-expansion +// versions (>=1.1.18 for the 1.x line, >=5.0.9 for the 5.x line) published 2026-07-30 +// to resolve the high-severity DoS/OOM advisories (GHSA-3jxr-9vmj-r5cp / +// GHSA-mh99-v99m-4gvg, range <=5.0.7). This is a lockfile-only devDependency bump +// (eslint/stryker → minimatch → brace-expansion); production (npm audit --omit=dev) is +// unaffected. The test pins the installed versions so the bump can't silently regress. + +const { test } = require('node:test'); +const assert = require('node:assert/strict'); +const { execFileSync } = require('node:child_process'); +const path = require('node:path'); + +const ROOT = path.join(__dirname, '..'); + +function npmLs(pkg) { + // `npm ls --json --all` lists every installed copy with its version. Collect + // the version of every node whose key is `pkg` (not the parent packages). + const out = execFileSync('npm', ['ls', pkg, '--json', '--all'], { + cwd: ROOT, encoding: 'utf8', shell: true, stdio: ['ignore', 'pipe', 'ignore'], + }); + const versions = []; + const walk = (node) => { + if (!node || !node.dependencies) return; + for (const [k, v] of Object.entries(node.dependencies)) { + if (k === pkg && v && v.version) versions.push(v.version); + walk(v); + } + }; + walk(JSON.parse(out)); + return versions; +} + +test('all installed brace-expansion copies are patched (>=1.1.18 / >=5.0.9) — #2765', () => { + const versions = npmLs('brace-expansion'); + assert.ok(versions.length > 0, 'brace-expansion must be installed (devDependency) to guard'); + for (const v of versions) { + const [maj, min, pat] = v.split('.').map(Number); + const ok = (maj === 1 && (min > 1 || (min === 1 && pat >= 18))) // 1.x >= 1.1.18 + || (maj === 5 && (min > 0 || pat >= 9)) // 5.x >= 5.0.9 + || (maj > 5); // >5.x + assert.ok(ok, + `brace-expansion@${v} is within the vulnerable range (<=5.0.7) — lockfile regressed the #2765 patch bump. ` + + 'Re-apply: npm audit fix (non-breaking) to bump to 1.1.18 / 5.0.9.'); + } +});