diff --git a/.changeset/zesty-seals-click.md b/.changeset/zesty-seals-click.md new file mode 100644 index 000000000..c05bf7f00 --- /dev/null +++ b/.changeset/zesty-seals-click.md @@ -0,0 +1,5 @@ +--- +type: Security +pr: 4560 +--- +**Pinned the transitive `hono` dependency to `>=4.13.5`** — fixes a moderate-severity path-traversal/DoS advisory chain (GHSA-gqvv-2mrq-wpjv, GHSA-g6gw-c38x-mqfc, GHSA-crvj-82cr-hjcx) in `hono <4.13.5`, pulled in transitively via `@anthropic-ai/claude-agent-sdk` -> `@modelcontextprotocol/sdk`. Discovered as a newly-published advisory blocking `tests/npm-integrity-gate.test.cjs` while verifying an unrelated PR; fixed inline per this repo's no-defer policy rather than left for a separate PR. (#4513) diff --git a/eslint-rules/no-adhoc-timeout-literal.allowlist.json b/eslint-rules/no-adhoc-timeout-literal.allowlist.json index e76ddb85d..3c04f1103 100644 --- a/eslint-rules/no-adhoc-timeout-literal.allowlist.json +++ b/eslint-rules/no-adhoc-timeout-literal.allowlist.json @@ -26,7 +26,6 @@ "tests/code-review-pipeline-regression.test.cjs", "tests/code-review.test.cjs", "tests/commands.test.cjs", - "tests/commit-files-pathspec.test.cjs", "tests/config-get-default.test.cjs", "tests/cursor-hook-workspace-roots.test.cjs", "tests/cursor-hooks.test.cjs", @@ -46,8 +45,6 @@ "tests/gen-health-docs.test.cjs", "tests/gen-section-manifest.test.cjs", "tests/gen-state-md-docs.test.cjs", - "tests/git-base-branch.test.cjs", - "tests/git-fixture.test.cjs", "tests/graphify.test.cjs", "tests/gsd-check-update-worker-platform-gate.test.cjs", "tests/gsd-mcp-server-bin.test.cjs", diff --git a/package-lock.json b/package-lock.json index fce181925..38a77f2a1 100644 --- a/package-lock.json +++ b/package-lock.json @@ -3615,9 +3615,9 @@ } }, "node_modules/hono": { - "version": "4.13.0", - "resolved": "https://registry.npmjs.org/hono/-/hono-4.13.0.tgz", - "integrity": "sha512-jhunvfHWxd7J5EFfSgH4xsYJzSe/lfqbUCxiyyeaQasUsXeEHXtzVid+7EOGByc5JnFa23SSFL3Y2RV/z1T+eQ==", + "version": "4.13.7", + "resolved": "https://registry.npmjs.org/hono/-/hono-4.13.7.tgz", + "integrity": "sha512-c8/gF9ac8Y78/agExVocyLevgR+JlpNB444Py0FSX8pJoPdYUfUzRcXtYEYGwt6l19qIlVZPN5Mfsw9jFShmQQ==", "license": "MIT", "engines": { "node": ">=16.9.0" diff --git a/package.json b/package.json index 99019bdcc..e3cc83000 100644 --- a/package.json +++ b/package.json @@ -85,7 +85,8 @@ "overrides": { "qs": ">=6.15.2", "body-parser": ">=2.3.0", - "@hono/node-server": ">=2.0.5" + "@hono/node-server": ">=2.0.5", + "hono": ">=4.13.5" }, "optionalDependencies": { "fallow": "^2.70.0" diff --git a/tests/commit-files-pathspec.test.cjs b/tests/commit-files-pathspec.test.cjs index 7e6ed04ba..47f760190 100644 --- a/tests/commit-files-pathspec.test.cjs +++ b/tests/commit-files-pathspec.test.cjs @@ -22,7 +22,7 @@ const { createTempGitProject, cleanup, runGsdTools } = require('./helpers.cjs'); const { execFileSync } = require('node:child_process'); const { gitOrThrow } = require('./helpers/git-fixture.cjs'); // #3145: class-norm timeout, not a per-suite value — see helpers/timeouts.cjs. -const { GIT_TIMEOUT_MS } = require('./helpers/timeouts.cjs'); +const { GIT_TIMEOUT_MS, PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs'); const { bareCommandName, tokenize, shellDashCPayloads, commentPortion, ISSUE_REF_RE, declarationReason, isDeclared, isUntrackedDeclaration, @@ -433,6 +433,16 @@ describe('commit --files: pathspec honors declared scope (#2112)', () => { // shared DEFAULT_GIT_TIMEOUT_MS norm. const STAGING_GIT_TIMEOUT_MS = 5000; +/** + * `commitWithFailingAdd`/`subrepoCommitWithFailingAdd` below spawn + * `process.execPath -e