* chore(#3238): bump js-yaml 4.3.0 -> 4.3.1 (GHSA-5p4m-2wfm-xmqj)
Dependabot alert 14. js-yaml 4.3.0 sits inside the vulnerable range
>=4.0.0 <4.3.1 of GHSA-5p4m-2wfm-xmqj -- high, CVSS 7.5
(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), CWE-407 Inefficient Algorithmic
Complexity.
resolveYamlOmap() enforces `!!omap` key uniqueness with a linear
objectKeys.indexOf() scan inside the per-element loop, so resolution is O(n^2)
in entry count. `!!omap` is registered in the DEFAULT schema, so a plain
yaml.load(untrustedInput) with no options is affected. The loop is synchronous,
so it blocks the event loop -- amplification is per-process, not per-request.
Same weakness as CVE-2026-59870, fixed in 5.x at 5.2.1 and only now backported
to the 3.x/4.x lines.
Reproduced locally against the installed 4.3.0, advisory PoC, default schema:
n= 5000 load= 22ms -
n=10000 load= 57ms 2.59x
n=20000 load= 199x 3.49x
n=40000 load= 768ms 3.86x <- ~4x per doubling = quadratic
After the bump, same machine, same PoC:
n= 5000 load= 33ms -
n=10000 load= 33ms 1.00x
n=20000 load= 49ms 1.48x
n=40000 load= 96ms 1.96x <- ~2x per doubling = linear
Duplicate-key rejection is preserved (YAMLException still raised), so the
upstream indexOf -> Set swap kept the semantics it was guarding.
Scope is development-only and stays that way: js-yaml is a devDependency and is
absent from package.json's `files` allowlist, so it never ships to consumers.
`npm audit --omit=dev` reported 0 vulnerabilities before this change and still
does; `npm audit` went 1 high -> 0.
Targeted install rather than `npm audit fix`, so the blast radius is auditable:
npm reports "changed 1 package", and the lockfile diff is 4 insertions /
4 deletions touching only js-yaml. The declared floor moves ^4.2.1 -> ^4.3.1 so
a future resolution cannot land back on a vulnerable 4.3.x -- the operative fix
is the lockfile, since npm ci is lockfile-driven.
Stayed on the v4-legacy line (4.3.1) rather than jumping to `latest` 5.2.3: 5.x
is a rewritten module layout and a separate change with its own blast radius.
The v4-legacy dist-tag exists precisely so 4.x consumers can take this patch.
Regression guard mirrors tests/issue-2765-brace-expansion-lockfile.test.cjs --
the repo's existing precedent for a dev-scope lockfile bump against a
high-severity DoS advisory. It walks `npm ls --json --all` so a transitive copy
left behind still fails, and carries a vacuity guard so an empty version list
cannot pass silently. No timing assertion: wall-clock assertions are barred by
the clock-seam rule and would be load-sensitive on shared benches, so the
measurements live in the diagnosis artifact instead.
Refs #3238
* fix(#3238): require 5.2.1 on the 5.x line; add the release-notes fragment
Three review findings, all fixed inline.
SPEC AXIS (the serious one): the guard's `(maj > 4)` clause accepted ANY 5.x.
GHSA-5p4m-2wfm-xmqj names only the 3.x and 4.x ranges, so the isolated
adversarial pass -- checking strictly against that advisory -- rated 5.0.0 as
correctly accepted. But the advisory's own body records that the SAME weakness
in the 5.x line is CVE-2026-59870 / GHSA-724g-mxrg-4qvm, fixed in 5.2.1. A
guard whose purpose is "this tree has no quadratic !!omap resolver" must
require 5.2.1 there too, or an accidental major bump to 5.0.0 silently
reintroduces the exact bug the test exists to prevent. The two reviewers
disagreed and the disagreement was load-bearing: taking only the adversarial
verdict would have shipped the hole.
ISOLATED ADVERSARIAL (item 4): Number('4.3.1-beta.1') produced NaN, and NaN
comparisons made the predicate return false. That failed safe, but by accident
rather than design, and majors outside {3,4} were reported vulnerable despite
being outside every advertised range. The predicate is now explicit -- build
metadata stripped, prerelease fails CLOSED (4.3.1-beta.1 sorts below 4.3.1 and
may predate the fix), unparseable fails closed, maj<3 accepted as predating the
affected lines.
Validated by a standalone harness over 27 version strings (12 accepted, 14
rejected, 1 build-metadata): all 27 agree with the advisory ranges. Boundary
rows on all three affected lines -- 3.15.0/3.15.1, 4.3.0/4.3.1, 5.2.0/5.2.1.
STANDARDS AXIS: the precedent this change mirrors, 54cb4145b (#2765, identical
dev-scope lockfile security bump), shipped `fix(#2765)` plus a
`.changeset/*.md` typed Fixed. This change was typed `chore` with no fragment.
Per CONTRIBUTING.md, `chore` is omitted from user-facing release notes
entirely, so a security fix would have merged invisibly. Adds the fragment
(type Fixed, pr:0 to be backfilled) and types this commit `fix`. Note the
changeset gate does not require a fragment for a package.json/tests diff
(`ok_no_user_facing_changes`) -- it is added because users should be told they
received a security patch, not to satisfy a gate.
Not fixed, recorded as not-a-defect: the near-duplication of
tests/issue-2765-brace-expansion-lockfile.test.cjs. The reviewer that raised it
also argued the repo's one-self-contained-guard-per-advisory convention is the
better call -- each advisory guard stays independently auditable and removable,
and a shared helper would couple unrelated advisories. Extracting it would also
be drive-by refactoring of a file this change only appends beside.
Refs #3238
* chore(#3238): backfill changeset PR number 3246
---------
Co-authored-by: sim <sim@local>
152 lines
8.2 KiB
JSON
152 lines
8.2 KiB
JSON
{
|
|
"name": "@opengsd/gsd-core",
|
|
"version": "1.10.0",
|
|
"description": "GSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.",
|
|
"main": ".opencode/plugins/gsd-core.js",
|
|
"bin": {
|
|
"gsd-core": "bin/install.js",
|
|
"gsd-tools": "gsd-core/bin/gsd-tools.cjs",
|
|
"gsd_run": "gsd-core/bin/gsd_run",
|
|
"gsd-mcp-server": "bin/gsd-mcp-server.js"
|
|
},
|
|
"files": [
|
|
"bin",
|
|
"commands",
|
|
"skills",
|
|
"gsd-core",
|
|
"assets",
|
|
"agents",
|
|
".claude-plugin",
|
|
".opencode",
|
|
"GEMINI.md",
|
|
"hooks",
|
|
"scripts",
|
|
"!scripts/gen-emitted-baseline.cjs",
|
|
"!scripts/qa-smell-ratchet.cjs",
|
|
"!scripts/live-config-guard.cjs",
|
|
"!scripts/run-tests.cjs",
|
|
"!scripts/affected-tests-lib.cjs",
|
|
"!scripts/run-affected-tests.cjs",
|
|
"pi",
|
|
"vscode"
|
|
],
|
|
"keywords": [
|
|
"claude",
|
|
"claude-code",
|
|
"ai",
|
|
"meta-prompting",
|
|
"context-engineering",
|
|
"spec-driven-development",
|
|
"codex",
|
|
"codex-cli"
|
|
],
|
|
"author": "OpenGSD",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/open-gsd/gsd-core.git"
|
|
},
|
|
"homepage": "https://github.com/open-gsd/gsd-core",
|
|
"bugs": {
|
|
"url": "https://github.com/open-gsd/gsd-core/issues"
|
|
},
|
|
"publishConfig": {
|
|
"access": "public"
|
|
},
|
|
"engines": {
|
|
"node": ">=22.0.0",
|
|
"npm": ">=10.0.0"
|
|
},
|
|
"dependencies": {
|
|
"@anthropic-ai/claude-agent-sdk": "^0.2.84",
|
|
"ws": "^8.21.0"
|
|
},
|
|
"devDependencies": {
|
|
"@eslint/js": "^9.39.4",
|
|
"@stryker-mutator/core": "^9.6.1",
|
|
"@types/node": "^22.19.19",
|
|
"c8": "^11.0.0",
|
|
"eslint": "^9.39.4",
|
|
"eslint-plugin-n": "^17.24.0",
|
|
"eslint-plugin-no-only-tests": "^3.4.0",
|
|
"fast-check": "^4.8.0",
|
|
"globals": "^16.5.0",
|
|
"js-yaml": "^4.3.1",
|
|
"typescript": "^6.0.3",
|
|
"typescript-eslint": "^8.60.0"
|
|
},
|
|
"overrides": {
|
|
"qs": ">=6.15.2",
|
|
"body-parser": ">=2.3.0",
|
|
"@hono/node-server": ">=2.0.5"
|
|
},
|
|
"optionalDependencies": {
|
|
"fallow": "^2.70.0"
|
|
},
|
|
"scripts": {
|
|
"sync:launcher": "node scripts/sync-runtime-launcher.cjs",
|
|
"check:env": "node scripts/check-env.cjs",
|
|
"check:alias-drift": "node scripts/check-alias-drift.cjs",
|
|
"check:identity-drift": "node scripts/lint-package-identity-drift.cjs",
|
|
"check:phase-id-drift": "node scripts/lint-phase-id-drift.cjs",
|
|
"check:integrity": "node scripts/check-npm-integrity.cjs",
|
|
"build": "npm run generate:identity && npm run build:lib && npm run gen:section-manifest && npm run gen:context-index && npm run gen:plugin-skills && npm run gen:loop-host-contract && npm run gen:capability-registry && npm run build:hooks",
|
|
"build:hooks": "node scripts/build-hooks.js",
|
|
"build:lib": "tsc -p tsconfig.build.json",
|
|
"generate:identity": "node scripts/generate-package-identity.cjs",
|
|
"gen:context-index": "node scripts/gen-context-index.cjs --write",
|
|
"gen:loop-host-contract": "node scripts/gen-loop-host-contract.cjs --write",
|
|
"gen:plugin-skills": "node scripts/gen-plugin-skills.cjs --write",
|
|
"gen:capability-registry": "node scripts/gen-capability-registry.cjs --write",
|
|
"gen:registry": "node scripts/gen-registry.cjs --write",
|
|
"gen:install-tree": "node scripts/gen-install-tree-fixtures.cjs",
|
|
"gen:section-manifest": "node scripts/gen-section-manifest.cjs --write",
|
|
"regen:derived": "npm run build && npm run gen:registry && node scripts/gen-adr-index.cjs --write && node scripts/gen-capability-matrix.cjs --write && node scripts/gen-inventory-manifest.cjs --write && node scripts/gen-context-index.cjs --write && npm run gen:section-manifest && node scripts/sync-manifest-versions.cjs && npm run gen:install-tree",
|
|
"validate:registry": "node scripts/validate-registry.cjs",
|
|
"prepack": "npm run build:lib",
|
|
"prepare": "npm run build:lib",
|
|
"version": "node scripts/sync-manifest-versions.cjs --stage && node scripts/gen-capability-registry.cjs --write && git add gsd-core/bin/lib/capability-registry.cjs",
|
|
"prepublishOnly": "npm run build:lib && npm run build:hooks",
|
|
"pretest": "npm run build:lib && npm run lint:skill-deps",
|
|
"pretest:coverage": "npm run build:lib && npm run lint:skill-deps",
|
|
"lint": "eslint . --cache --cache-location node_modules/.cache/eslint/",
|
|
"lint:fix": "eslint . --fix",
|
|
"lint:table-schema-drift": "node scripts/lint-table-schema-drift.cjs",
|
|
"lint:ci": "npm run lint && npm run lint:skill-deps && npm run lint:generated-sync && node scripts/lint-test-file-count.cjs && node scripts/lint-command-contract.cjs && node scripts/lint-pr-check-project-dir.cjs && npm run lint:legacy-name && node scripts/lint-regression-test-names.cjs && node scripts/lint-allow-test-rule-refs.cjs && node scripts/lint-resolution-provenance.cjs && node scripts/lint-emitted-drift-ack.cjs && node scripts/lint-portable-timeout.cjs && node scripts/validate-registry.cjs && node scripts/lint-table-schema-drift.cjs && node scripts/lint-fix-has-regression-test.cjs && node scripts/lint-example-parser-parity.cjs && node scripts/lint-docs-command-form.cjs && node scripts/lint-plan-count-drift.cjs && node scripts/lint-milestone-window-drift.cjs && node scripts/lint-phase-enumeration-drift.cjs && node scripts/lint-planning-prompt-drift.cjs && node scripts/lint-completion-ratio-drift.cjs",
|
|
"lint:allow-test-rule-refs": "node scripts/lint-allow-test-rule-refs.cjs",
|
|
"lint:regression-names": "node scripts/lint-regression-test-names.cjs",
|
|
"lint:descriptions": "node scripts/lint-descriptions.cjs",
|
|
"lint:skill-deps": "node scripts/lint-skill-deps.cjs",
|
|
"lint:test-file-count": "node scripts/lint-test-file-count.cjs",
|
|
"lint:pr-checks": "node scripts/lint-pr-check-project-dir.cjs",
|
|
"lint:changeset": "node scripts/changeset/lint.cjs",
|
|
"lint:generated-sync": "node scripts/gen-capability-registry.cjs --check && node scripts/gen-loop-host-contract.cjs --check && node scripts/gen-capability-matrix.cjs --check && node scripts/sync-manifest-versions.cjs --check && node scripts/gen-inventory-manifest.cjs --check && node scripts/generate-package-identity.cjs --check && node scripts/gen-plugin-skills.cjs --check && node scripts/gen-registry.cjs --check && node scripts/gen-adr-index.cjs --check && node scripts/check-glossary-refs.cjs --check && node scripts/lint-compiled-artifact-sync.cjs --check && node scripts/gen-context-index.cjs --check && node scripts/gen-section-manifest.cjs --check",
|
|
"lint:docs": "node scripts/lint-docs-required.cjs",
|
|
"lint:qa-smells": "node scripts/qa-smell-ratchet.cjs",
|
|
"lint:legacy-name": "node scripts/lint-legacy-dir-name.cjs",
|
|
"lint:docs-command-form": "node scripts/lint-docs-command-form.cjs",
|
|
"ci:test-scope": "node scripts/ci-test-scope.cjs",
|
|
"changeset": "node scripts/changeset/new.cjs",
|
|
"changelog:render": "node scripts/changeset/cli.cjs render",
|
|
"test": "node scripts/run-tests.cjs",
|
|
"test:unit": "node scripts/run-tests.cjs --suite unit",
|
|
"test:integration": "node scripts/run-tests.cjs --suite integration",
|
|
"test:install": "node scripts/run-tests.cjs --suite install",
|
|
"test:security": "node scripts/run-tests.cjs --suite security",
|
|
"test:slow": "node scripts/run-tests.cjs --suite slow",
|
|
"test:qa": "node scripts/run-tests.cjs --suite qa",
|
|
"test:affected": "node scripts/run-affected-tests.cjs",
|
|
"test:coverage": "c8 --check-coverage --lines 70 --branches 60 --reporter text --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all node scripts/run-tests.cjs",
|
|
"test:coverage:scripts-floor": "c8 check-coverage --lines 55 --include 'scripts/**/*.cjs' --exclude 'tests/**' --all",
|
|
"test:coverage:unit": "c8 --reporter text --reporter json-summary --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all node scripts/run-tests.cjs --suite unit && node scripts/check-coverage-gate.cjs",
|
|
"test:coverage:unit:raw": "c8 --reporter none node scripts/run-tests.cjs --suite unit",
|
|
"test:coverage:report": "c8 report --reporter text --reporter json-summary --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all && node scripts/check-coverage-gate.cjs",
|
|
"test:coverage:all": "npm run test:coverage",
|
|
"test:mutation": "stryker run",
|
|
"test:mutation:since": "stryker run --incremental --since origin/next"
|
|
},
|
|
"allowScripts": {
|
|
"fallow@2.70.0": true
|
|
}
|
|
}
|