Skip to content

fix(deps): update brace-expansion to patched releases - #39

Open
frantuma wants to merge 1 commit into
mainfrom
fix/brace-expansion-dos-advisories
Open

frantuma wants to merge 1 commit into
mainfrom
fix/brace-expansion-dos-advisories

Conversation

@frantuma

@frantuma frantuma commented Oct 1, 2026

Copy link
Copy Markdown
Member

Change

The dependency-audit job fails on main (run 36873323031) with two findings. This PR addresses the first: brace-expansion is affected by GHSA-q2hr-2g5m-vwhr (quadratic-time {a},b} rewrite), GHSA-qhr7-859c-m2p7 (unbounded recursion on nested groups) and GHSA-6j4f-fj2g-mc7p (unbounded recursion in parseCommaParts), all denial-of-service issues.

Each of the eight copies in the tree moves to the patched release of its own major line: 1.1.18 to 1.1.21, 2.1.4 to 2.1.7, and 5.0.9 to 5.0.12. All the minimatch versions that depend on it already allow these releases (^1.1.7, ^2.0.1, ^5.0.x), so this is a lockfile-only change, made with npm update brace-expansion. It needs no package.json change and no overrides. The upstream diff is limited to the hardening itself: an iterative parseCommaParts plus depth and rewrite caps set well above realistic patterns. The new versions come from the same maintainer and add no dependencies or install scripts.

The audit marks every copy except the client one as dev-only, but two of them ship. The 2.x copy (via vscode-languageclient) is bundled into the client, and the 1.x copy (via @stoplight/spectral-core's minimatch) is bundled into both server builds. The bundle inventories now record 2.1.7 for the client and 1.1.21 for the server.

The second finding (serialize-javascript, low) is deliberately out of scope here, so dependency-audit will still fail on this PR until it is addressed separately.

Verification

I ran the build job's steps locally on Node 24.10.0 / npm 11.6.1 after a clean npm ci from the updated lockfile. All of them passed: check-version-sync, the lockfile consistency check (npm install --package-lock-only produces no diff), build:types, lint, typescript:check-types, test:tooling, build:prod, check-attribution, test:browser, test:previews, npm run test (server unit tests plus e2e, including the Spectral ruleset loading tests, with 0 failures), npm publish --dry-run --workspace=server and vscode:package. npm audit now reports only the serialize-javascript finding. The packaged vscode-openapi-toolkit-1.5.3.vsix has sha256 faa4b14e9ac647cd61b141e388f6e362f5c6a220b1fd7a99357fa0762592b08c.

  • Examples and attachments are suitable for public disclosure.
  • User-facing documentation reflects the change (no user-facing behavior change).

Resolves GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7 and GHSA-6j4f-fj2g-mc7p
(CPU and stack-exhaustion DoS), which fail the dependency-audit job.

Every copy moves to the patched release of its major line (1.1.21, 2.1.7,
5.0.12). The existing minimatch ranges already admit these versions, so only
the lockfile changes. The 1.x copy (via Spectral's minimatch) is bundled into
the server and the 2.x copy (via vscode-languageclient) into the client.
@frantuma
frantuma requested a review from char0n as a code owner October 1, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant