Conversation
Resolves GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7 and GHSA-6j4f-fj2g-mc7p (CPU and stack-exhaustion DoS), which fail the dependency-audit job. Every copy moves to the patched release of its major line (1.1.21, 2.1.7, 5.0.12). The existing minimatch ranges already admit these versions, so only the lockfile changes. The 1.x copy (via Spectral's minimatch) is bundled into the server and the 2.x copy (via vscode-languageclient) into the client.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
The
dependency-auditjob fails onmain(run 36873323031) with two findings. This PR addresses the first:brace-expansionis affected by GHSA-q2hr-2g5m-vwhr (quadratic-time{a},b}rewrite), GHSA-qhr7-859c-m2p7 (unbounded recursion on nested groups) and GHSA-6j4f-fj2g-mc7p (unbounded recursion inparseCommaParts), all denial-of-service issues.Each of the eight copies in the tree moves to the patched release of its own major line: 1.1.18 to 1.1.21, 2.1.4 to 2.1.7, and 5.0.9 to 5.0.12. All the
minimatchversions that depend on it already allow these releases (^1.1.7,^2.0.1,^5.0.x), so this is a lockfile-only change, made withnpm update brace-expansion. It needs nopackage.jsonchange and nooverrides. The upstream diff is limited to the hardening itself: an iterativeparseCommaPartsplus depth and rewrite caps set well above realistic patterns. The new versions come from the same maintainer and add no dependencies or install scripts.The audit marks every copy except the client one as dev-only, but two of them ship. The 2.x copy (via
vscode-languageclient) is bundled into the client, and the 1.x copy (via@stoplight/spectral-core'sminimatch) is bundled into both server builds. The bundle inventories now record 2.1.7 for the client and 1.1.21 for the server.The second finding (
serialize-javascript, low) is deliberately out of scope here, sodependency-auditwill still fail on this PR until it is addressed separately.Verification
I ran the build job's steps locally on Node 24.10.0 / npm 11.6.1 after a clean
npm cifrom the updated lockfile. All of them passed:check-version-sync, the lockfile consistency check (npm install --package-lock-onlyproduces no diff),build:types,lint,typescript:check-types,test:tooling,build:prod,check-attribution,test:browser,test:previews,npm run test(server unit tests plus e2e, including the Spectral ruleset loading tests, with 0 failures),npm publish --dry-run --workspace=serverandvscode:package.npm auditnow reports only theserialize-javascriptfinding. The packagedvscode-openapi-toolkit-1.5.3.vsixhas sha256faa4b14e9ac647cd61b141e388f6e362f5c6a220b1fd7a99357fa0762592b08c.