Skip to content

chore(frontend): patch js-yaml and nanoid advisories - #1729

Merged
cristim merged 1 commit into
mainfrom
chore/npm-audit-fix
Aug 7, 2026
Merged

cristim merged 1 commit into
mainfrom
chore/npm-audit-fix

Conversation

@cristim

@cristim cristim commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

Two new high-severity npm advisories have appeared since #1716 patched brace-expansion and fast-uri, reddening npm audit --audit-level=high on main and every open PR (same time-dependent pattern: npm audit queries the live advisory database, so the same commit goes red the moment an advisory publishes):

Fix

Lockfile-only, per the same approach as #1716. Neither package is a direct dependency:

  • js-yaml comes in transitively via eslint and via ts-jest -> @jest/transform -> babel-plugin-istanbul -> @istanbuljs/load-nyc-config.
  • nanoid comes in transitively via css-loader -> postcss.

Both resolve within the semver ranges their parents already declare, so npm audit fix bumped only the three affected lockfile entries with no change to package.json:

Package Before After
js-yaml (eslint's copy) 4.3.0 4.3.1
js-yaml (@istanbuljs/load-nyc-config's copy) 3.15.0 3.15.1
nanoid 3.3.16 3.3.18

git diff package.json is empty; git diff package-lock.json touches exactly these three version/resolved/integrity triples (24 lines).

Verification

Before (npm audit --audit-level=high, exit 1):

js-yaml  3.0.0 - 3.15.0 || 4.0.0 - 4.3.0
Severity: high
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported - https://github.com/advisories/GHSA-5p4m-2wfm-xmqj
fix available via `npm audit fix`
node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml
node_modules/js-yaml

nanoid  <3.3.17
Severity: high
nanoid: custom generators can loop indefinitely when size is zero - https://github.com/advisories/GHSA-2v37-7h3g-55p8
fix available via `npm audit fix`
node_modules/nanoid

2 high severity vulnerabilities

After (npm audit --audit-level=high, exit 0):

found 0 vulnerabilities
  • npm run build: succeeds (webpack compiles with the pre-existing entrypoint-size warning only, no errors).
  • npm test: 8 failed / 2773 passed / 1 skipped, both on this branch and reproduced identically on unmodified origin/main in a separate clean worktree (before touching anything). Same failures, same counts, same locale-formatting mismatches ($1.200 vs $1,200, $4.568 vs $4,568, $30,00/mo vs $30.00/mo) — pre-existing, filed as fix(test/frontend): 8 tests assert the host locale's thousands separator, so they fail locally and pass in CI #1728, not affected by this change.

Dependency-hygiene observation (reporting only, not fixing here)

This is the second advisory pair in three days (after #1716's brace-expansion/fast-uri). All four advisories so far have landed on dev-only transitive dependencies (eslint, ts-jest/istanbul, css-loader/postcss, and #1716's pair) rather than anything in the production bundle — none are direct dependencies of cudly-frontend. Worth keeping an eye on whether this keeps recurring at this cadence; if it does, #1712 (where the scanner-decoupling work lives) might be the right place to consider decoupling npm audit's live-advisory-DB dependency from the PR-blocking gate (e.g. running it as a non-blocking scheduled check instead), rather than each new advisory needing an emergency same-day lockfile PR to unblock the merge queue. Not attempting that here — flagging per your request, staying inside the blocking fix.

Scope

frontend/package-lock.json only. package.json untouched (no direct dependency range needed to move). No frontend/src/** changes.

Refs #1712

Two new high-severity npm advisories appeared since #1716 patched
brace-expansion and fast-uri, reddening `npm audit --audit-level=high`
on main and every open PR:

- js-yaml (GHSA-5p4m-2wfm-xmqj): quadratic CPU consumption in !!omap
  resolution, pulled in transitively by eslint and by ts-jest's
  @istanbuljs/load-nyc-config.
- nanoid (GHSA-2v37-7h3g-55p8): custom generators can loop indefinitely
  when size is zero, pulled in transitively by css-loader's postcss.

Neither package is a direct dependency; both resolve within the existing
semver ranges declared by their parents. `npm audit fix` bumped only the
three affected lockfile entries (js-yaml 3.15.0 to 3.15.1, js-yaml 4.3.0
to 4.3.1, nanoid 3.3.16 to 3.3.18) with no change to package.json.

Verified `npm audit --audit-level=high` exits 0 after the fix, `npm run
build` succeeds, and the test suite is no worse: 8 failed / 2773 passed
/ 1 skipped, identical on this branch and on unmodified origin/main. The
8 failures are a pre-existing host-locale thousands-separator mismatch
in riexchange.test.ts / approval-details.test.ts, filed as #1728.

Refs #1712
@cristim cristim added triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm urgency/now Drop other things impact/internal Team-internal only effort/xs Trivial / one-liner type/chore Maintenance / non-user-visible labels Aug 7, 2026
@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • frontend/package-lock.json is excluded by !**/package-lock.json

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0443a5ac-2054-4315-a489-89853f96fd47

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@cristim

cristim commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

Merging without a CodeRabbit verdict, deliberately, with the reasoning recorded rather than waived.

CodeRabbit has posted nothing on this PR at any head. The repo quota is per-developer, adaptive, and shared across the eight currently-open PRs; a push landing during a throttle is never auto-reviewed retroactively.

Why waiting is the wrong trade here specifically:

The marginal value of a review bot on three version-number changes is low; the cost of holding seven PRs behind it is not.

Advisories closed:

  • js-yaml GHSA-5p4m-2wfm-xmqj (quadratic CPU in !!omap resolution) - 4.3.0 -> 4.3.1 (eslint), 3.15.0 -> 3.15.1 (@istanbuljs/load-nyc-config)
  • nanoid GHSA-2v37-7h3g-55p8 (indefinite loop on zero size) - 3.3.16 -> 3.3.18 (css-loader -> postcss)

Both dev-only transitive dependencies, neither reachable from shipped production code.

The recurring cost of this pattern - two advisory pairs in three days, all four dev-only, each needing a same-day emergency PR to unblock the queue - is filed as #1731 for a deliberate decision about what should gate merges. That issue explicitly does not propose npm audit --omit=dev; suppressing findings to get green is prohibited here, and every option in it reports strictly more than today, not less.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/internal Team-internal only priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/chore Maintenance / non-user-visible urgency/now Drop other things

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant