Repository navigation
chore(frontend): patch js-yaml and nanoid advisories - #1729
Conversation
Two new high-severity npm advisories appeared since #1716 patched brace-expansion and fast-uri, reddening `npm audit --audit-level=high` on main and every open PR: - js-yaml (GHSA-5p4m-2wfm-xmqj): quadratic CPU consumption in !!omap resolution, pulled in transitively by eslint and by ts-jest's @istanbuljs/load-nyc-config. - nanoid (GHSA-2v37-7h3g-55p8): custom generators can loop indefinitely when size is zero, pulled in transitively by css-loader's postcss. Neither package is a direct dependency; both resolve within the existing semver ranges declared by their parents. `npm audit fix` bumped only the three affected lockfile entries (js-yaml 3.15.0 to 3.15.1, js-yaml 4.3.0 to 4.3.1, nanoid 3.3.16 to 3.3.18) with no change to package.json. Verified `npm audit --audit-level=high` exits 0 after the fix, `npm run build` succeeds, and the test suite is no worse: 8 failed / 2773 passed / 1 skipped, identical on this branch and on unmodified origin/main. The 8 failures are a pre-existing host-locale thousands-separator mismatch in riexchange.test.ts / approval-details.test.ts, filed as #1728. Refs #1712
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Merging without a CodeRabbit verdict, deliberately, with the reasoning recorded rather than waived. CodeRabbit has posted nothing on this PR at any head. The repo quota is per-developer, adaptive, and shared across the eight currently-open PRs; a push landing during a throttle is never auto-reviewed retroactively. Why waiting is the wrong trade here specifically:
The marginal value of a review bot on three version-number changes is low; the cost of holding seven PRs behind it is not. Advisories closed:
Both dev-only transitive dependencies, neither reachable from shipped production code. The recurring cost of this pattern - two advisory pairs in three days, all four dev-only, each needing a same-day emergency PR to unblock the queue - is filed as #1731 for a deliberate decision about what should gate merges. That issue explicitly does not propose |
Summary
Two new high-severity npm advisories have appeared since #1716 patched
brace-expansionandfast-uri, reddeningnpm audit --audit-level=highonmainand every open PR (same time-dependent pattern:npm auditqueries the live advisory database, so the same commit goes red the moment an advisory publishes):!!omapresolution)Fix
Lockfile-only, per the same approach as #1716. Neither package is a direct dependency:
js-yamlcomes in transitively viaeslintand viats-jest->@jest/transform->babel-plugin-istanbul->@istanbuljs/load-nyc-config.nanoidcomes in transitively viacss-loader->postcss.Both resolve within the semver ranges their parents already declare, so
npm audit fixbumped only the three affected lockfile entries with no change topackage.json:git diff package.jsonis empty;git diff package-lock.jsontouches exactly these threeversion/resolved/integritytriples (24 lines).Verification
Before (
npm audit --audit-level=high, exit 1):After (
npm audit --audit-level=high, exit 0):npm run build: succeeds (webpack compiles with the pre-existing entrypoint-size warning only, no errors).npm test: 8 failed / 2773 passed / 1 skipped, both on this branch and reproduced identically on unmodifiedorigin/mainin a separate clean worktree (before touching anything). Same failures, same counts, same locale-formatting mismatches ($1.200vs$1,200,$4.568vs$4,568,$30,00/movs$30.00/mo) — pre-existing, filed as fix(test/frontend): 8 tests assert the host locale's thousands separator, so they fail locally and pass in CI #1728, not affected by this change.Dependency-hygiene observation (reporting only, not fixing here)
This is the second advisory pair in three days (after #1716's
brace-expansion/fast-uri). All four advisories so far have landed on dev-only transitive dependencies (eslint, ts-jest/istanbul, css-loader/postcss, and #1716's pair) rather than anything in the production bundle — none are direct dependencies ofcudly-frontend. Worth keeping an eye on whether this keeps recurring at this cadence; if it does,#1712(where the scanner-decoupling work lives) might be the right place to consider decouplingnpm audit's live-advisory-DB dependency from the PR-blocking gate (e.g. running it as a non-blocking scheduled check instead), rather than each new advisory needing an emergency same-day lockfile PR to unblock the merge queue. Not attempting that here — flagging per your request, staying inside the blocking fix.Scope
frontend/package-lock.jsononly.package.jsonuntouched (no direct dependency range needed to move). Nofrontend/src/**changes.Refs #1712