Skip to content

fix(deps): close security advisories to bring CI back to green - #5

Merged
LuanTrindade95 merged 2 commits into
mainfrom
fix/ci-dependency-advisories
Sep 20, 2026
Merged

LuanTrindade95 merged 2 commits into
mainfrom
fix/ci-dependency-advisories

Conversation

@LuanTrindade95

Copy link
Copy Markdown
Owner

Problema

O CI da main estava vermelho desde o merge do PR #1: os dois jobs falhavam na auditoria de dependências, sem nenhum teste quebrado.

Correção

Atualização de locks dentro das majors atuais. Nenhum composer.json alterado, nenhum gate afrouxado, nenhum teste desabilitado.

Backend (só composer.lock) — 22 advisories fechadas:

Pacote Antes Depois
guzzlehttp/guzzle 7.11.0 7.15.5
guzzlehttp/psr7 2.11.0 2.13.1
league/commonmark 2.8.2 2.10.1
phpseclib/phpseclib 3.0.52 3.0.57

Frontend — a vulnerabilidade critical (tar, path traversal) foi fechada via overrides:

Categoria Antes Depois
Critical 1 0
High 30 17
Moderate 17 13
Low 3 2

Os overrides "pacote": "20.0.1" e "tar": "^7.5.21" existem porque @angular/cli@19.2.27 fixa pacote em 20.0.0 exato, cuja dependência tar ^6.1.11 está numa linha que nunca recebeu patch de segurança. A única diferença entre pacote 20.0.0 e 20.0.1 é tar: ^6.1.11 -> ^7.5.10. pacote é usado apenas por ng update/ng add, nunca em build, teste ou runtime. Forçar 20.0.1 está fora do pin exato do CLI e foi aceito como exceção consciente, registrada em ADR.

Não corrigido (registrado como risco, conforme ADR-24)

As advisories high/moderate restantes são da toolchain e do runtime Angular e só fecham com upgrade de major (@angular/*@22.x, @angular-devkit/build-angular@21.2.24+). 19.2.25 é a última versão publicada da linha 19 dos pacotes de runtime. Exceções: @sigstore/sign e @sigstore/verify têm fix disponível e ficam como pendência.

Verificação

Instalação limpa em container com paridade de CI (PHP 8.3, Node 22):

  • composer audit -> exit 0, "No security vulnerability advisories found."
  • npm ci + npm audit --audit-level=critical -> exit 0
  • Pint 115 files, Pest 33 passed (191 assertions), tsc --noEmit, lint, Jest 15/15, build SSR
  • IngestionPipelineTest passa, confirmando que o bump do CommonMark não altera a ingestão
  • CI na branch: run 35474423377, Backend e Frontend success no SHA 3c1095b

Auditoria adversarial independente: APROVADO nos 9 itens do roteiro.

Pendências (fora deste PR)

  • Avisos de depreciação do Node 20 em actions/checkout@v4 e actions/setup-node@v4
  • Migração do ubuntu-latest para Ubuntu 26 em outubro de 2026
  • @sigstore/sign e @sigstore/verify com fix disponível
  • Upgrade da toolchain Angular para fechar as highs remanescentes
  • Pest no CI reporta 32 warnings, 1 passed (condição de ambiente do runner) enquanto localmente dá 33 passed

🤖 Generated with Claude Code

LuanTrindade95 and others added 2 commits September 19, 2026 15:32
Bumps guzzlehttp/guzzle 7.11.0->7.15.5, guzzlehttp/psr7 2.11.0->2.13.1,
league/commonmark 2.8.2->2.10.1, and phpseclib/phpseclib 3.0.52->3.0.57
within their existing composer.json constraints. All four packages had
composer audit advisories (guzzle high/medium host/cookie handling,
commonmark high DoS/XSS, psr7 medium host confusion/CRLF, phpseclib
medium SSRF via X.509 AIA). No composer.json range changed and no major
version moved. Pest suite (33 tests, including IngestionPipelineTest
covering MarkdownParser) and Pint pass unchanged, confirming the
commonmark bump does not alter ingestion behavior.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Adds npm overrides to force pacote 20.0.0 -> 20.0.1 (its only change is
tar ^6.1.11 -> ^7.5.10) and tar -> ^7.5.21, closing the critical
node-tar hardlink/symlink path-traversal advisory (GHSA-34x7-hfp2-rc4v
and related) that affected @angular/cli's transitive pacote/cacache/
node-gyp dependency chain. pacote's own package.json pins tar via a
caret range that 7.5.21 satisfies once pacote is on 20.0.1; @angular/cli
itself pins pacote at an exact "20.0.0", so the pacote bump is a
justified one-patch override, not a range violation of any package that
still resolves tar through it, and pacote 20.0.0->20.0.1 changes no
other dependency (diff-checked). Angular itself stays on 19.x, unchanged.

Runs `npm audit fix` (non-force) to close the shell-quote, ws,
socket.io-parser/engine.io/socket.io-adapter, and serialize-javascript
high advisories pulled in by karma/webpack-dev-server/jest-environment-
jsdom dev tooling; all within already-declared devDependency ranges, no
package.json range changed beyond the overrides above.

`npm audit --audit-level=critical` now exits 0. 32 vulnerabilities
remain (2 low, 13 moderate, 17 high): all require a major bump of
@angular/cli or @angular-devkit/build-angular (21.x/22.x) which is out
of scope. Angular framework packages (core/common/compiler/forms/
platform-*/router) cannot be bumped past 19.2.25 either: it is the last
version ever published on the 19.x line, despite advisory data listing
"<=19.2.25" as the affected range.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@LuanTrindade95
LuanTrindade95 merged commit 8623fea into main Sep 20, 2026
4 checks passed
@LuanTrindade95
LuanTrindade95 deleted the fix/ci-dependency-advisories branch September 23, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant