fix(deps): close security advisories to bring CI back to green - #5
Merged
Merged
Conversation
Bumps guzzlehttp/guzzle 7.11.0->7.15.5, guzzlehttp/psr7 2.11.0->2.13.1, league/commonmark 2.8.2->2.10.1, and phpseclib/phpseclib 3.0.52->3.0.57 within their existing composer.json constraints. All four packages had composer audit advisories (guzzle high/medium host/cookie handling, commonmark high DoS/XSS, psr7 medium host confusion/CRLF, phpseclib medium SSRF via X.509 AIA). No composer.json range changed and no major version moved. Pest suite (33 tests, including IngestionPipelineTest covering MarkdownParser) and Pint pass unchanged, confirming the commonmark bump does not alter ingestion behavior. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Adds npm overrides to force pacote 20.0.0 -> 20.0.1 (its only change is tar ^6.1.11 -> ^7.5.10) and tar -> ^7.5.21, closing the critical node-tar hardlink/symlink path-traversal advisory (GHSA-34x7-hfp2-rc4v and related) that affected @angular/cli's transitive pacote/cacache/ node-gyp dependency chain. pacote's own package.json pins tar via a caret range that 7.5.21 satisfies once pacote is on 20.0.1; @angular/cli itself pins pacote at an exact "20.0.0", so the pacote bump is a justified one-patch override, not a range violation of any package that still resolves tar through it, and pacote 20.0.0->20.0.1 changes no other dependency (diff-checked). Angular itself stays on 19.x, unchanged. Runs `npm audit fix` (non-force) to close the shell-quote, ws, socket.io-parser/engine.io/socket.io-adapter, and serialize-javascript high advisories pulled in by karma/webpack-dev-server/jest-environment- jsdom dev tooling; all within already-declared devDependency ranges, no package.json range changed beyond the overrides above. `npm audit --audit-level=critical` now exits 0. 32 vulnerabilities remain (2 low, 13 moderate, 17 high): all require a major bump of @angular/cli or @angular-devkit/build-angular (21.x/22.x) which is out of scope. Angular framework packages (core/common/compiler/forms/ platform-*/router) cannot be bumped past 19.2.25 either: it is the last version ever published on the 19.x line, despite advisory data listing "<=19.2.25" as the affected range. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problema
O CI da
mainestava vermelho desde o merge do PR #1: os dois jobs falhavam na auditoria de dependências, sem nenhum teste quebrado.Correção
Atualização de locks dentro das majors atuais. Nenhum
composer.jsonalterado, nenhum gate afrouxado, nenhum teste desabilitado.Backend (só
composer.lock) — 22 advisories fechadas:Frontend — a vulnerabilidade critical (
tar, path traversal) foi fechada viaoverrides:Os overrides
"pacote": "20.0.1"e"tar": "^7.5.21"existem porque@angular/cli@19.2.27fixapacoteem20.0.0exato, cuja dependênciatar ^6.1.11está numa linha que nunca recebeu patch de segurança. A única diferença entrepacote20.0.0 e 20.0.1 étar: ^6.1.11 -> ^7.5.10.pacoteé usado apenas porng update/ng add, nunca em build, teste ou runtime. Forçar20.0.1está fora do pin exato do CLI e foi aceito como exceção consciente, registrada em ADR.Não corrigido (registrado como risco, conforme ADR-24)
As advisories high/moderate restantes são da toolchain e do runtime Angular e só fecham com upgrade de major (
@angular/*@22.x,@angular-devkit/build-angular@21.2.24+).19.2.25é a última versão publicada da linha 19 dos pacotes de runtime. Exceções:@sigstore/signe@sigstore/verifytêm fix disponível e ficam como pendência.Verificação
Instalação limpa em container com paridade de CI (PHP 8.3, Node 22):
composer audit-> exit 0, "No security vulnerability advisories found."npm ci+npm audit --audit-level=critical-> exit 0tsc --noEmit, lint, Jest 15/15, build SSRIngestionPipelineTestpassa, confirmando que o bump do CommonMark não altera a ingestãosuccessno SHA3c1095bAuditoria adversarial independente: APROVADO nos 9 itens do roteiro.
Pendências (fora deste PR)
actions/checkout@v4eactions/setup-node@v4ubuntu-latestpara Ubuntu 26 em outubro de 2026@sigstore/signe@sigstore/verifycom fix disponível32 warnings, 1 passed(condição de ambiente do runner) enquanto localmente dá33 passed🤖 Generated with Claude Code