Skip to content

deps: revisit brace-expansion when Docusaurus moves serve-handler off minimatch@3 #5

Description

@MarcusKainth

Why this is open rather than fixed

Dependabot alert #4 — brace-expansion, high, DoS via unbounded expansion causing
an out-of-memory crash (GHSA-mh99-v99m-4gvg). It is dismissed as tolerable risk,
not fixed, because there is currently no way to fix it. This issue exists so the
dismissal is not the end of the story.

Why there is no fix

The chain is:

@docusaurus/core -> serve-handler@6.1.7 -> minimatch@3.1.5 (brace-expansion ^1.1.7)
  • The advisory covers <= 5.0.7, and the patch exists only in 5.0.8. 1.1.16
    is the newest release on the 1.x line and there is no backport, so the installed
    version is already as far forward as 1.x goes.
  • minimatch@3.1.5 requires ^1.1.7, so it can never resolve to 5.x.
  • An overrides entry does not work either. 1.x exports the function directly
    (module.exports = expandTop); 5.0.8's CommonJS build exports a named
    expand (exports.expand = expand). minimatch@3.1.5 does
    var expand = require('brace-expansion'); expand(pattern), which would throw
    expand is not a function and break docusaurus serve.

@docusaurus/core is already at the latest 3.10.2, so there is no Docusaurus bump
to take.

Exposure

Low, and local-only. serve-handler runs under docusaurus serve — the local
preview of an already-built site — over this repository's own files. It is not on
the docusaurus build path, it is not in the deployed artifact, and nothing
published depends on it. docusaurus.config.ts sets future.faster, so the build
runs on Rspack, SWC and Lightning CSS.

What closes this

Either of:

  • brace-expansion backports the expansion-length bound to the 1.x line. The alert
    was dismissed rather than added to .github/dependabot.yml's ignore list
    specifically so that a backport raises a fresh alert instead of being swallowed.
  • Docusaurus moves serve-handler onto minimatch@10, or off serve-handler
    altogether, at which point the override is unnecessary.

At that point, drop the corresponding paragraph from SECURITY.md's Dependency
advisories
section.

Related

Alerts for serialize-javascript and uuid from the same sweep were fixable and
are pinned forward by overrides in website/package.json — see the
fix(website): pin serialize-javascript and uuid past their advisories PR. Those
overrides should be removed once Docusaurus ships the parent majors that carry
the fixes (css-minimizer-webpack-plugin@8, copy-webpack-plugin@14,
webpack-dev-server@6), so that is worth checking whenever this issue is revisited.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions