Why this is open rather than fixed
Dependabot alert #4 — brace-expansion, high, DoS via unbounded expansion causing
an out-of-memory crash (GHSA-mh99-v99m-4gvg). It is dismissed as tolerable risk,
not fixed, because there is currently no way to fix it. This issue exists so the
dismissal is not the end of the story.
Why there is no fix
The chain is:
@docusaurus/core -> serve-handler@6.1.7 -> minimatch@3.1.5 (brace-expansion ^1.1.7)
- The advisory covers
<= 5.0.7, and the patch exists only in 5.0.8. 1.1.16
is the newest release on the 1.x line and there is no backport, so the installed
version is already as far forward as 1.x goes.
minimatch@3.1.5 requires ^1.1.7, so it can never resolve to 5.x.
- An
overrides entry does not work either. 1.x exports the function directly
(module.exports = expandTop); 5.0.8's CommonJS build exports a named
expand (exports.expand = expand). minimatch@3.1.5 does
var expand = require('brace-expansion'); expand(pattern), which would throw
expand is not a function and break docusaurus serve.
@docusaurus/core is already at the latest 3.10.2, so there is no Docusaurus bump
to take.
Exposure
Low, and local-only. serve-handler runs under docusaurus serve — the local
preview of an already-built site — over this repository's own files. It is not on
the docusaurus build path, it is not in the deployed artifact, and nothing
published depends on it. docusaurus.config.ts sets future.faster, so the build
runs on Rspack, SWC and Lightning CSS.
What closes this
Either of:
brace-expansion backports the expansion-length bound to the 1.x line. The alert
was dismissed rather than added to .github/dependabot.yml's ignore list
specifically so that a backport raises a fresh alert instead of being swallowed.
- Docusaurus moves
serve-handler onto minimatch@10, or off serve-handler
altogether, at which point the override is unnecessary.
At that point, drop the corresponding paragraph from SECURITY.md's Dependency
advisories section.
Related
Alerts for serialize-javascript and uuid from the same sweep were fixable and
are pinned forward by overrides in website/package.json — see the
fix(website): pin serialize-javascript and uuid past their advisories PR. Those
overrides should be removed once Docusaurus ships the parent majors that carry
the fixes (css-minimizer-webpack-plugin@8, copy-webpack-plugin@14,
webpack-dev-server@6), so that is worth checking whenever this issue is revisited.
Why this is open rather than fixed
Dependabot alert #4 —
brace-expansion, high, DoS via unbounded expansion causingan out-of-memory crash (GHSA-mh99-v99m-4gvg). It is dismissed as tolerable risk,
not fixed, because there is currently no way to fix it. This issue exists so the
dismissal is not the end of the story.
Why there is no fix
The chain is:
<= 5.0.7, and the patch exists only in 5.0.8.1.1.16is the newest release on the 1.x line and there is no backport, so the installed
version is already as far forward as 1.x goes.
minimatch@3.1.5requires^1.1.7, so it can never resolve to 5.x.overridesentry does not work either. 1.x exports the function directly(
module.exports = expandTop); 5.0.8's CommonJS build exports a namedexpand(exports.expand = expand).minimatch@3.1.5doesvar expand = require('brace-expansion'); expand(pattern), which would throwexpand is not a functionand breakdocusaurus serve.@docusaurus/coreis already at the latest 3.10.2, so there is no Docusaurus bumpto take.
Exposure
Low, and local-only.
serve-handlerruns underdocusaurus serve— the localpreview of an already-built site — over this repository's own files. It is not on
the
docusaurus buildpath, it is not in the deployed artifact, and nothingpublished depends on it.
docusaurus.config.tssetsfuture.faster, so the buildruns on Rspack, SWC and Lightning CSS.
What closes this
Either of:
brace-expansionbackports the expansion-length bound to the 1.x line. The alertwas dismissed rather than added to
.github/dependabot.yml's ignore listspecifically so that a backport raises a fresh alert instead of being swallowed.
serve-handlerontominimatch@10, or offserve-handleraltogether, at which point the override is unnecessary.
At that point, drop the corresponding paragraph from
SECURITY.md's Dependencyadvisories section.
Related
Alerts for
serialize-javascriptanduuidfrom the same sweep were fixable andare pinned forward by
overridesinwebsite/package.json— see thefix(website): pin serialize-javascript and uuid past their advisoriesPR. Thoseoverrides should be removed once Docusaurus ships the parent majors that carry
the fixes (
css-minimizer-webpack-plugin@8,copy-webpack-plugin@14,webpack-dev-server@6), so that is worth checking whenever this issue is revisited.