diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2cd8119..2438cb7 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,6 +1,16 @@ name: Dependency Review + on: pull_request: + +permissions: + contents: read + jobs: review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@07ce007bad08fdcf07409a5f372baabda8781354 # main + with: + # brace-expansion OOM DoS: no in-range fix (patch only in 5.0.8; @11ty/recursive-copy + # pins minimatch <10.0.3). Build-time-only exposure, adjudicated in + # .security-review/suppressions.json — remove when recursive-copy bumps minimatch. + allow-ghsas: GHSA-mh99-v99m-4gvg diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json index 46f9dd9..b3a4e23 100644 --- a/.security-review/suppressions.json +++ b/.security-review/suppressions.json @@ -11,6 +11,22 @@ { "id": "gitleaks-generic-api-key-2464", "justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181." + }, + { + "id": "npmaudit-brace-expansion", + "justification": "Accepted risk. GHSA-mh99-v99m-4gvg (OOM DoS in glob brace expansion) has no in-range fix: the patch exists only in brace-expansion 5.0.8, and @11ty/recursive-copy@4.0.4 pins minimatch <10.0.3, which requires brace-expansion 1.x. Exposure is build-time only: Eleventy expands glob patterns from our own config, never untrusted input, so the DoS is not reachable by an attacker. REMOVE when @11ty/recursive-copy ships a minimatch >=10.0.3 bump (npm audit will go clean). GitHub Dependabot alerts remain active as the independent detector for any NEW advisory on this package." + }, + { + "id": "npmaudit-minimatch", + "justification": "Accepted risk. Not itself vulnerable; flagged only for depending on the vulnerable brace-expansion 1.x range (GHSA-mh99-v99m-4gvg, see npmaudit-brace-expansion). Same chain, same build-time-only exposure, same removal trigger. NOTE: id is package-keyed, so a future distinct minimatch advisory would also be masked locally; Dependabot alerts cover that gap." + }, + { + "id": "npmaudit-@11ty/recursive-copy", + "justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain — REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory." + }, + { + "id": "npmaudit-@11ty/eleventy", + "justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap." } ] } diff --git a/package-lock.json b/package-lock.json index 820c13f..a95946b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -344,9 +344,9 @@ } }, "node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.16", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.16.tgz", + "integrity": "sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==", "license": "MIT", "dependencies": { "balanced-match": "^1.0.0", @@ -922,9 +922,9 @@ } }, "node_modules/js-yaml": { - "version": "4.2.0", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz", - "integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==", + "version": "4.3.0", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz", + "integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==", "funding": [ { "type": "github", @@ -971,9 +971,9 @@ } }, "node_modules/linkify-it": { - "version": "5.0.1", - "resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.1.tgz", - "integrity": "sha512-wVoTjP4Q6R0NW5hiZkVJaFZPWgtXfoGF+6LucL3/FtiNjmcHhYjEr5f1Kqjirc1nBW07J/ZuRFumqr2oqccEWg==", + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.2.tgz", + "integrity": "sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==", "funding": [ { "type": "github", @@ -990,9 +990,9 @@ } }, "node_modules/liquidjs": { - "version": "10.27.0", - "resolved": "https://registry.npmjs.org/liquidjs/-/liquidjs-10.27.0.tgz", - "integrity": "sha512-tw/OA59K7aIBlMKIrKlumr37fiZUheShVHXY8cVctWisgY1p9mc5hreOvlreoS0wTiwlWk14Ya7305c2a/Cg5w==", + "version": "10.27.2", + "resolved": "https://registry.npmjs.org/liquidjs/-/liquidjs-10.27.2.tgz", + "integrity": "sha512-kvknfAEtOHjHkAAv7GxLEJh8ghpMQm3Fc4uWVyF7hERSTsSRsdC7saWs0p5aDG7GDcWsu5o+T4232O+8KZO55w==", "license": "MIT", "dependencies": { "commander": "^10.0.0"