chore(security): resolve open npm audit and code scanning alerts (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run

* build(deps): resolve npm audit advisories via in-range bumps

npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs
10.27.2, and brace-expansion 1.1.16 to clear four high DoS
advisories. Eleventy build verified passing at 3.1.6.

The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has
no in-range fix: the patch exists only in 5.0.8, and
@11ty/recursive-copy pins an older minimatch. Exposure is
build-time only (glob patterns from our own config, never
untrusted input), so it is suppressed with justification in
.security-review/suppressions.json rather than forcing the
eleventy downgrade npm audit fix --force proposes. Remove the
npmaudit-* suppressions when recursive-copy ships a minimatch
>=10.0.3 bump.

* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.

* ci(dependency-review): allow adjudicated brace-expansion GHSA

Re-pins the callable to 07ce007 (adds the allow-ghsas input, org
PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check
flags on the bumped-but-still-in-range brace-expansion 1.1.16.
The advisory has no in-range fix and is an accepted risk with
written justification in .security-review/suppressions.json;
remove the allowance together with those suppressions when
@11ty/recursive-copy ships a minimatch >=10.0.3 bump.
This commit is contained in:
Adam Moussa 2026-07-27 13:41:00 -04:00 • committed by GitHub
parent 761faceed7
commit 1b71f5f56e
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 39 additions and 13 deletions

View file

@ -1,6 +1,16 @@
name: Dependency Review name: Dependency Review
on: on:
pull_request: pull_request:
permissions:
contents: read
jobs: jobs:
review: review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@07ce007bad08fdcf07409a5f372baabda8781354 # main
with:
# brace-expansion OOM DoS: no in-range fix (patch only in 5.0.8; @11ty/recursive-copy
# pins minimatch <10.0.3). Build-time-only exposure, adjudicated in
# .security-review/suppressions.json — remove when recursive-copy bumps minimatch.
allow-ghsas: GHSA-mh99-v99m-4gvg

View file

@ -11,6 +11,22 @@
{ {
"id": "gitleaks-generic-api-key-2464", "id": "gitleaks-generic-api-key-2464",
"justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181." "justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181."
},
{
"id": "npmaudit-brace-expansion",
"justification": "Accepted risk. GHSA-mh99-v99m-4gvg (OOM DoS in glob brace expansion) has no in-range fix: the patch exists only in brace-expansion 5.0.8, and @11ty/recursive-copy@4.0.4 pins minimatch <10.0.3, which requires brace-expansion 1.x. Exposure is build-time only: Eleventy expands glob patterns from our own config, never untrusted input, so the DoS is not reachable by an attacker. REMOVE when @11ty/recursive-copy ships a minimatch >=10.0.3 bump (npm audit will go clean). GitHub Dependabot alerts remain active as the independent detector for any NEW advisory on this package."
},
{
"id": "npmaudit-minimatch",
"justification": "Accepted risk. Not itself vulnerable; flagged only for depending on the vulnerable brace-expansion 1.x range (GHSA-mh99-v99m-4gvg, see npmaudit-brace-expansion). Same chain, same build-time-only exposure, same removal trigger. NOTE: id is package-keyed, so a future distinct minimatch advisory would also be masked locally; Dependabot alerts cover that gap."
},
{
"id": "npmaudit-@11ty/recursive-copy",
"justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain — REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory."
},
{
"id": "npmaudit-@11ty/eleventy",
"justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap."
} }
] ]
} }

24
package-lock.json generated
View file

@ -344,9 +344,9 @@
} }
}, },
"node_modules/brace-expansion": { "node_modules/brace-expansion": {
"version": "1.1.15", "version": "1.1.16",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.16.tgz",
"integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "integrity": "sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"balanced-match": "^1.0.0", "balanced-match": "^1.0.0",
@ -922,9 +922,9 @@
} }
}, },
"node_modules/js-yaml": { "node_modules/js-yaml": {
"version": "4.2.0", "version": "4.3.0",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz", "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz",
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==", "integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==",
"funding": [ "funding": [
{ {
"type": "github", "type": "github",
@ -971,9 +971,9 @@
} }
}, },
"node_modules/linkify-it": { "node_modules/linkify-it": {
"version": "5.0.1", "version": "5.0.2",
"resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.1.tgz", "resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.2.tgz",
"integrity": "sha512-wVoTjP4Q6R0NW5hiZkVJaFZPWgtXfoGF+6LucL3/FtiNjmcHhYjEr5f1Kqjirc1nBW07J/ZuRFumqr2oqccEWg==", "integrity": "sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==",
"funding": [ "funding": [
{ {
"type": "github", "type": "github",
@ -990,9 +990,9 @@
} }
}, },
"node_modules/liquidjs": { "node_modules/liquidjs": {
"version": "10.27.0", "version": "10.27.2",
"resolved": "https://registry.npmjs.org/liquidjs/-/liquidjs-10.27.0.tgz", "resolved": "https://registry.npmjs.org/liquidjs/-/liquidjs-10.27.2.tgz",
"integrity": "sha512-tw/OA59K7aIBlMKIrKlumr37fiZUheShVHXY8cVctWisgY1p9mc5hreOvlreoS0wTiwlWk14Ya7305c2a/Cg5w==", "integrity": "sha512-kvknfAEtOHjHkAAv7GxLEJh8ghpMQm3Fc4uWVyF7hERSTsSRsdC7saWs0p5aDG7GDcWsu5o+T4232O+8KZO55w==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"commander": "^10.0.0" "commander": "^10.0.0"