mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 05:23:18 +00:00
chore(security): resolve open npm audit and code scanning alerts (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs 10.27.2, and brace-expansion 1.1.16 to clear four high DoS advisories. Eleventy build verified passing at 3.1.6. The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has no in-range fix: the patch exists only in 5.0.8, and @11ty/recursive-copy pins an older minimatch. Exposure is build-time only (glob patterns from our own config, never untrusted input), so it is suppressed with justification in .security-review/suppressions.json rather than forcing the eleventy downgrade npm audit fix --force proposes. Remove the npmaudit-* suppressions when recursive-copy ships a minimatch >=10.0.3 bump. * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match. * ci(dependency-review): allow adjudicated brace-expansion GHSA Re-pins the callable to 07ce007 (adds the allow-ghsas input, org PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check flags on the bumped-but-still-in-range brace-expansion 1.1.16. The advisory has no in-range fix and is an accepted risk with written justification in .security-review/suppressions.json; remove the allowance together with those suppressions when @11ty/recursive-copy ships a minimatch >=10.0.3 bump.
This commit is contained in:
parent
761faceed7
commit
1b71f5f56e
3 changed files with 39 additions and 13 deletions
12
.github/workflows/dependency-review.yml
vendored
12
.github/workflows/dependency-review.yml
vendored
|
|
@ -1,6 +1,16 @@
|
|||
name: Dependency Review
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
review:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@07ce007bad08fdcf07409a5f372baabda8781354 # main
|
||||
with:
|
||||
# brace-expansion OOM DoS: no in-range fix (patch only in 5.0.8; @11ty/recursive-copy
|
||||
# pins minimatch <10.0.3). Build-time-only exposure, adjudicated in
|
||||
# .security-review/suppressions.json — remove when recursive-copy bumps minimatch.
|
||||
allow-ghsas: GHSA-mh99-v99m-4gvg
|
||||
|
|
|
|||
|
|
@ -11,6 +11,22 @@
|
|||
{
|
||||
"id": "gitleaks-generic-api-key-2464",
|
||||
"justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181."
|
||||
},
|
||||
{
|
||||
"id": "npmaudit-brace-expansion",
|
||||
"justification": "Accepted risk. GHSA-mh99-v99m-4gvg (OOM DoS in glob brace expansion) has no in-range fix: the patch exists only in brace-expansion 5.0.8, and @11ty/recursive-copy@4.0.4 pins minimatch <10.0.3, which requires brace-expansion 1.x. Exposure is build-time only: Eleventy expands glob patterns from our own config, never untrusted input, so the DoS is not reachable by an attacker. REMOVE when @11ty/recursive-copy ships a minimatch >=10.0.3 bump (npm audit will go clean). GitHub Dependabot alerts remain active as the independent detector for any NEW advisory on this package."
|
||||
},
|
||||
{
|
||||
"id": "npmaudit-minimatch",
|
||||
"justification": "Accepted risk. Not itself vulnerable; flagged only for depending on the vulnerable brace-expansion 1.x range (GHSA-mh99-v99m-4gvg, see npmaudit-brace-expansion). Same chain, same build-time-only exposure, same removal trigger. NOTE: id is package-keyed, so a future distinct minimatch advisory would also be masked locally; Dependabot alerts cover that gap."
|
||||
},
|
||||
{
|
||||
"id": "npmaudit-@11ty/recursive-copy",
|
||||
"justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain — REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory."
|
||||
},
|
||||
{
|
||||
"id": "npmaudit-@11ty/eleventy",
|
||||
"justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap."
|
||||
}
|
||||
]
|
||||
}
|
||||
|
|
|
|||
24
package-lock.json
generated
24
package-lock.json
generated
|
|
@ -344,9 +344,9 @@
|
|||
}
|
||||
},
|
||||
"node_modules/brace-expansion": {
|
||||
"version": "1.1.15",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz",
|
||||
"integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==",
|
||||
"version": "1.1.16",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.16.tgz",
|
||||
"integrity": "sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"balanced-match": "^1.0.0",
|
||||
|
|
@ -922,9 +922,9 @@
|
|||
}
|
||||
},
|
||||
"node_modules/js-yaml": {
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"version": "4.3.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz",
|
||||
"integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==",
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
|
|
@ -971,9 +971,9 @@
|
|||
}
|
||||
},
|
||||
"node_modules/linkify-it": {
|
||||
"version": "5.0.1",
|
||||
"resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.1.tgz",
|
||||
"integrity": "sha512-wVoTjP4Q6R0NW5hiZkVJaFZPWgtXfoGF+6LucL3/FtiNjmcHhYjEr5f1Kqjirc1nBW07J/ZuRFumqr2oqccEWg==",
|
||||
"version": "5.0.2",
|
||||
"resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.2.tgz",
|
||||
"integrity": "sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==",
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
|
|
@ -990,9 +990,9 @@
|
|||
}
|
||||
},
|
||||
"node_modules/liquidjs": {
|
||||
"version": "10.27.0",
|
||||
"resolved": "https://registry.npmjs.org/liquidjs/-/liquidjs-10.27.0.tgz",
|
||||
"integrity": "sha512-tw/OA59K7aIBlMKIrKlumr37fiZUheShVHXY8cVctWisgY1p9mc5hreOvlreoS0wTiwlWk14Ya7305c2a/Cg5w==",
|
||||
"version": "10.27.2",
|
||||
"resolved": "https://registry.npmjs.org/liquidjs/-/liquidjs-10.27.2.tgz",
|
||||
"integrity": "sha512-kvknfAEtOHjHkAAv7GxLEJh8ghpMQm3Fc4uWVyF7hERSTsSRsdC7saWs0p5aDG7GDcWsu5o+T4232O+8KZO55w==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"commander": "^10.0.0"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue