Skip to content

Frontend: fix vulnerabilities reported by pnpm audit - #1386

Merged
gusthoff merged 1 commit into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/pnpm/security-audit-fixes/2026-09-26
Sep 26, 2026
Merged

gusthoff merged 1 commit into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/pnpm/security-audit-fixes/2026-09-26

Conversation

@gusthoff

Copy link
Copy Markdown
Collaborator

pnpm audit reported 18 findings (10 high, 7 moderate, 1 low) across seven packages, all new advisories published since the 2026-07-24 pnpm-workspace.yaml overrides fix. Bump the four existing overrides and add three new ones.

Verified: pnpm audit now reports 0 vulnerabilities (was 18).

`pnpm audit` reported 18 findings (10 high, 7 moderate, 1 low) across
seven packages, all new advisories published since the 2026-07-24
`pnpm-workspace.yaml` overrides fix. Bump the four existing overrides
and add three new ones, each to the version its own advisories are
fixed at:

- `brace-expansion` ^5.0.7 -> ^5.0.9 (GHSA-rgw5-rvv9-x895, DoS via
  unbounded intermediate arrays)
- `fast-uri` -> ^3.1.6, new override (GHSA-7p8r-x3mc-p8w7,
  GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf,
  GHSA-jqff-g426-hqxp; host-confusion and SSRF issues, pulled in via
  `ajv`, used by webpack's schema validation)
- `js-yaml` ^4.3.0 -> ^4.3.2 (GHSA-5p4m-2wfm-xmqj,
  GHSA-2883-xcg3-v3hh; quadratic CPU consumption in merge-key/omap
  handling, pulled in via `webpack-cli`)
- `postcss-selector-parser` -> ^7.1.3, new override
  (GHSA-w9m9-85wc-3x92, DoS via uncontrolled AST recursion, pulled in
  via `css-loader`'s CSS-modules plugins)
- `qs` -> ^6.16.0, new override (GHSA-x5fp-wj9c-mxmx,
  GHSA-4mjr-xmp4-gh2g; array-limit bypass and isBuffer DoS, pulled in
  via `webpack-dev-server`'s `express` dependency)
- `svgo` ^4.0.2 -> ^4.1.0 (GHSA-w27v-7q3p-w38r, GHSA-4vpr-x523-8j87;
  `removeScripts` executable-content bypasses, pulled in via the
  production CSS minification pipeline)
- `undici` ^7.28.0 -> ^7.29.0 (GHSA-4cwx-7wf7-3272 plus four moderate
  advisories; cache/cookie/CRLF handling issues, pulled in via
  `jsdom` for the mocha test suite's DOM environment)

All seven are transitive dependencies of build and test tooling only
(webpack, its plugins, and jsdom); none ship in the compiled site
bundle.

Verified: `pnpm audit` now reports 0 vulnerabilities (was 18).
`pnpm run cover` (126 passing, coverage unchanged at 99.94%
statements / 97.42% branches), `pnpm run production` (clean compile,
unchanged pre-existing bundle-size warnings), and `pnpm run eslint`
(0 problems) all behave identically to before the overrides.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@gusthoff
gusthoff force-pushed the dev/topic/infrastructure/pnpm/security-audit-fixes/2026-09-26 branch from 7721cbe to 92fbeee Compare September 26, 2026 00:00
@gusthoff
gusthoff merged commit 2c8c725 into AdaCore:main Sep 26, 2026
9 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant