Skip to content

fix(deps): resolve brace-expansion, http-cache-semantics and serialize-javascript Snyk/npm-audit findings (+Claude) - #238

Merged
dhruv-parekh-cs merged 1 commit into
developmentfrom
CL-snyk-fixes/05-Oct-2026
Oct 5, 2026
Merged

dhruv-parekh-cs merged 1 commit into
developmentfrom
CL-snyk-fixes/05-Oct-2026

Conversation

@dhruv-parekh-cs

Copy link
Copy Markdown

What changed

Automated snyk-fix run (05-Oct-2026), Node surface only (launch-cli has one package.json, no Go, no Dockerfile). Based on development.

Fixes

Ecosystem Finding Severity Package Before -> after Bucket Rationale
Node SNYK-JS-BRACEEXPANSION-20244948 high brace-expansion (via @oclif/core > minimatch@10.2.5) 5.0.9 -> 5.0.12 non-fixable (override) minimatch@10.2.5 override floor raised ^5.0.9 -> ^5.0.12
Node SNYK-JS-BRACEEXPANSION-20244952 high brace-expansion 5.0.9 -> 5.0.12 non-fixable (override) same override
Node SNYK-JS-BRACEEXPANSION-20244950 medium brace-expansion 5.0.9 -> 5.0.12 non-fixable (override) same override (fixed in 5.0.12)
Node same advisories, 2.x and 1.x lines high/medium brace-expansion 2.1.4 -> 2.1.7, 1.1.18 -> 1.1.21 non-fixable (override) minimatch@9.0.9, minimatch@5.1.9 floors ^2.1.4 -> ^2.1.7; brace-expansion@1 floor ^1.1.18 -> ^1.1.21, so a fresh install cannot resolve a vulnerable release
Node npm audit (http-cache-semantics max-stale disclosure) high http-cache-semantics (via oclif > got > cacheable-request) 4.2.0 -> 4.3.0 lockfile refresh in-range; found by npm audit, not by Snyk
Node npm audit (serialize-javascript XSS) low serialize-javascript (via mocha) 7.1.1 -> 7.1.2 lockfile refresh in-range under existing ^7.1.0 override

All ranges are carets (loosest safe floor).

Ecosystem-native audit (step 1.5)

  • npm audit: 43 (1 low, 5 moderate, 37 high) -> 40 (5 moderate, 35 high) after this PR. The remainder is documented under "needs human review".
  • npm audit fix (no --force) was run first. It resolved the advisories above but also bumped @oclif/core 4.11.14 -> 4.14.0, @contentstack/cli-command/cli-utilities, oclif, @oclif/plugin-not-found and plugin-warn-if-update-available, none of which carried an advisory. @oclif/core@4.14.0 makes all 6 suites of npm run test:integration fail (A dynamic import callback was invoked without --experimental-vm-modules), reproduced on a clean origin/development checkout with only that package bumped. Those unrelated bumps were therefore discarded and only the advisory-backed ones kept (http-cache-semantics, serialize-javascript, brace-expansion), applied by targeted npm update plus the override edits.
  • npm audit declined as breaking (left in place): braces <=3.0.3 (GHSA-vfj7-8cjw-p6xm, high, no patched 3.x exists) reached via micromatch from lint-staged, jest, oclif, shx (all devDependencies); npm's only offered fix is a major bump of those tools.

Retired overrides (step 2.5)

Removed from package.json overrides: ajv, fast-uri, proxy-addr, istanbul-lib-processinfo.uuid. Evidence: with each removed, a fresh resolve and the real tree still land at or above the old floor on their own (ajv@8.20.0 via conf, fast-uri@3.1.8 via ajv, proxy-addr@2.0.8 via express), and istanbul-lib-processinfo@3.0.1 no longer depends on uuid at all. npm ls and the Snyk re-scan are clean for these. The qs override was also tested and is NOT obsolete: express@4.22.2 pins qs ~6.15.1, so without it the tree drops to qs@6.15.3. It was restored and left as is. Other overrides (eslint/@eslint/eslintrc ajv, tmp, serialize-javascript, diff) are still doing work and untouched.

Lockfile note

brace-expansion@1 is now installed as nested copies (with balanced-match@1.0.2) instead of one hoisted copy, because npm install re-evaluated placement once the minimatch@10.2.5 subtree moved to 5.0.12. Versions all satisfy their ranges; npm ci is clean.

Self code review (step 7.5)

2 rounds. Round 1 findings: (Medium) unrelated @oclif/core/oclif/cli-command bumps from npm audit fix and the integration-test regression they cause -> fixed by dropping them; (Medium) qs override retired but still required -> restored. Round 2 found no High/Medium issues. Low: lockfile placement churn noted above. No application code changed, no comments added, no workflow or Dockerfile changes (no Node/Go version moved, so .github/workflows needed no sync).

Needs human review (not resolved by this PR)

  • SNYK-JS-DEEPMERGE-19964053 (high, prototype pollution) in deepmerge@4.3.1 via @rollup/plugin-node-resolve@16.0.3. No fixed version exists upstream.
  • SNYK-JS-CSVPARSE-19639017 (medium, prototype pollution) in csv-parse@4.16.3 via @contentstack/cli-utilities > tty-table > csv@5.5.3. Fixed in 7.0.2, but forcing an override across three majors against csv@5's expected API cannot be validated by this repo's tests and could change behavior; needs a human decision (or an upstream tty-table/cli-utilities release).
  • npm audit only: braces chain above (devDependency majors: lint-staged 16, jest 30, oclif, shx).

Warnings / environment

  • npm audit fix and npm view return 403 for @contentstack/cli-command through the repo-local GitHub Packages .npmrc mapping, although the lockfile resolves all @contentstack/* from registry.npmjs.org. Worked around per command with --@contentstack:registry=https://registry.npmjs.org; .npmrc was not modified.
  • npm run lint reports 107 pre-existing errors in untouched src/ files (unchanged by this PR).

Validation

npm ci, npm run build, npm test (139 unit tests + 31 integration tests) pass. snyk test --all-projects (1 project, 463 dependencies) is clean for every fixed finding; only the two needs-human-review ids above remain.

#claude_code#
🤖 Generated with Claude Code

…e-javascript Snyk/npm-audit findings (+Claude)

Raise the brace-expansion override floors to the patched releases
(^5.0.12, ^2.1.7, ^1.1.21) for SNYK-JS-BRACEEXPANSION-20244948,
-20244950 and -20244952, and refresh http-cache-semantics (4.3.0) and
serialize-javascript (7.1.2) in the lockfile.

Retire the ajv, fast-uri, proxy-addr and istanbul-lib-processinfo
overrides, which no longer change what the tree resolves.

#claude_code#
🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
@dhruv-parekh-cs
dhruv-parekh-cs requested review from a team as code owners October 5, 2026 07:57
Copilot AI balanced review requested due to automatic review settings October 5, 2026 07:57
@snyk-io

snyk-io Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 1 25 ✅ Passed
🟡 Medium Severity 0 2 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 0
  • High without fixes: 1
  • Medium without fixes: 2
  • Low without fixes: 0

✅ BUILD PASSED - All security checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The targeted manifest and lockfile changes are consistent, with no blocking issues identified and passing validation reported.

Review effort: Balanced
Findings: None

What changed in this PR

Addresses dependency security advisories in the Launch CLI without changing application code.

Changes:

  • Raises brace-expansion override floors to patched releases.
  • Updates http-cache-semantics and serialize-javascript in the lockfile.
  • Removes obsolete overrides while retaining those still needed.
File Description
package.json Raises security override floors and removes obsolete overrides.
package-lock.json Records patched dependencies and updated placement of nested packages.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dhruv-parekh-cs
dhruv-parekh-cs merged commit 65a22fa into development Oct 5, 2026
9 checks passed
@dhruv-parekh-cs
dhruv-parekh-cs deleted the CL-snyk-fixes/05-Oct-2026 branch October 5, 2026 09:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants