Skip to content

chore(deps): fix Trivy security findings - #426

Merged
appleboy merged 1 commit into
masterfrom
chore/fix-trivy-npm-dependencies
Oct 6, 2026
Merged

appleboy merged 1 commit into
masterfrom
chore/fix-trivy-npm-dependencies

Conversation

@appleboy

@appleboy appleboy commented Oct 6, 2026

Copy link
Copy Markdown
Member

Summary

Fix nine Trivy vulnerability records in four transitive npm dependencies. Require patched versions through the existing overrides mechanism and refresh only their lockfile entries:

Dependency Before After
devalue 5.9.2 5.9.4
postcss-selector-parser 6.1.4 7.1.6
smol-toml 1.8.0 1.9.0
source-map-js 1.2.1 1.2.2

The selector parser fix requires the 7.x line; upstream documents the CPU exhaustion fix in 7.1.6. Scan severity, scanners, and ignore policy are unchanged.

Plan and related issues

Scope: eliminate current Trivy findings with focused dependency updates and verify the documentation site still builds. No issue identifiers were supplied.

AI authorship

  • AI was used: OpenAI Codex.
  • AI-authored files: package.json, package-lock.json.
  • Human line-by-line reviewed: None — not yet reviewed by a human.

Change classification

  • Leaf change: dependencies of this static documentation site's build; no shared Go library or public API changes.
  • Recommend one maintainer reviewer, especially for the selector-parser major-version override.

Verification

Checkout chore/fix-trivy-npm-dependencies (head 255691f9e21ca79ce59c3c64bbb4ad5e0ca4b25d) in a disposable checkout. Run from the repository root with Node 22 (tested 22.23.3), npm 11.11.0, and Trivy 0.69.3. Trivy DB was updated at 2026-10-06 13:07 UTC.

Command Expected behavior Observed result
npm ci --no-audit --no-fund Locked dependencies install Passed; 283 packages installed
npm run build Static site, search index and sitemap generated Passed; 1,226 pages generated
trivy fs --scanners vuln,secret,misconfig --severity CRITICAL,HIGH,MEDIUM --ignore-unfixed --exit-code 1 --skip-dirs node_modules --skip-dirs dist --skip-dirs .git . No findings at the CI threshold, exit 0 Passed on clean tracked source; nine findings before, zero after
git diff --check master...HEAD No whitespace errors Passed

The scan was performed on exported tracked source before installing packages; the skip directories above reproduce that scope after building. Existing npm warnings remain for the deprecated starlight-utils/astro-integration-kit packages and their Astro peer range; installation and build succeed.

Selector-parser compatibility regression

With dependencies installed, run:

node --input-type=module <<'JS'
import assert from 'node:assert/strict';
import postcss from 'postcss';
import nested from 'postcss-nested';
const cases = [
  ['.parent { & .child { color: red; } }', '.parent .child'],
  ['.parent { &:is(.a, .b) { color: red; } }', '.parent:is(.a, .b)'],
  ['.parent { &[data-label="a,b"] { color: red; } }', '.parent[data-label="a,b"]'],
];
for (const [css, selector] of cases) {
  const result = await postcss([nested]).process(css, { from: undefined });
  assert.ok(result.css.includes(selector), result.css);
}
await assert.rejects(postcss([nested]).process('.parent { &:is( { color: red; } }', { from: undefined }));
console.log('PASS');
JS

Expected: nested, pseudo-class and attribute selectors retain their meaning; malformed CSS rejects; command prints PASS and exits 0. Observed: Passed on Node 22. No production data or deployment involved; dispose of the test checkout after verification.

Security, risk and rollback

  • No secrets or unrelated files in the diff.
  • External interfaces and permission logic are unchanged.
  • Main risk: selector-parser 7.x compatibility with postcss-nested 6.x; full build and focused selector checks pass.
  • Roll back by reverting this commit, which also restores the vulnerable versions.
  • Review package.json overrides carefully and spot-check the four lockfile version/integrity updates.

- Require patched versions of four vulnerable transitive dependencies
- Refresh locked versions without changing scan thresholds
@appleboy
appleboy merged commit ca38d12 into master Oct 6, 2026
2 checks passed
@appleboy
appleboy deleted the chore/fix-trivy-npm-dependencies branch October 6, 2026 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant