Skip to content

fix(security): pin browserslist to 4.28.8 - #42

Merged
vins13pattar merged 1 commit into
mainfrom
claude/fix-browserslist-advisory
Sep 3, 2026
Merged

vins13pattar merged 1 commit into
mainfrom
claude/fix-browserslist-advisory

Conversation

@vins13pattar

Copy link
Copy Markdown
Owner

Summary

pnpm audit --audit-level high is failing on main and on every open PR, on two newly-published high advisories against browserslist:

Advisory Impact Vulnerable Patched
GHSA-c83g-rgw3-j3cx Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM <=4.28.6 >=4.28.7
GHSA-73wf-gq98-2v4g Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) <=4.28.6 >=4.28.7

Both are reached through a single path: apps/web > autoprefixer@10.5.0 > browserslist@4.28.2. It is a build-time dependency — autoprefixer uses it to decide which CSS prefixes to emit — so neither advisory is reachable at runtime in a deployed service. The check is still red, and it gates every PR.

This adds a pnpm override pinning 4.28.8 (latest published, satisfies >=4.28.7), matching how esbuild, hono, ip-address, nanoid, postcss, sharp and shell-quote are already pinned in this repo:

   "overrides": {
+      "browserslist": "4.28.8",
     "esbuild": "0.28.1",

The lockfile change stays inside the browserslist graph — browserslist 4.28.2 → 4.28.8, update-browserslist-db 1.2.3 → 1.3.1, plus its data packages (caniuse-lite, electron-to-chromium, node-releases, baseline-browser-mapping). Nothing else moved.

Found while opening #41 (a docs-only change), whose dependency-audit failed for this reason. That PR is blocked until this lands.

Security and privacy

  • No credentials, real IMEIs, customer locations, or production data are included. The diff is a version pin and a regenerated lockfile.
  • Authentication, tenant isolation, and input-validation impacts were considered. None — browserslist is a build-time input to autoprefixer's CSS prefixing and touches no request path, database identity, or validation logic. This change closes two advisories and opens none.

Verification

Run locally against this branch:

  • pnpm audit --audit-level high — exits 0. Before: 1 low | 1 moderate | 2 high (exit 1). After: 1 low | 1 moderate (exit 0). The remaining low and moderate findings are below the CI threshold and are unchanged by this PR.
  • pnpm install --frozen-lockfile — resolves cleanly, so package.json and pnpm-lock.yaml agree.
  • pnpm typecheck — not run locally; no TypeScript changed. Covered by the verify job.
  • pnpm test — not run locally; no application code changed. Covered by the verify job.
  • pnpm build — not run locally. This is the one worth a reviewer's attention: a browserslist bump can in principle change autoprefixer's emitted CSS. It is a patch-level bump within the same minor, so I expect no visible change, but the verify job's production build is the real check here rather than anything I ran.
  • Relevant database/RLS or protocol tests were run — not applicable; no database or protocol code changed.

🤖 Generated with Claude Code

https://claude.ai/code/session_016i4eitqukrs4RQwtvkTPU2


Generated by Claude Code

pnpm audit --audit-level high fails on two high-severity advisories
against browserslist <=4.28.6, reached through apps/web > autoprefixer:

- GHSA-c83g-rgw3-j3cx: unbounded memory growth (no cache eviction) via
  distinct query results, leading to eventual OOM
- GHSA-73wf-gq98-2v4g: uncaught crash / prototype write via untrusted
  browserslist-stats.json custom stats (normalizeStats)

Both are patched in >=4.28.7. Adds a pnpm override pinning 4.28.8,
matching how esbuild, hono, ip-address, nanoid, postcss, sharp and
shell-quote are already pinned, and regenerates the lockfile.

The lockfile change is confined to the browserslist graph: browserslist
4.28.2 -> 4.28.8, update-browserslist-db 1.2.3 -> 1.3.1, and its data
packages (caniuse-lite, electron-to-chromium, node-releases,
baseline-browser-mapping). Nothing else moved.

Verified: pnpm audit --audit-level high now exits 0 (2 high -> 0 high;
the remaining low and moderate findings are below the CI threshold and
unchanged), and pnpm install --frozen-lockfile resolves cleanly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016i4eitqukrs4RQwtvkTPU2
@vins13pattar
vins13pattar merged commit 498defc into main Sep 3, 2026
8 checks passed
@vins13pattar
vins13pattar deleted the claude/fix-browserslist-advisory branch September 3, 2026 13:53
vins13pattar pushed a commit that referenced this pull request Sep 3, 2026
Brings in the browserslist advisory pin (#42) so dependency-audit runs
against the fixed lockfile.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016i4eitqukrs4RQwtvkTPU2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants