Skip to content

docs: clarify remediation for published security advisories - #12180

Merged
proggeramlug merged 2 commits into
PerryTS:mainfrom
jdalton:fix/security-advisory-followup
Oct 8, 2026
Merged

proggeramlug merged 2 commits into
PerryTS:mainfrom
jdalton:fix/security-advisory-followup

Conversation

@jdalton

@jdalton jdalton commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Impact

Give users a private vulnerability reporting path and clear upgrade guidance for both published advisories. GitHub can detect the new root SECURITY.md instead of displaying “No security policy detected.”

Before → after

  • No repository security policy → discoverable private reporting instructions, with useful reproduction details and no invented response SLA.
  • Two advisory cards with unclear current status → direct links and first patched versions: publish path traversal in 0.5.1159; JWT expiration in 0.5.1166.
  • Compiler upgrade alone could be mistaken for remediation → explicitly instruct users to rebuild and redistribute executables compiled with affected versions.

Investigation

Both vulnerabilities already have fixes on main. Publish validates artifact names and only permits server-provided local paths from loopback hubs (#4989). JWT expiry enforcement landed in #5008; the duplicate extension fix followed in #5072, and both native JWT implementations were subsequently removed in #10687 in favor of compiling the npm package.

These are published historical advisories, not unresolved code alerts. A PR cannot remove their cards or change advisory metadata. This PR documents the existing remediation and fixes the missing security policy; it does not claim a new runtime security fix.

Validation

Reviewed the advisory patched-version metadata and current publish sanitization/local-hub gate, including the existing traversal and loopback regression tests. Confirmed GitHub private vulnerability reporting is enabled. Documentation-only change; no runtime tests run.

@jdalton
jdalton marked this pull request as ready for review October 8, 2026 00:47
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 17559920-cb21-4474-811e-37e8db8880b4
📥 Commits

Reviewing files that changed from the base of the PR and between 09358c4 and 572c188.

📒 Files selected for processing (1)
  • SECURITY.md
 _______________________________________________________________________________________________________
< Start when you're ready. You've been building experience all your life. Don't ignore niggling doubts. >
 -------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@proggeramlug
proggeramlug merged commit a0a46e4 into PerryTS:main Oct 8, 2026
115 of 118 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants