fix(deps): brace-expansion 钉到 5.0.12(CVE-2026-102276/102277/102278) - #345
Conversation
osv-scanner 在 main(8519f57)上报出三条告警,全部落在 brace-expansion@5.0.9:
两个栈耗尽型 DoS(102276 的 parseCommaParts 无界递归与 push.apply 大数组、
102278 的嵌套花括号递归)与一个二次时间 CPU DoS(102277 的 {a},b} 重写循环)。
三条都只影响可用性,不涉及代码执行或数据泄露。
该包只经开发依赖进入:c8(覆盖率)→ test-exclude → minimatch →
brace-expansion。npm ls --omit=dev 为空,package.json 的 dependencies 只有
morphicons,发布产物的 files 也不含 lockfile——安装本插件的用户拿不到这段
代码。且触发这三个洞都需要把精心构造的字符串当 glob 模式喂给 expand(),在
c8 里这个输入来自项目自己的覆盖率配置,外部不可控。故真实风险≈0,但告警会
一直挂在 Security 页面。
按仓库既有做法(adm-zip 同样走 overrides 钉版本)加一条 overrides 到 5.0.12:
三个洞分别修在 5.0.10 / 5.0.11 / 5.0.12,5.0.12 一版全清;minimatch 声明的
是 ^5.0.8,其余依赖无需改动。改动只有 package.json 与 package-lock.json。
测试 1437 项:1436 通过 / 0 失败 / 1 跳过。
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: slow-stack/mneme/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughdsh-mneme 的依赖覆盖配置新增 Changes依赖版本覆盖
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The dependency pin addresses the reported vulnerabilities without an evident resolution or runtime compatibility mismatch. No material merge risk remains; installation and runtime execution were not independently performed. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
问题
osv-scanner 在 main(commit
8519f57)上报出三条告警,全部落在同一个包brace-expansion@5.0.9:parseCommaParts无界递归 +push.apply大数组){a},b}重写循环)三条都是可用性问题,不涉及代码执行或数据泄露。
影响面:实际打不着
该包只经开发依赖进入本项目:
npm ls --omit=dev为空 —— 生产依赖树里没有它package.json的dependencies只有morphiconsfiles不含 lockfile所以安装本插件的用户拿不到这段代码。而触发这三个洞都需要把一个精心构造的恶意字符串当作 glob 模式喂给
expand();在 c8 里这个字符串来自项目自己的覆盖率配置,不是外部可控输入。结论:真实风险≈0,但三条告警会一直挂在 Security 页面。
改动
按仓库既有做法(
adm-zip就是走overrides钉版本的)加一条:5.0.12是三个洞修复版里最高的那个(分别修在 5.0.10 / 5.0.11 / 5.0.12),一版全清。minimatch声明的是^5.0.8,所以不需要动其它依赖。改动规模:
package.json+2/−1,package-lock.json+3/−3。验证
测试 1437 项:1436 通过 / 0 失败 / 1 跳过。
合并进 main 后,osv-scanner 会在 push 时重扫,这三条告警应自动转为 fixed。
Summary by CodeRabbit
brace-expansion固定为 5.0.12;adm-zip的版本设置保持不变。