Skip to content

fix(deps): brace-expansion 钉到 5.0.12(CVE-2026-102276/102277/102278) - #345

Merged
modusensus merged 2 commits into
mainfrom
fix/osv-brace-expansion
Sep 30, 2026
Merged

modusensus merged 2 commits into
mainfrom
fix/osv-brace-expansion

Conversation

@modusensus

@modusensus modusensus commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

问题

osv-scanner 在 main(commit 8519f57)上报出三条告警,全部落在同一个包 brace-expansion@5.0.9:

# 严重度 CVE 类型
7 high CVE-2026-102276 栈耗尽 DoS(parseCommaParts 无界递归 + push.apply 大数组)
8 medium CVE-2026-102277 二次时间 CPU DoS({a},b} 重写循环)
9 high CVE-2026-102278 栈耗尽 DoS(嵌套花括号递归)

三条都是可用性问题,不涉及代码执行或数据泄露。

影响面:实际打不着

该包只经开发依赖进入本项目:

c8@12(覆盖率工具,devDependency)
└─ test-exclude@8.0.0
   └─ minimatch@10.2.6
      └─ brace-expansion@5.0.9
  • npm ls --omit=dev 为空 —— 生产依赖树里没有它
  • package.json 的 dependencies 只有 morphicons
  • 发布产物的 files 不含 lockfile

所以安装本插件的用户拿不到这段代码。而触发这三个洞都需要把一个精心构造的恶意字符串当作 glob 模式喂给 expand();在 c8 里这个字符串来自项目自己的覆盖率配置,不是外部可控输入。

结论:真实风险≈0,但三条告警会一直挂在 Security 页面。

改动

按仓库既有做法(adm-zip 就是走 overrides 钉版本的)加一条:

"overrides": {
  "adm-zip": "0.6.1",
  "brace-expansion": "5.0.12"
}

5.0.12 是三个洞修复版里最高的那个(分别修在 5.0.10 / 5.0.11 / 5.0.12),一版全清。minimatch 声明的是 ^5.0.8,所以不需要动其它依赖。

改动规模:package.json +2/−1,package-lock.json +3/−3。

验证

$ npm ls brace-expansion --all
`-- c8@12.0.0
  `-- test-exclude@8.0.0
    `-- minimatch@10.2.6
      `-- brace-expansion@5.0.12 overridden

测试 1437 项:1436 通过 / 0 失败 / 1 跳过。

合并进 main 后,osv-scanner 会在 push 时重扫,这三条告警应自动转为 fixed。


与宿主导主版本适配(#344)是两个独立改动,故分开提。

Summary by CodeRabbit

  • 维护
    • 将 brace-expansion 固定为 5.0.12;adm-zip 的版本设置保持不变。

osv-scanner 在 main(8519f57)上报出三条告警,全部落在 brace-expansion@5.0.9:
两个栈耗尽型 DoS(102276 的 parseCommaParts 无界递归与 push.apply 大数组、
102278 的嵌套花括号递归)与一个二次时间 CPU DoS(102277 的 {a},b} 重写循环)。
三条都只影响可用性,不涉及代码执行或数据泄露。

该包只经开发依赖进入:c8(覆盖率)→ test-exclude → minimatch →
brace-expansion。npm ls --omit=dev 为空,package.json 的 dependencies 只有
morphicons,发布产物的 files 也不含 lockfile——安装本插件的用户拿不到这段
代码。且触发这三个洞都需要把精心构造的字符串当 glob 模式喂给 expand(),在
c8 里这个输入来自项目自己的覆盖率配置,外部不可控。故真实风险≈0,但告警会
一直挂在 Security 页面。

按仓库既有做法(adm-zip 同样走 overrides 钉版本)加一条 overrides 到 5.0.12:
三个洞分别修在 5.0.10 / 5.0.11 / 5.0.12,5.0.12 一版全清;minimatch 声明的
是 ^5.0.8,其余依赖无需改动。改动只有 package.json 与 package-lock.json。

测试 1437 项:1436 通过 / 0 失败 / 1 跳过。
Copilot AI lite review requested due to automatic review settings September 30, 2026 11:10

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: slow-stack/mneme/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 8218a724-7306-44cb-846c-dc85a1238258

📥 Commits

Reviewing files that changed from the base of the PR and between 9968bd0 and 9e1042f.

⛔ Files ignored due to path filters (1)
  • dsh-mneme/package-lock.json is excluded by !**/package-lock.json, !**/package-lock.json
📒 Files selected for processing (1)
  • dsh-mneme/package.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

dsh-mneme 的依赖覆盖配置新增 brace-expansion,版本固定为 5.0.12。原有 adm-zip 覆盖保持不变。

Changes

依赖版本覆盖

Layer / File(s) Summary
新增 brace-expansion 覆盖
dsh-mneme/package.json
overrides 将 brace-expansion 固定为 5.0.12。原有 adm-zip 覆盖未变。

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: anans-ivresse

Merge Risk: ⚪ Minimal · up to 9e104

The dependency pin addresses the reported vulnerabilities without an evident resolution or runtime compatibility mismatch. No material merge risk remains; installation and runtime execution were not independently performed.

Architecture Summary

Architecture risk: 🔵 Low · up to 9e104

The change affects 1 system.

Changed systems: dsh-mneme

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — dsh-mneme (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in dsh-mneme/package.json: overrides 新增 brace-expansion 版本 5.0.12;原有 adm-zip 覆盖未变。
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 标题准确概括了主要变更:将 brace-expansion 固定到 5.0.12,并明确说明了对应的 CVE。标题简洁、具体,与变更内容一致。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Copilot AI lite review requested due to automatic review settings September 30, 2026 12:21

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@modusensus
modusensus merged commit 4c05a52 into main Sep 30, 2026
9 checks passed
@modusensus
modusensus deleted the fix/osv-brace-expansion branch September 30, 2026 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants