Skip to content

fix(deps): clear the js-yaml advisory from the Electron chain (R-10) - #47

Merged
LMPrado-DZ23 merged 2 commits into
release/v3.8.55from
fix/electron-jsyaml-r10
Sep 19, 2026
Merged

LMPrado-DZ23 merged 2 commits into
release/v3.8.55from
fix/electron-jsyaml-r10

Conversation

@LMPrado-DZ23

Copy link
Copy Markdown
Owner

What

Clears R-10 — GHSA-2883-xcg3-v3hh (high, CVSS 7.5, CWE-400/CWE-407) — from the Electron app's production dependency tree.

It was the last high advisory in a shipped production tree, and the only record still carried as an accepted residual.

Dependency chain

omniroute-desktop (electron/)
└── electron-updater@6.8.9      [prod dependency, declares js-yaml ^4.1.0]
    └── js-yaml@4.3.1           <-- affected: >=4.0.0 <4.3.2

The dev-only electron-builder packages (app-builder-lib, builder-util, dmg-builder 26.15.3) dedupe onto the same hoisted copy, so a single bump cleared both trees.

Blast radius is the Electron shell's update-check chain only (electron/main.js loads electron-updater and calls autoUpdater.checkForUpdates(), which parses release-metadata YAML from the GitHub publish feed). Not in the container image, the npm package or the server runtime.

The fix

Lockfile-only:

npm update js-yaml --package-lock-only --ignore-scripts

js-yaml 4.3.1 → 4.3.2 (the v4-legacy dist-tag; first fixed version per the advisory).

  • electron/package.json is unchanged. The existing ^4.2.0 override already permitted 4.3.2, so no new overrides entry was needed.
  • node_modules was not touched — other worktrees share it.

Before / after

npm audit --omit=dev --package-lock-only:

Tree info low moderate high critical total
Electron production — before 0 0 0 1 0 1
Electron production — after 0 0 0 0 0 0
Root production — before 0 0 0 0 0 0
Root production — after 0 0 0 0 0 0

The Electron tree is also clean in the full run including dev deps (npm audit --package-lock-only): {"info":0,"low":0,"moderate":0,"high":0,"critical":0,"total":0}.

Root production was already at zero (PR #42's adm-zip fix) and is untouched here.

Nothing unrelated moved

 electron/package-lock.json | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

Three of those lines are js-yaml (version, resolved, integrity). The other two are npm synchronising the lockfile's own version field from a stale 3.8.51 to the 3.8.54 already declared in electron/package.json — a pre-existing drift, not a dependency change. No other package changed version.

Verification actually run

  • npm run check:lockfile — OK (no issues; workspace lock entries match their manifests)
  • npm --prefix electron audit --audit-level=critical — exit 0
  • npm --prefix electron audit --audit-level=high — exit 0 (the non-blocking high-severity warning audit:electron used to print is gone)
  • check-doc-links — PASS, 172 docs / 1044 internal links
  • check-fabricated-docs — PASS, no fabricated references
  • check-docs-frontmatter — OK, 132 docs
  • check-docs-sync — PASS
  • check-changelog-integrity — OK, no base bullets lost
  • markdownlint on both changed docs: same single pre-existing MD025 before and after — zero new issues

Stated plainly, not claimed

  • A full electron-builder packaging run was NOT executed. It needs a download of the Electron binaries and a signing environment this worktree does not have. What was checked: electron/package.json parses, its build block is unchanged by this commit, and the only file touched under electron/ is package-lock.json.
  • The audit:electron script was not run end to end on this machine — its (cmd || echo) POSIX shell form is rejected by cmd.exe before npm audit runs. That is a pre-existing Windows-only limitation of the script, unrelated to this change; the two commands behind it were run directly and both exit 0.

Docs

  • docs/security/VULNERABILITY_REGISTER.md — R-10 marked Fixed in the summary row, detail section and proposed-PR item; new "Electron re-measurement — 2026-09-19" section; the stale "1 high advisory … (R-10)" and "Electron app lockfile is unchanged" sentences corrected.
  • docs/EVOLUTION_STATUS.md — Phase 10 supply-chain table re-measured (Electron production high: 1 → 0), the "accepted as residual" paragraph rewritten, the Risks row marked Closed, and the known-limits bullet struck through.

R-10 is closed. No advisory is accepted as residual in either shipped production tree.

🤖 Generated with Claude Code

GHSA-2883-xcg3-v3hh (high, CVSS 7.5) reached the Electron app's production
tree through electron-updater 6.8.9 -> js-yaml 4.3.1, the update-check chain.
It was the last high advisory in a shipped production tree and the only record
still carried as an accepted residual.

Lockfile-only fix: `npm update js-yaml --package-lock-only --ignore-scripts`
moved js-yaml 4.3.1 -> 4.3.2, inside both electron-updater's declared ^4.1.0
and the existing ^4.2.0 override in electron/package.json. No package.json
change and no new override were needed. node_modules was not touched.

  electron prod  before: high 1, total 1  ->  after: 0 across every severity
  electron full  after:  0 across every severity (the dev-only
                 app-builder-lib / builder-util / dmg-builder copies dedupe
                 onto the same hoisted entry, so one bump cleared them too)
  root prod      0 before and after - untouched by this change

The lockfile diff is five lines: three for js-yaml (version, resolved,
integrity) and two where npm synchronised the lockfile's own version field
from a stale 3.8.51 to the 3.8.54 already declared in electron/package.json.
No other package changed version.

Docs updated to match: R-10 is marked fixed in the vulnerability register
(summary row, detail section, proposed-PR item) with a new Electron
re-measurement section, and EVOLUTION_STATUS's Phase 10 table, risks table
and known-limits list no longer describe it as an accepted residual.

Verified: check:lockfile OK; both commands behind audit:electron exit 0;
check-doc-links, check-fabricated-docs, check-docs-frontmatter,
check-docs-sync and check-changelog-integrity all pass. A full
electron-builder packaging run was not executed - it needs the Electron
binaries and a signing environment this worktree does not have; the
packaging config was verified to parse and to be unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e3329535-000b-4f01-b1b8-3895c8fbad1c


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Items 1 and 2 of that section are both applied now — adm-zip 0.6.1 in PR #42 and
js-yaml 4.3.2 in this one — so a heading reading "Proposed dependency PR (not
applied)" states the opposite of what the section records.

Renaming it moves the anchor, which is why it was left alone. But all three
references live inside this same file, so there was nothing external to break:
the heading and its three links are updated together.

  check-doc-links  exit 0  — 172 docs, 1044 internal links, none broken

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@LMPrado-DZ23
LMPrado-DZ23 merged commit f488c2d into release/v3.8.55 Sep 19, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants