Repository navigation
fix(deps): resolve brace-expansion DoS CVE (#907) - #915
LucasSantana-Dev wants to merge 2 commits into
Conversation
|
No reviewable files after applying ignore patterns. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR Code Suggestions ✨No code suggestions found for the PR. |
a117b61 to
21320fe
Compare
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
Resolves two moderate CVEs: - brace-expansion 5.0.2-5.0.5 → DoS (CVE-2024-45049 / GHSA-jxxr-4gwj-5jf2) - ws 8.0.0 - <8.20.1 → uninitialized memory disclosure (GHSA-58qx-3vcg-4xpx) Uses package.json `overrides` (existing pattern, brace-expansion was already at >=5.0.5; bumped to >=5.0.6; ws pinned at 8.20.1 to escape the vulnerable range). Regenerates lockfile from scratch to avoid `npm audit fix`'s optional-dep shuffling bug (npm/cli#4828) that broke @rolldown/binding-linux-x64-gnu resolution. npm audit: 0 vulnerabilities.
21320fe to
e351e5d
Compare
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe PR updates dependency override constraints in ChangesSecurity Dependency Overrides
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Suggested labels
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Parking — Lucky's
|
Lucky's `frontend` and `shared` workspaces pin `zod: ^4.4.3`, but the
backend code used Zod 3 API:
- validate.ts:4 used z.ZodTypeDef (removed in Zod 4)
- autoMessages.ts:9,37 used { required_error: '...' } (removed in 4)
The root lockfile happened to hoist Zod 3.25.76 (from `@infisical/sdk`'s
nested dep, hoisted by historical npm install ordering), masking the drift.
Any lockfile regen could flip the hoist and break the backend build —
which is what tripped PR #915 twice when trying to land the brace-expansion
CVE patch.
Changes:
validate.ts z.ZodType<T, z.ZodTypeDef, unknown> → z.ZodType<T, unknown>
(Zod 4 dropped the middle Def type parameter)
autoMessages { required_error: '...' } → { error: () => '...' } (x2)
backend pkg declare 'zod': '^4.4.3' as a direct dep, so npm resolves
backend's Zod to 4 (nested at packages/backend/node_modules/zod
if root continues to hoist a transitive Zod 3, leaving the
rest of the lockfile untouched)
Lockfile diff: 186 lines (zod entries + `requires` updates only). The
@rolldown/* native bindings, undici, vitest, jsdom et al stay exactly as
they were on the base — no transitive bumps, no cascade.
Verified:
✓ npm ci --legacy-peer-deps --ignore-scripts succeeds
✓ backend resolves zod 4.4.3 at packages/backend/node_modules/zod
✓ npm run build:shared
✓ npm run type:check --workspace=packages/backend
✓ npm test --workspace=packages/backend → 66 suites / 832 tests pass
Unblocks the CVE work in issue #907.
Decision record:
docs/decisions/2026-05-21-backend-zod-3-to-4-migration.md.



Summary
Resolves CVE-2024-45049 (GHSA-jxxr-4gwj-5jf2) in
brace-expansionand GHSA-58qx-3vcg-4xpx inws.Changes
Verification
npm auditconfirms zero moderate+ vulnerabilitiesnpm audit fixCloses #907
Summary by CodeRabbit