Skip to content

fix(security): bump form-data/vite (2 HIGH) + env-harden workflow template-injection + allowlist guarded workflow_run - #3949

Merged
diegosouzapw merged 1 commit into
release/v3.8.26from
fix/security-findings-deps-workflows
Jun 16, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.26from
fix/security-findings-deps-workflows

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Passo B — corrige os findings de segurança reais que os scanners (agora funcionais, #3947) revelaram.

form-data + vite (2 HIGH de dependência → 0 HIGH)

Bumps patch limpos via overrides (ambos transitivos):

  • form-data 4.0.5→4.0.6 (via axios) — GHSA-hmw2-7cc7-3qxx.
  • vite 8.0.5→8.0.16 (via vitest/plugin-react/fumadocs) — GHSA-fx2h-pf6j-xcff + GHSA-v6wh-96g9-6wx3.
  • osv: 13→10 vulns, 0 HIGH · build:cli verde · test:vitest 187 testes 0-fail · check:deps/lockfile OK · churn do lock só no subtree vite/form-data.

template-injection (7 → 0) — env-harden

Movido cada ${{ ... }} do corpo do run: para env: (mitigação documentada do GitHub), referenciando "$VAR":

  • ci.yml i18n (matrix.lang→MATRIX_LANG); electron-release validate/build/release (github.event_name/inputs.version/needs.validate.outputs.version). Comportamento idêntico (valores regex-validados).

dangerous-trigger (1 → 0) — allowlist justificado

deploy-vps.yml workflow_run já guardado (conclusion=='success') + deploy via SSH (sem checkout de código não-confiável) → não-explorável. Allowlistado em .zizmor.yml (schema rules:) com justificativa + revisão no próximo release.

Baselines apertados (melhoria capturada)

vulnCount 13→10 · zizmorFindings 195→187 (direction down — futuras regressões pegas a partir do estado melhor).

Validação (auditada por mim)

osv 0 HIGH · zizmor 0 template-injection/0 dangerous-trigger · lockfile com 4.0.6/8.0.16 · build/vitest verdes · env-harden byte-equivalente.

Não gera versão.

…plate-injection + allowlist guarded workflow_run

Remediate the real findings the now-functional osv-scanner and zizmor gates
surfaced on release/v3.8.26.

Deps (osv-scanner, 2 HIGH -> 0):
- form-data 4.0.5 -> ^4.0.6 (GHSA-hmw2-7cc7-3qxx, transitive via axios)
- vite 8.0.5 -> ^8.0.16 (GHSA-fx2h-pf6j-xcff HIGH + GHSA-v6wh-96g9-6wx3
  MODERATE; dev-only via vitest/@vitejs/plugin-react/fumadocs-mdx)
Applied via package.json overrides of existing deps (no new allowlist entry
needed). vulnCount 13 -> 10; build:cli + vitest MCP suite (16 files/187 tests)
green post-bump.

Workflows (zizmor, 195 -> 187):
- env-harden 7 template-injection findings by moving each ${{ ... }} into env:
  and referencing "$VAR" in the script (GitHub-documented mitigation):
  ci.yml i18n; electron-release.yml validate/build/release steps.
- allowlist 1 dangerous-triggers FP: deploy-vps.yml on:workflow_run is guarded
  on conclusion=='success' and deploys via SSH without checking out untrusted
  code. Added .zizmor.yml rules.dangerous-triggers.ignore with justification.

Tighten baselines to the improved state (direction: down): vulnCount 13 -> 10,
zizmorFindings 195 -> 187. secretFindings (3) and bundleSize (5601) unchanged.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@diegosouzapw
diegosouzapw merged commit bc32c67 into release/v3.8.26 Jun 16, 2026
2 checks passed
@diegosouzapw diegosouzapw mentioned this pull request Jun 16, 2026
diegosouzapw added a commit that referenced this pull request Jun 16, 2026
OmniRoute v3.8.26 — see CHANGELOG.md [3.8.26] for the full notes.

Highlights: Vertex AI media generation (#3929), GLM-5.2 effort-tier routing (#3885),
sticky round-robin combos (#3846), OpenRouter connection presets (#3878), compression
prompt-cache fix (#3936/#3890), and a security pass (form-data/vite + workflow hardening, #3949).

Co-authored-by: artickc <artickc@users.noreply.github.com>
Co-authored-by: rdself <rdself@users.noreply.github.com>
Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>
Co-authored-by: Jack Smith <16862258+YunyunZhai@users.noreply.github.com>
Co-authored-by: dhaern <dhaern@users.noreply.github.com>
Co-authored-by: adivekar-utexas <adivekar-utexas@users.noreply.github.com>
Co-authored-by: megamen32 <megamen32@users.noreply.github.com>
Co-authored-by: zhiru <zhiru@users.noreply.github.com>
Co-authored-by: insoln <insoln@users.noreply.github.com>
Co-authored-by: diego-anselmo <diego-anselmo@users.noreply.github.com>
diegosouzapw added a commit that referenced this pull request Jun 16, 2026
…drift) (#3962)

The main quality-gate failed on the forward-merge release->main (run 27593205254):
eslintWarnings 3769 > baseline 3760. Measured now on origin/release/v3.8.26
(273ecf7, all cycle merges) via quality:collect = 3769 — identical to CI. The
later gate PRs (#3947/#3949/#3951/#3956/#3961) did not change the count
(scripts/check/*.mjs are eslint-ignored; the new test files added no any/warnings).
The +9 is pre-existing release-wide drift from v3.8.26 feature/other-session merges,
not a product regression. Conscious re-baseline to the real measured value; tighten
via --require-tighten at cycle-end (consistent with prior _eslint_rebaseline notes).

Validated: ratchet passes with the real CI metrics (24 metrics OK, exit 0).
@diegosouzapw
diegosouzapw deleted the fix/security-findings-deps-workflows branch June 17, 2026 00:54
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
OmniRoute v3.8.26 — see CHANGELOG.md [3.8.26] for the full notes.

Highlights: Vertex AI media generation (diegosouzapw#3929), GLM-5.2 effort-tier routing (diegosouzapw#3885),
sticky round-robin combos (diegosouzapw#3846), OpenRouter connection presets (diegosouzapw#3878), compression
prompt-cache fix (diegosouzapw#3936/diegosouzapw#3890), and a security pass (form-data/vite + workflow hardening, diegosouzapw#3949).

Co-authored-by: artickc <artickc@users.noreply.github.com>
Co-authored-by: rdself <rdself@users.noreply.github.com>
Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>
Co-authored-by: Jack Smith <16862258+YunyunZhai@users.noreply.github.com>
Co-authored-by: dhaern <dhaern@users.noreply.github.com>
Co-authored-by: adivekar-utexas <adivekar-utexas@users.noreply.github.com>
Co-authored-by: megamen32 <megamen32@users.noreply.github.com>
Co-authored-by: zhiru <zhiru@users.noreply.github.com>
Co-authored-by: insoln <insoln@users.noreply.github.com>
Co-authored-by: diego-anselmo <diego-anselmo@users.noreply.github.com>
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
OmniRoute v3.8.26 — see CHANGELOG.md [3.8.26] for the full notes.

Highlights: Vertex AI media generation (diegosouzapw#3929), GLM-5.2 effort-tier routing (diegosouzapw#3885),
sticky round-robin combos (diegosouzapw#3846), OpenRouter connection presets (diegosouzapw#3878), compression
prompt-cache fix (diegosouzapw#3936/diegosouzapw#3890), and a security pass (form-data/vite + workflow hardening, diegosouzapw#3949).

Co-authored-by: artickc <artickc@users.noreply.github.com>
Co-authored-by: rdself <rdself@users.noreply.github.com>
Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>
Co-authored-by: Jack Smith <16862258+YunyunZhai@users.noreply.github.com>
Co-authored-by: dhaern <dhaern@users.noreply.github.com>
Co-authored-by: adivekar-utexas <adivekar-utexas@users.noreply.github.com>
Co-authored-by: megamen32 <megamen32@users.noreply.github.com>
Co-authored-by: zhiru <zhiru@users.noreply.github.com>
Co-authored-by: insoln <insoln@users.noreply.github.com>
Co-authored-by: diego-anselmo <diego-anselmo@users.noreply.github.com>
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…plate-injection + allowlist guarded workflow_run (diegosouzapw#3949)

Remediate the real findings the now-functional osv-scanner and zizmor gates
surfaced on release/v3.8.26.

Deps (osv-scanner, 2 HIGH -> 0):
- form-data 4.0.5 -> ^4.0.6 (GHSA-hmw2-7cc7-3qxx, transitive via axios)
- vite 8.0.5 -> ^8.0.16 (GHSA-fx2h-pf6j-xcff HIGH + GHSA-v6wh-96g9-6wx3
  MODERATE; dev-only via vitest/@vitejs/plugin-react/fumadocs-mdx)
Applied via package.json overrides of existing deps (no new allowlist entry
needed). vulnCount 13 -> 10; build:cli + vitest MCP suite (16 files/187 tests)
green post-bump.

Workflows (zizmor, 195 -> 187):
- env-harden 7 template-injection findings by moving each ${{ ... }} into env:
  and referencing "$VAR" in the script (GitHub-documented mitigation):
  ci.yml i18n; electron-release.yml validate/build/release steps.
- allowlist 1 dangerous-triggers FP: deploy-vps.yml on:workflow_run is guarded
  on conclusion=='success' and deploys via SSH without checking out untrusted
  code. Added .zizmor.yml rules.dangerous-triggers.ignore with justification.

Tighten baselines to the improved state (direction: down): vulnCount 13 -> 10,
zizmorFindings 195 -> 187. secretFindings (3) and bundleSize (5601) unchanged.
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…drift) (diegosouzapw#3962)

The main quality-gate failed on the forward-merge release->main (run 27593205254):
eslintWarnings 3769 > baseline 3760. Measured now on origin/release/v3.8.26
(19b37e6, all cycle merges) via quality:collect = 3769 — identical to CI. The
later gate PRs (diegosouzapw#3947/diegosouzapw#3949/diegosouzapw#3951/diegosouzapw#3956/diegosouzapw#3961) did not change the count
(scripts/check/*.mjs are eslint-ignored; the new test files added no any/warnings).
The +9 is pre-existing release-wide drift from v3.8.26 feature/other-session merges,
not a product regression. Conscious re-baseline to the real measured value; tighten
via --require-tighten at cycle-end (consistent with prior _eslint_rebaseline notes).

Validated: ratchet passes with the real CI metrics (24 metrics OK, exit 0).
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
OmniRoute v3.8.26 — see CHANGELOG.md [3.8.26] for the full notes.

Highlights: Vertex AI media generation (diegosouzapw#3929), GLM-5.2 effort-tier routing (diegosouzapw#3885),
sticky round-robin combos (diegosouzapw#3846), OpenRouter connection presets (diegosouzapw#3878), compression
prompt-cache fix (diegosouzapw#3936/diegosouzapw#3890), and a security pass (form-data/vite + workflow hardening, diegosouzapw#3949).

Co-authored-by: artickc <artickc@users.noreply.github.com>
Co-authored-by: rdself <rdself@users.noreply.github.com>
Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>
Co-authored-by: Jack Smith <16862258+YunyunZhai@users.noreply.github.com>
Co-authored-by: dhaern <dhaern@users.noreply.github.com>
Co-authored-by: adivekar-utexas <adivekar-utexas@users.noreply.github.com>
Co-authored-by: megamen32 <megamen32@users.noreply.github.com>
Co-authored-by: zhiru <zhiru@users.noreply.github.com>
Co-authored-by: insoln <insoln@users.noreply.github.com>
Co-authored-by: diego-anselmo <diego-anselmo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant