Skip to content

fix(security): adm-zip >=0.6.0 + exact host matching in mitm DNS test (main) - #7733

Merged
diegosouzapw merged 1 commit into
mainfrom
fix/sec-alerts-adm-zip-codeql-main
Jul 19, 2026
Merged

diegosouzapw merged 1 commit into
mainfrom
fix/sec-alerts-adm-zip-codeql-main

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Same security fixes as #7732, targeted at main so the CodeQL alert clears on main's scanned ref too (per owner request to adjust on both the release branch and main).

adm-zip (Dependabot #106, high, dev-scope)

Dev-only transitive (promptfoo → onnxruntime-node). npm overrides → adm-zip@^0.6.0; lock regenerated (found 0 vulnerabilities). Only used to extract its own trusted prebuilt binary, never untrusted ZIP input.

CodeQL js/incomplete-url-substring-sanitization

tests/unit/mitm-dns-graceful-degrade-6127.test.ts host assertion switched from substring .includes() to exact matching (h === "custom.example.com"). Line-neutral; test green (4/4 on this branch's version of the file).

CI note — changelog-integrity is a pre-existing base-red on main

check-changelog-integrity.mjs hardcodes origin/release/v3.8.49 as its base and flags main's CHANGELOG.md as missing the 294 unreleased bullets. This reproduces identically on pristine origin/main (verified) and is not introduced here — this PR does not touch CHANGELOG.md (only adds a changelog.d/ fragment). It clears when the release syncs into main.

Regression: node --import tsx/esm --test tests/unit/mitm-dns-graceful-degrade-6127.test.ts → 4/4 pass.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@github-actions

Copy link
Copy Markdown
Contributor

CI Coverage Report

  • Coverage job: success
  • PR test policy: success

Coverage artifact was not available for this run.

@sonarqubecloud

Copy link
Copy Markdown

@diegosouzapw

Copy link
Copy Markdown
Owner Author

Merging into main — same security fix as #7732 (adm-zip ^0.6.0 override + exact/suffix host matching in the mitm DNS test, CodeQL js/incomplete-url-substring-sanitization), targeting the default branch to clear the alert. The identical test+dep change was validated green in the release merge-train (#7732 @ 65768d6e9). The train's changelog-integrity red here is a base artifact — it compares against release/v3.8.49, which carries 294 unreleased bullets main legitimately does not yet have; not a defect of this PR.

@diegosouzapw
diegosouzapw merged commit 698b6eb into main Jul 19, 2026
6 checks passed
@diegosouzapw
diegosouzapw deleted the fix/sec-alerts-adm-zip-codeql-main branch July 19, 2026 21:01
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
KooshaPari pushed a commit to KooshaPari/OmniRoute that referenced this pull request Aug 11, 2026
KooshaPari added a commit to KooshaPari/OmniRoute that referenced this pull request Aug 11, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant