fix(security): adm-zip >=0.6.0 + exact host matching in mitm DNS test (main) - #7733
Conversation
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
CI Coverage Report
Coverage artifact was not available for this run. |
|
|
Merging into main — same security fix as #7732 (adm-zip ^0.6.0 override + exact/suffix host matching in the mitm DNS test, CodeQL js/incomplete-url-substring-sanitization), targeting the default branch to clear the alert. The identical test+dep change was validated green in the release merge-train (#7732 @ 65768d6e9). The train's changelog-integrity red here is a base artifact — it compares against release/v3.8.49, which carries 294 unreleased bullets main legitimately does not yet have; not a defect of this PR. |



Same security fixes as #7732, targeted at
mainso the CodeQL alert clears on main's scanned ref too (per owner request to adjust on both the release branch and main).adm-zip (Dependabot #106, high, dev-scope)
Dev-only transitive (
promptfoo → onnxruntime-node). npmoverrides→adm-zip@^0.6.0; lock regenerated (found 0 vulnerabilities). Only used to extract its own trusted prebuilt binary, never untrusted ZIP input.CodeQL js/incomplete-url-substring-sanitization
tests/unit/mitm-dns-graceful-degrade-6127.test.tshost assertion switched from substring.includes()to exact matching (h === "custom.example.com"). Line-neutral; test green (4/4 on this branch's version of the file).CI note — changelog-integrity is a pre-existing base-red on main
check-changelog-integrity.mjshardcodesorigin/release/v3.8.49as its base and flags main'sCHANGELOG.mdas missing the 294 unreleased bullets. This reproduces identically on pristineorigin/main(verified) and is not introduced here — this PR does not touchCHANGELOG.md(only adds achangelog.d/fragment). It clears when the release syncs into main.Regression:
node --import tsx/esm --test tests/unit/mitm-dns-graceful-degrade-6127.test.ts→ 4/4 pass.