fix(security): patch transitive deepmerge-ts stack exhaustion - #525
fix(security): patch transitive deepmerge-ts stack exhaustion#525seonghobae wants to merge 21 commits into
Conversation
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…, and Dependencies
|
Fresh fleet dependency handoff from writer-free rollup PR #602: exact Owner-path acceptance: compare advisory fixed ranges and upstream compatibility; if |
Understood. The extraneous |
Current exact authority — 2026-09-08
developmental@2fa92012bcf80acc1f921a4bafea76b3b1424b46534280c1e59ec43378e1a9801bc16dc81d93d39fThe older
2131c17a...four-file description below is predecessor evidence only. It is not current authority. Ordinary descendants preserved additional valid deltas, so this PR must not be merged or narrowed by destructive history rewriting.Current dependency result
The exact lockfile resolves:
deepmerge-ts@8.0.0instead of vulnerable7.1.5;browserslist@4.28.7instead of vulnerable4.28.2;Exact-head CI
33998319198, Security Scan33998319155, OSV-Scanner33998319186, Dependency Review33998319176, and SAST33998319229are terminal success. CodeQL PR33998319180remains terminal failure in the central dispatch/verdict path and is not counted as passing.Preservation and separation boundary
The current comparison contains these nine paths:
.github/workflows/ci.yml.github/workflows/dependency-review.yml.github/workflows/osvscanner.yml.jules/sentinel.mdpackage.jsonpackages/web/src/app/api/orgs/[orgSlug]/dashboard/sessions/route.tspackages/web/src/lib/server/csv-export.test.tspackages/web/src/lib/server/csv-export.tspnpm-lock.yamlThis is no longer a bounded dependency-only tree: it also carries CSV behavior and repository-workflow changes. Keep Draft. Before promotion, non-force restack/separation must preserve every valid delta in a verified successor/owner path, retain both dependency fixes without suppression, and obtain exact-current-head central CodeQL plus qualifying independent review. Do not reset, force-push, delete mixed valid work, or transfer predecessor results.
Predecessor record (superseded as current authority)
Security outcome
This lane owns only the shared dependency remediation for
deepmerge-ts. Protecteddevelopmentalresolves Prisma's configuration chain to vulnerabledeepmerge-ts@7.1.5; the product delta pins8.0.0through the root pnpm override and records the compatibility/rollback evidence. Session-CSV formula-injection code and repository workflow policy are separate owner concerns and are not part of the effective PR delta.Current exact authority — 2026-09-06
developmental@2fa92012bcf80acc1f921a4bafea76b3b1424b462131c17a97c033253bc118e4cce79e0ee393f1082fa92012bcf80acc1f921a4bafea76b3b1424b46Intervening-delta repair
The previously adjudicated dependency tree was recorded at
6362bfeb8983a4bf98cb2ea205cba4ee2444d92dwith tree557d92d21218bc2028832aa7d403d0bb63098992. Three later normal commits advanced the branch to846c765237429836ac0b8abc6bc67a7b05b2321cand mixed in unrelated session-CSV source/tests plus local workflow edits while simultaneously deleting this lane's doctoring document and CHANGELOG evidence.The fleet did not force-push, reset, or destructively rebase that history. Commit
ddc275b1e21fb4ccfda0d96d9aa0d7b9588cba43is a normal child of846c7652...that adopts the already-adjudicated dependency tree exactly, so the intervening history remains in ancestry without remaining in the product tree. Commit2131c17a...then restores.jules/sentinel.mdbyte-for-byte to the protected-base blob, keeping this local remediation out of repository-wide generated doctrine.Fresh protected-base comparison now contains exactly four files:
package.json: rootpnpm.overrides.deepmerge-ts = "8.0.0";pnpm-lock.yaml: transitive resolution update;docs/doctoring/deepmerge-ts-cve-2026-40345.md: vulnerability, compatibility, rollback, removal condition, and traceability;CHANGELOG.md: Unreleased security entry.No
.github/workflows/*, CSV route/source/test, or.jules/sentinel.mdfile remains in the effective delta.Vulnerability and compatibility boundary
The reviewed advisory
GHSA-ggr8-5vv4-36mx/CVE-2026-40345identifies stack exhaustion when vulnerable DeepmergeTS releases merge crafted recursive object graphs;8.0.0is the remediation target recorded by this lane. Because this is a transitive major-version override under Prisma's configuration chain, scanner success alone is insufficient.Promotion requires one unchanged exact head to prove frozen install, Prisma generation/configuration, migrations, build, typecheck/lint, application tests, and security/audit behavior. If 8.x compatibility fails, do not revert to vulnerable 7.1.5 and do not suppress the advisory; select an upstream Prisma path that naturally resolves to a patched DeepmergeTS release. Remove the override only when the protected dependency chain itself resolves a patched version and fresh install/security evidence proves the override redundant.
Primary traceability:
GHSA-ggr8-5vv4-36mx/CVE-2026-40345.Bump deepmerge-ts to >= 8.0.0 in @prisma/config (CVE-2026-40345).Current exact-head gates
Fresh runs materialized for
2131c17a...:33986616261— queued33986616232— pending33986616276— queued33986616224— queuedHistorical GREEN from predecessor generations is not transferred. A qualifying current independent non-author approval and zero valid unresolved findings are also required before Ready/merge promotion.
No self-approval, force update, destructive rebase, source-neutral retrigger, scanner suppression, admin bypass, workflow-policy side quest, or gate weakening.