Skip to content

Take fast-uri and js-yaml security patches (lockfile only) - #186

Merged
bazauto merged 1 commit into
mainfrom
deps/fast-uri-js-yaml-advisories
Sep 9, 2026
Merged

bazauto merged 1 commit into
mainfrom
deps/fast-uri-js-yaml-advisories

Conversation

@bazauto

@bazauto bazauto commented Sep 9, 2026

Copy link
Copy Markdown
Owner

Dependabot had eight open alerts, all high, and all of them the same package: fast-uri,
caught on two version lines at once. Four advisories against the 3.x line installed here and
four against a 4.x copy deeper in the tree — SSRF via malformed IPv6 normalization and via
repeated hostname percent-decoding, and host confusion via percent-encoded scheme
normalization and skipped IDN canonicalization.

Both lines are transitive under Fastify: @fastify/ajv-compiler → ajv → fast-uri for the
3.x copy, fast-json-stringify → fast-uri for the 4.x one. Nothing in this stack parses an
attacker-supplied URI — fast-uri is there to resolve JSON Schema $refs at route-compile
time, against schemas we wrote — so the exposure argument is weak in both directions. It did
not have to be settled: the fix is a patch bump on each line, which is cheaper than reasoning
about reachability.

Plain npm audit fix did the whole thing. package-lock.json is the only file that moves:

  • fast-uri 3.1.5 → 3.1.7 (advisories fixed in 3.1.6)
  • fast-uri 4.1.2 → 4.1.4 (fixed in 4.1.3)
  • js-yaml 4.3.1 → 4.3.2

The js-yaml bump came along in the same run. It is a high that npm audit reports and
Dependabot had not raised, and it is dev-only — eslint → @eslint/eslintrc.

No package.json changed, no direct dependency changed, and npm audit fix --force was not
involved. npm audit now reports zero high-severity advisories.

What is deliberately not fixed

Seven moderate advisories remain, and both chains behind them need a breaking change:

  • drizzle-kit@0.18.1 — the existing banned case, four advisories on one unreachable
    @esbuild-kit → esbuild@0.18.20 chain. Still a major downgrade of the tool that
    generates migrations against the live database.
  • vitest@5 — new since the ban was written. GHSA-82fw-gwwq-j7x9, a path traversal in
    @vitest/mocker, with no fix on the 3.x line both workspaces declare. Reachable only
    against a running Vitest server on a developer's machine. A major-version migration of the
    suite that guards a control system is worth doing on its own branch, deliberately, and not
    as a side effect of an audit.

Docs

docs/current-state.md §Repo notes said the only remaining --force suggestion was the
drizzle-kit downgrade, and that "the four residual moderate advisories" were one chain. Both
halves are now false — there are two chains and seven advisories. That section is rewritten to
cover both, with the reachability argument for each, and the CLAUDE.md rule it backs is
updated to match.

Verification

Run on this branch, from the repo root:

npm test    → backend  84 files, 1500 tests passed
              frontend 27 files,  332 tests passed
              exit 0
npm run lint                                 → exit 0
npm run build --workspace=packages/backend   → exit 0
npm run build --workspace=packages/frontend  → exit 0 (dist 298.95 kB, gzip 89.66 kB)
npm audit   → 7 moderate, 0 high

Both workspace builds were run because there is no root build script and CI is not the only
thing that has to survive this — the bench box builds on the box at deploy time.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV

@bazauto
bazauto enabled auto-merge (squash) September 9, 2026 17:30
@bazauto
bazauto force-pushed the deps/fast-uri-js-yaml-advisories branch from ce7289c to 39ecab6 Compare September 9, 2026 17:53
Closes all eight open high-severity Dependabot alerts. Every one was
fast-uri, on two version lines at once: 3.1.5 -> 3.1.7 and 4.1.2 ->
4.1.4, both transitive under Fastify (@fastify/ajv-compiler -> ajv, and
fast-json-stringify). The same plain `npm audit fix` took js-yaml 4.3.1
-> 4.3.2, a high that npm audit reports and Dependabot had not raised,
dev-only under eslint -> @eslint/eslintrc.

package-lock.json is the only file that moves. No package.json changed,
no direct dependency changed, and no --force was involved.

Docs: the Repo notes section in docs/current-state.md said the only
remaining --force suggestion was the drizzle-kit downgrade and that four
residual moderate advisories were one chain. There are now two chains and
seven advisories -- vitest@5 has joined it -- so both that section and the
CLAUDE.md rule it backs are rewritten to match.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV
@bazauto
bazauto merged commit bafabca into main Sep 9, 2026
1 check passed
@bazauto
bazauto deleted the deps/fast-uri-js-yaml-advisories branch September 9, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant