Skip to content

BAD CODE: 26 open Dependabot alerts on main, including a critical in node-tar #39

Description

@flyingrobots

Observation

gh api repos/flyingrobots/think/dependabot/alerts reports 26 open alerts on the default branch:

Severity Count
critical 1
high 9
medium 16

Affected packages: fast-uri, hono, ip-address, tar, undici.

The critical and highs:

critical  tar          node-tar: Decompression/parse DoS via unlimited input
high      tar          node-tar: Negative tar entry size causes infinite loop in archive replace
high      fast-uri     host confusion via backslash authority introducer
high      fast-uri     host confusion via failed IDN canonicalization
high      fast-uri     host confusion via literal backslash authority delimiter
high      ip-address   Address4 decodes leading-zero octets as decimal while resolvers decode as octal (SSRF / trust-boundary bypass)

npm audit additionally reports a fixable advisory against @modelcontextprotocol/sdk, which is a direct dependency rather than transitive.

Why this matters here specifically

node-tar is not incidental to this repository. The git-cas fixture path extracts archives with tar — test/acceptance/repair-v17-mind.test.js and test/acceptance/readme-smoke-mind-fixture.test.js both restore a tarball and unpack it, and scripts/build-smoke-mind-fixture.mjs produces them. A decompression DoS in the library used to unpack fixture archives is squarely on a path this project exercises in CI.

ip-address SSRF-class bypasses matter because Think performs upstream reachability checks and pushes to a configured remote URL.

Every alert reports a fix as available, so this is upgrade work, not mitigation work.

Why it went unnoticed

Nothing in the repository surfaces this. Pushes print a Dependabot banner to stderr, which is easy to scroll past, and npm run lint and npm test are both silent about advisories. docs/method/backlog/bad-code/CORE_audit-no-dependency-freshness-cadence.md already records the absence of a freshness cadence; this issue is the concrete evidence of what that gap costs.

Suggested direction

  • Resolve the critical and high alerts first; all have fixes published.
  • Decide whether npm audit belongs in CI as a gate or a report. Given the repo's existing preference for ratchets over prose, an advisory-count ratchet would fit the established pattern and would not block on newly-disclosed advisories the way a hard gate does.
  • Reconcile with BAD CODE: exact-pinned @git-stunts dependencies stop upstream fixes reaching Think #37: raising these versions interacts with the exact pins on @git-stunts/*, and with the pending plumbing/git-warp propagation.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions