Repository navigation
npm audit fix - #3399
Merged
Merged
npm audit fix#3399
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
david-crespo
enabled auto-merge (squash)
October 7, 2026 16:02
david-crespo
added a commit
to oxidecomputer/omicron
that referenced
this pull request
Oct 9, 2026
oxidecomputer/console@14ec752...00cc6bf * [00cc6bf6](oxidecomputer/console@00cc6bf6) oxidecomputer/console#3312 * [d9229150](oxidecomputer/console@d9229150) oxidecomputer/console#3399 * [cc346756](oxidecomputer/console@cc346756) oxidecomputer/console#3398 * [d7258e7c](oxidecomputer/console@d7258e7c) oxidecomputer/console#3397 * [d0c0cc4d](oxidecomputer/console@d0c0cc4d) oxidecomputer/console#3395 * [4f1ba374](oxidecomputer/console@4f1ba374) oxidecomputer/console#3394
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Required bumping oxfmt, so there's one formatting change.
🤖 why remaining
bracesvuln is not a practical problemYes, it's not important. The bug is a stack overflow when braces expands a deeply nested
{a,{b,{c,...}}}pattern, and in our tree nothing that could be hostile ever reaches it.braces only gets installed through patch-package, which runs on
postinstall:findWorkspaceRoot()(node_modules/patch-package/dist/detectPackageManager.js:54).package.json. If one has aworkspacesfield, it passes those globs to micromatch (node_modules/find-yarn-workspace-root/index.js:24-28). micromatch uses braces to expand them.So the only input is the
workspacesfield in our ownpackage.jsonfiles, and ours doesn't even have one. Anyone who could plant a malicious pattern there could already put arbitrary code in apostinstallscript, so the bug gives them nothing new. Even then, the worst case is thatnpm installcrashes. None of this goes into the browser bundle.If you want the warning gone, you could add an
overridesentry once braces publishes a patched version. Right now 3.0.3 is both the latest release and inside the vulnerable range. I'd ignore it until then.