Skip to content

npm audit fix - #3399

Merged
david-crespo merged 3 commits into
mainfrom
npm-audit-fix
Oct 7, 2026
Merged

david-crespo merged 3 commits into
mainfrom
npm-audit-fix

Conversation

@david-crespo

Copy link
Copy Markdown
Collaborator

Required bumping oxfmt, so there's one formatting change.

🤖 why remaining braces vuln is not a practical problem

Yes, it's not important. The bug is a stack overflow when braces expands a deeply nested {a,{b,{c,...}}} pattern, and in our tree nothing that could be hostile ever reaches it.

braces only gets installed through patch-package, which runs on postinstall:

  • patch-package calls findWorkspaceRoot() (node_modules/patch-package/dist/detectPackageManager.js:54).
  • That function goes up the directory tree from the current directory, reading each package.json. If one has a workspaces field, it passes those globs to micromatch (node_modules/find-yarn-workspace-root/index.js:24-28). micromatch uses braces to expand them.

So the only input is the workspaces field in our own package.json files, and ours doesn't even have one. Anyone who could plant a malicious pattern there could already put arbitrary code in a postinstall script, so the bug gives them nothing new. Even then, the worst case is that npm install crashes. None of this goes into the browser bundle.

If you want the warning gone, you could add an overrides entry once braces publishes a patched version. Right now 3.0.3 is both the latest release and inside the vulnerable range. I'd ignore it until then.

@vercel

vercel Bot commented Oct 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
console Ready Ready Preview Oct 7, 2026 4:01pm UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 58e8848e Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant