Skip to content

fix(deps): resolve all CVE advisories via bumps and overrides (TIM-399) - #232

Merged
timoa merged 1 commit into
mainfrom
fix/TIM-399-high-cve-bump
Oct 7, 2026
Merged

timoa merged 1 commit into
mainfrom
fix/TIM-399-high-cve-bump

Conversation

@timoa

@timoa timoa commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

Resolves all 28 CVE advisories reported in TIM-399 (10 high / 14 moderate / 4 low). Final state: 0 advisories on pnpm audit.

Changes

Direct bumps (package.json)

Package From To Why
@vscode/vsce 3.9.2 ^4.0.0 Major bump — refreshes publish-time chain (ajv/cheerio/minimatch/secretlint)
vitest ^4.1.8 ^4.1.11 Fixes @vitest/mocker path traversal (CVE-2026-84373)
@vitest/coverage-v8 ^4.1.8 ^4.1.11 Match vitest

pnpm.overrides for transitives with no upstream release yet

fast-uri               ^4.1.5     (5x CVEs in ajv chain — fix needs 4.1.3/4/5)
brace-expansion        ^5.0.12    (3x CVEs in minimatch chain)
source-map-js          ^1.2.2     (CVE-2026-93749 — tailwindcss chain)
@humanfs/node          ^0.16.8    (eslint chain — symlink copy)
js-yaml                ^5.4.1     (secretlint chain)
qs                     ^6.16.0    (vsce chain — array-limit bypass + isBuffer DoS)
postcss-selector-parser ^7.1.6     (css-loader chain)
serialize-javascript   ^7.0.5     (mocha chain — last 1 high + 1 moderate)
diff                   ^8.0.3     (mocha chain — last 1 low)

Verification

pnpm audit  →  0 critical, 0 high, 0 moderate, 0 low
pnpm run compile    →  clean
pnpm run lint       →  clean
pnpm run test       →  201 / 201 passed (15 files)
pnpm run webpack    →  compiled successfully

Risk notes

  • @vscode/vsce major bump only affects pnpm run package / pnpm run publish. Will be exercised in CI before merge.
  • serialize-javascript 6 → 7 and diff 7 → 8 are major overrides. Pnpm override forces it on mocha's transitive; risk = silent breakage in mocha's YAML/fixture serialization paths. test suite covers this — green.
  • pnpm.overrides is the documented mitigation when upstream chains can't bump. If a maintainer prefers, the overrides can be dropped once upstream releases land.

Refs TIM-399.

Summary by CodeRabbit

  • Chores
    • Updated development testing tool versions and constrained several transitive dependency versions.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3ea3997f-8fdd-495a-8f40-883b64f8041a
📥 Commits

Reviewing files that changed from the base of the PR and between c11bfad and 24b3f0a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json
 ____________________________________
< No tests? Bold. Approval? Also no. >
 ------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@timoa
timoa force-pushed the fix/TIM-399-high-cve-bump branch from b20643a to aa026a1 Compare October 7, 2026 04:46
- Bump @vscode/vsce 3.9.2 -> ^4.0.0 (publish-time chain)
- Bump vitest ^4.1.8 -> ^4.1.11 (@vitest/mocker path traversal)
- Bump @vitest/coverage-v8 ^4.1.8 -> ^4.1.11
- pnpm overrides force patched versions for transitives with no upstream release yet:
  fast-uri ^4.1.5, brace-expansion ^5.0.12, source-map-js ^1.2.2,
  @humanfs/node ^0.16.8, js-yaml ^5.4.1, qs ^6.16.0,
  postcss-selector-parser ^7.1.6, serialize-javascript ^7.0.5, diff ^8.0.3

pnpm audit: 28 -> 0 advisories (was 10 high / 14 moderate / 4 low).
Compile + 201 unit tests + lint + webpack all green.

Refs TIM-399
@timoa
timoa force-pushed the fix/TIM-399-high-cve-bump branch from aa026a1 to 24b3f0a Compare October 7, 2026 04:50
@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.13%. Comparing base (c11bfad) to head (24b3f0a).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #232   +/-   ##
=======================================
  Coverage   94.13%   94.13%           
=======================================
  Files          10       10           
  Lines         290      290           
  Branches      105      105           
=======================================
  Hits          273      273           
  Misses          1        1           
  Partials       16       16           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@timoa
timoa merged commit 49cd68e into main Oct 7, 2026
10 of 11 checks passed
@timoa
timoa deleted the fix/TIM-399-high-cve-bump branch October 7, 2026 04:55
timoa-bot Bot pushed a commit that referenced this pull request Oct 7, 2026
## [1.2.56](v1.2.55...v1.2.56) (2026-10-07)

### Bug Fixes

* **deps:** resolve high+moderate CVE advisories via bumps and overrides ([#232](#232)) ([49cd68e](49cd68e))
@timoa-bot

timoa-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.2.56 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

@timoa-bot timoa-bot Bot added the released label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants