Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions SECURITY-OVERRIDES.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,13 @@ This file documents the provenance and exit condition for each override. **When

## Entries

### `basic-ftp: ^5.3.1`
### `basic-ftp: ^6.2.1`

- **Class**: runtime
- **Path**: `proxy-agent → pac-proxy-agent → get-uri → basic-ftp`
- **CVEs cleared**: GHSA-5rq4-664w-9x2c, GHSA-6v7q-wjvx-w8wg, GHSA-rp42-5vxx-qpwr, GHSA-rpmf-866q-6p89
- **Exit**: `get-uri` bumps its `basic-ftp` dep range to include `^5.3.1`.
- **CVEs cleared**: GHSA-5rq4-664w-9x2c, GHSA-6v7q-wjvx-w8wg, GHSA-rp42-5vxx-qpwr, GHSA-rpmf-866q-6p89, GHSA-c475-qrg2-pj4r
- **Why an override is needed**: `get-uri` (through 8.0.1) caps `basic-ftp` at `^5.3.1`, below the 6.2.1 fix. The `Client` API get-uri uses is unchanged in 6.x; the 6.0 major only defaults `allowSeparateTransferHost` to `false`, so a PASV reply naming a different host is rejected.
- **Exit**: `get-uri` widens its `basic-ftp` range to include `^6.2.1`.

### `@75lb/deep-merge: ^1.1.2`

Expand Down
9 changes: 7 additions & 2 deletions osv-scanner.toml
Original file line number Diff line number Diff line change
Expand Up @@ -16,17 +16,22 @@
#
# CONVENTION: use suppressions sparingly, only with a strong reason
# (unreachable code path + no fix available, or dev-only + not shipped).
# EVERY [[IgnoredVulns]] entry MUST set `ignoreUntil = "YYYY-MM-DD"`
# EVERY [[IgnoredVulns]] entry MUST set `ignoreUntil = YYYY-MM-DD`
# (~6 months out). OSV-Scanner v2.3.8 honors it natively; when it lapses
# the finding re-surfaces, forcing a re-review instead of a permanent
# silent ignore.
#
# Example:
# [[IgnoredVulns]]
# id = "GHSA-xxxx-xxxx-xxxx"
# ignoreUntil = "2026-01-15"
# ignoreUntil = 2026-01-15 # bare TOML date; a quoted string fails to parse
# reason = "dev-only (eslint toolchain); not reachable from shipped dist/."
#
# This file starts empty -- populate iteratively as the first scan run
# surfaces real false positives or dev-only findings worth excluding.
# Do not pre-populate with speculative suppressions.

[[IgnoredVulns]]
id = "GHSA-vfj7-8cjw-p6xm"
ignoreUntil = 2027-04-05
reason = "braces: no fixed release (3.0.3 is latest). Dev-only (mocha -> chokidar, globby -> fast-glob -> micromatch); not in shipped dist/."
50 changes: 25 additions & 25 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,7 @@
"@databricks/databricks-sql-kernel-win32-arm64-msvc": "1.1.0"
},
"overrides": {
"basic-ftp": "^5.3.1",
"basic-ftp": "^6.2.1",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Low — This override forces basic-ftp across a major version boundary (5.x → 6.x), past get-uri's declared ^5.3.1 cap. As the SECURITY-OVERRIDES.md note acknowledges, 6.0 changes the default of allowSeparateTransferHost to false, so FTP data connections where the PASV/EPSV reply names a different host than the control connection are now rejected. For this connector that path is only reachable via an ftp:// proxy URI through proxy-agent, so the blast radius is small and the change is intentional — flagging only so the behavioral shift is visible to reviewers/consumers who may rely on FTP-proxy transfers. No change requested.

"@75lb/deep-merge": "^1.1.2",
"ws": "^8.18.0",
"ip-address": "^10.1.1",
Expand Down
Loading