Skip to content

fix(deps): drop braces from the dependency tree - #41

Merged
frantuma merged 1 commit into
mainfrom
fix/remove-braces-from-dependency-tree
Oct 6, 2026
Merged

frantuma merged 1 commit into
mainfrom
fix/remove-braces-from-dependency-tree

Conversation

@frantuma

@frantuma frantuma commented Oct 6, 2026

Copy link
Copy Markdown
Member

Change

dependency-audit fails on main (run 37305388361) even though the same commit passed in #40. A new advisory reached the audit feed between the two runs: GHSA-vfj7-8cjw-p6xm (CVE-2026-93687, high), a stack-exhaustion denial of service in braces. It affects every release up to 3.0.3, the latest, and has no patched version. The only way to resolve it is to remove the packages that pull braces in.

There are two such paths, both development tooling; braces is not in any shipped bundle. The first is @babel/cli → chokidar@3 → braces. No script invokes @babel/cli, because the build uses babel-loader with @babel/core and babel.config.cjs, so this PR removes it. The second is @vscode/vsce@3 → secretlint → globby → fast-glob → micromatch → braces. @vscode/vsce 4.0.0 replaces the secretlint CLI and glob with @secretlint/core and tinyglobby, so this PR moves to it. That removes 160 lockfile entries and adds 17, none of them production entries. Most of the additions are the prebuilt @napi-rs/keyring binaries that replace the native keytar module. The suggested npm audit fix --force is not usable here: it installs @babel/cli 8, which requires @babel/core 8 and Node ≥ 24.11 (.nvmrc pins 24.10.0), and it would not touch the vsce path.

Moving to vsce 4 exposed two packages that our bundles used without declaring, because the vsce 3 tree happened to hoist them. buffer@5.7.1 (via keytar) is the Buffer polyfill for @stoplight/yaml-ast-parser in the server's browser bundle, and without it that build fails. supports-color@7.2.0 (via chalk) is debug's optional colour probe in the client and server Node bundles, and without it the build passes with a warning. This PR declares both, at the versions already being bundled, in the workspaces that bundle them: buffer and supports-color in the server's devDependencies, and supports-color in the client's dependencies. As a result, the built output does not change.

Verification

I ran the build job's steps locally on Node 24.10.0 / npm 11.6.1 after a clean npm ci from the updated lockfile. npm audit --audit-level=low reports 0 vulnerabilities, and npm ls braces finds nothing. All of these passed: the lockfile consistency check, check-version-sync, build:types, lint, typescript:check-types, test:tooling, build:prod (all six webpack compilations clean, with no warnings), check-attribution, test:browser, test:previews, npm run test (server unit tests and e2e, 0 failures), npm publish --dry-run --workspace=server and vscode:package.

To confirm the shipped artifacts are unaffected, I built and packaged main and this branch and compared every output file by sha256. All 111 files under client/dist and all 27 under server/dist are byte-identical. Inside the VSIX, the only file that differs is extension/package.json, by exactly the two devDependencies edits in this PR.

The packaging step in CI is meant to exercise vsce's secretlint scan, so I also checked that vsce 4 still enforces it. With a fake RSA private key planted in a packaged file, npm run vscode:package reported found private key ... [privatekey], exited 1 and produced no VSIX. After the file was removed, packaging succeeded.

This repo uses vsce only for packaging. Its credential-storage change from keytar to @napi-rs/keyring only affects vsce login and vsce publish, which nothing here invokes.

  • Examples and attachments are suitable for public disclosure.
  • User-facing documentation reflects the change (no user-facing behavior change).

GHSA-vfj7-8cjw-p6xm (stack-exhaustion DoS) affects every braces release and
has no patched version, so it can only be resolved by removing the packages
that pull braces in. Both paths are development tooling:

- @babel/cli is not invoked by any script; the build uses babel-loader with
  @babel/core. Removing it drops chokidar@3 and its braces dependency.
- @vscode/vsce 4.0.0 replaces the secretlint CLI and globby/fast-glob with
  @secretlint/core and tinyglobby, which drops micromatch and braces. It
  also replaces the native keytar module with prebuilt @napi-rs/keyring.

The vsce 3 tree hoisted buffer@5.7.1 (via keytar) and supports-color@7.2.0
(via chalk), which the bundles resolved without declaring: buffer is the
Buffer polyfill for @stoplight/yaml-ast-parser in the server browser bundle,
and supports-color is debug's optional colour probe in the Node bundles.
Declare both, at the versions already bundled, in the workspaces that bundle
them, so the built client and server output is unchanged.
@frantuma
frantuma requested a review from char0n as a code owner October 6, 2026 09:29
@frantuma
frantuma merged commit 14fbe9e into main Oct 6, 2026
5 checks passed
@frantuma
frantuma deleted the fix/remove-braces-from-dependency-tree branch October 6, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant