Skip to content

fix(frontend): clear the high-severity advisories blocking every PR - #444

Merged
fabiodalez-dev merged 1 commit into
mainfrom
fix/frontend-advisories-oct
Oct 1, 2026
Merged

fabiodalez-dev merged 1 commit into
mainfrom
fix/frontend-advisories-oct

Conversation

@fabiodalez-dev

Copy link
Copy Markdown
Owner

npm audit --audit-level=high in frontend/ began failing after the last green run on main, which blocks the required Frontend audit, lint and reproducible build check on every open pull request. main itself is green only because it was last audited on 29 September, before these advisories were published.

Three advisories, all fixable inside the existing semver ranges, so package.json is untouched and only the lockfile moves:

package from to severity advisory
dompurify 3.4.13 3.4.16 high GHSA-p98j-92pf-mc4p
brace-expansion 1.1.20 1.1.21 high GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p
fast-uri 3.1.7 3.1.8 moderate GHSA-hrr3-gc8f-f4qj

The DOMPurify one is the only one with real exposure here: it is a direct dependency and ships inside the vendor bundle. With IN_PLACE, a node-removing afterSanitize hook left event handlers armed on the detached subtree, which gives DOM XSS. The other two are denial-of-service paths in build-time transitive packages.

public/assets/vendor.bundle.js is regenerated because DOMPurify is bundled into it. No other built asset changes.

Verified before pushing

  • npm audit --audit-level=high in frontend/: 0 vulnerabilities (was 1 high, 1 moderate, 1 low).
  • npm run lint: clean.
  • Two consecutive npm run build runs produce a byte-identical vendor.bundle.js (129bdeca…3d7222), so the double-build reproducibility check stays satisfied.
  • Confirmed DOMPurify 3.4.16 is the version actually present in the rebuilt bundle.

`npm audit --audit-level=high` in frontend/ started failing after the last
green run on main, blocking the required Frontend audit check on every open
pull request. Three advisories, all fixable within the existing semver ranges,
so package.json is untouched and only the lockfile moves:

- dompurify 3.4.13 -> 3.4.16 (high, GHSA-p98j-92pf-mc4p): with IN_PLACE, a
  node-removing afterSanitize hook left event handlers armed on the detached
  subtree, giving DOM XSS. This is the one that actually matters here, since
  dompurify is a direct dependency and ships in the vendor bundle.
- brace-expansion 1.1.20 -> 1.1.21 (high, GHSA-q2hr-2g5m-vwhr,
  GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p): three denial-of-service paths,
  transitive and build-time only.
- fast-uri 3.1.7 -> 3.1.8 (moderate, GHSA-hrr3-gc8f-f4qj): inconsistent host
  case normalization. Below the gate's threshold, but it came along with the
  same fix.

public/assets/vendor.bundle.js is regenerated because dompurify is bundled
into it; no other built asset changes. Verified: npm audit reports 0
vulnerabilities, eslint is clean, and two consecutive production builds
produce a byte-identical vendor.bundle.js, so the double-build
reproducibility check stays satisfied.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

💤 Files selected but had no reviewable changes (1)
  • public/assets/vendor.bundle.js
⛔ Files ignored due to path filters (1)
  • frontend/package-lock.json is excluded by !**/package-lock.json
⚙️ Run configuration

Configuration used: Repository: fabiodalez-dev/Pinakes/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a38db391-7965-4762-9545-9d1993b40833

📥 Commits

Reviewing files that changed from the base of the PR and between b1e4547 and 5b63096.

⛔ Files ignored due to path filters (1)
  • frontend/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • public/assets/vendor.bundle.js

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@fabiodalez-dev
fabiodalez-dev merged commit 0e9d2b2 into main Oct 1, 2026
42 of 44 checks passed
@fabiodalez-dev
fabiodalez-dev deleted the fix/frontend-advisories-oct branch October 1, 2026 17:19
fabiodalez-dev added a commit that referenced this pull request Oct 1, 2026
main now ships the same DOMPurify, fast-uri and brace-expansion versions (#444), resolved identically; only the declared DOMPurify range differed. Matching main keeps this branch's diff to its own change.
fabiodalez-dev added a commit that referenced this pull request Oct 1, 2026
main now ships the same DOMPurify, fast-uri and brace-expansion versions (#444), resolved identically; only the declared DOMPurify range differed. Matching main keeps this branch's diff to its own change.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant