Skip to content

Tracking: resolve open Dependabot and code scanning security alerts #1706

Description

@cliffhall

Summary

Tracking issue for the open GitHub security alerts on this repository. This covers both:

As of triage there are 17 open Dependabot alerts and 1 open code scanning alert. Items are grouped so that alerts fixable by a single dependency bump / PR share one checkbox, with the individual alerts bulleted underneath. Resolve each by upgrading the affected dependency (or applying a fix), or dismiss with a rationale if it doesn't apply to how the Inspector uses it.

Code scanning

  • Critical — SSRF fix in server/src/index.ts
    • #53 js/request-forgery — Server-side request forgery

Dependabot

  • hono upgrade (High + Medium)

    • #126 High — CORS middleware reflects any Origin with credentials when origin defaults to wildcard
    • #128 Medium — Body Limit middleware bypass on AWS Lambda via understated Content-Length
    • #127 Medium — Lambda@Edge adapter keeps only last value of a repeated request header
    • #125 Medium — Path traversal in serve-static on Windows via encoded backslash (%5C)
    • #124 Medium — AWS Lambda adapter merges multiple Set-Cookie headers, dropping cookies
  • minimatch upgrade (High)

    • #69 High — ReDoS: matchOne() combinatorial backtracking via non-adjacent GLOBSTAR segments
    • #66 High — ReDoS: nested *() extglobs generate catastrophically backtracking regexes
    • #61 High — ReDoS via repeated wildcards with non-matching literal in pattern
  • vite upgrade (High + Medium)

    • #123 High — server.fs.deny bypass on Windows alternate paths
    • #129 Medium — launch-editor (transitive): NTLMv2 hash disclosure via UNC path handling on Windows
  • js-yaml upgrade (Medium)

    • #134 Medium — Quadratic-complexity DoS in merge key handling via repeated aliases
    • #133 Medium — Quadratic-complexity DoS in merge key handling via repeated aliases
  • shell-quote upgrade (Critical)

    • #120 Critical — quote() does not escape newlines in object .op values
  • vitest upgrade (Critical)

    • #119 Critical — arbitrary file read/execute when Vitest UI server is listening
  • form-data upgrade (High)

    • #130 High — CRLF injection via unescaped multipart field names and filenames
  • @babel/core upgrade (Low)

    • #132 Low — Arbitrary file read via sourceMappingURL comment
  • esbuild upgrade (Low)

    • #121 Low — arbitrary file read when running the dev server on Windows

Counts and links captured at time of filing; check the Security tab for the current live state.

Activity

  1. cliffhall commented on Jul 17, 2026

    @cliffhall
    MemberAuthor

    PRs opened (one per group)

    Group Alerts PR
    shell-quote (Critical) #120 #1711
    vitest (Critical) #119 #1707
    hono #126, #128, #127, #125, #124 #1708
    vite #123, #129 #1709
    minimatch #69, #66, #61 #1715
    form-data #130 #1710
    js-yaml #134, #133 #1713
    esbuild #121 #1714
    @babel/core #132 #1712

    Each PR applies the minimal fix (direct bump or a targeted overrides entry), verifies the vulnerable version is gone via npm ls, and passes the local check suite: prettier --check, check-version, client lint, client tests (535), cli tests (85), and npm run build. E2e (Playwright) was not run locally and is left to CI.

    Note

    Heads-up on CI formatting: main currently has pre-existing Prettier drift on 5 client source files under the latest Prettier (3.9.5), while the lockfile pins 3.7.4. Because CI runs npx prettier --check . before npm install, it fetches the latest Prettier and this step will show red on these PRs regardless of their changes. This should be addressed separately (reformat + pin, or run the format check after install).

  2. cliffhall commented on Jul 17, 2026

    @cliffhall
    MemberAuthor

    Code scanning + CI follow-ups

    That covers all 17 Dependabot alerts + the 1 code-scanning alert on the Security tab, one PR per checkbox group.

  3. cliffhall commented on Jul 17, 2026

    @cliffhall
    MemberAuthor

    Code scanning #53 (SSRF) — dismissed as won't fix with justification. The /fetch proxy must accept dynamic user URLs (localhost/LAN are core use cases), so the allowlist CodeQL requires as a sanitizer isn't viable. PR #1717 adds defense-in-depth instead (DNS-resolved blocklist of link-local/cloud-metadata ranges + per-redirect re-validation, incl. the IPv4-mapped IPv6 form). Alert instances #53 and #62 dismissed.

  4. 10 remaining items

  5. cliffhall commented on Jul 18, 2026

    @cliffhall
    MemberAuthor

    ✅ All items resolved. main audits clean: 0 open Dependabot alerts, and the code-scanning SSRF alert is dismissed with mitigation.

    Merged: #1716 (prettier/CI), #1707 vitest, #1709 vite, #1711 shell-quote, #1708 hono, #1710 form-data, #1712 @babel/core, #1717 SSRF, and #1718 (lockfile regen finalizing esbuild/minimatch/@babel/core + js-yaml guard). PRs #1713/#1714/#1715 were superseded by #1718.

    Note: npm wouldn't apply several transitive overrides to the existing lockfile minimally (leaving residual vulnerable copies), so #1718 regenerated the lockfile with version-targeted overrides — verified 0 vulnerable copies across all nine packages, build + client (535) + cli tests passing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions