The Check audit CI step is red on every push because sas/package.json depends on @sasjs/cli 4.20.1, whose adm-zip 0.6.0 dependency is flagged by GHSA-vwc7-r8mq-g2x9 (CVE-2026-76845, moderate: extraction follows destination symlinks).
There is no remediation available today:
No patched adm-zip release exists (advisory first_patched_version is null; the upstream fix, cthackers/adm-zip#575, is still an unmerged draft PR).
npm audit fix --force (npm's suggestion) would downgrade @sasjs/cli to 3.13.6, a June 2022 release carrying 2 critical + several high advisories (form-data, axios chain via @sasjs/adapter) and lacking 4.x-era config support - strictly worse than the current 2 moderates.
The affected code path is adm-zip extractAllTo inside the CLI, reached only by sasjs create (seed-app extraction into an empty directory). No DC build, deploy or test script invokes it, so the exposure through this repo is not reachable.
Change
scripts/audit-gate.js - npm audit wrapper with an explicit, documented ALLOWED map. Fails on everything except allowlisted advisory IDs; prints the justification for each allowed entry; warns when an allowlist entry no longer matches anything (so it gets removed once a fix ships).
.gitea/workflows/build.yaml and release.yaml - the sas audit step now runs the gate (node ../scripts/audit-gate.js). Root and client audits are unchanged.
Why not audit-ci or similar
Zero new dependencies; the gate is ~100 lines of stdlib node that reads the same npm audit --json report. Verified locally:
DC-equivalent tree (@sasjs/cli 4.20.1, prod deps): gate exits 0, prints the allow reason.
Tree with other vulns (e.g. the axios chain): gate exits 1 and lists each blocked advisory.
Removal
Delete the GHSA-vwc7-r8mq-g2x9 entry (and revert this commit) once @sasjs/cli ships with a patched adm-zip or a replacement extractor - a fix is being prepared upstream (sasjs/cli PR follows).
## Problem
The `Check audit` CI step is red on every push because `sas/package.json` depends on `@sasjs/cli` 4.20.1, whose `adm-zip` 0.6.0 dependency is flagged by [GHSA-vwc7-r8mq-g2x9](https://github.com/advisories/GHSA-vwc7-r8mq-g2x9) (CVE-2026-76845, moderate: extraction follows destination symlinks).
There is no remediation available today:
- No patched adm-zip release exists (advisory `first_patched_version` is null; the upstream fix, cthackers/adm-zip#575, is still an unmerged draft PR).
- `npm audit fix --force` (npm's suggestion) would downgrade `@sasjs/cli` to 3.13.6, a June 2022 release carrying 2 critical + several high advisories (form-data, axios chain via @sasjs/adapter) and lacking 4.x-era config support - strictly worse than the current 2 moderates.
- The affected code path is `adm-zip extractAllTo` inside the CLI, reached only by `sasjs create` (seed-app extraction into an empty directory). No DC build, deploy or test script invokes it, so the exposure through this repo is not reachable.
## Change
- `scripts/audit-gate.js` - npm audit wrapper with an explicit, documented `ALLOWED` map. Fails on everything except allowlisted advisory IDs; prints the justification for each allowed entry; warns when an allowlist entry no longer matches anything (so it gets removed once a fix ships).
- `.gitea/workflows/build.yaml` and `release.yaml` - the `sas` audit step now runs the gate (`node ../scripts/audit-gate.js`). Root and client audits are unchanged.
## Why not audit-ci or similar
Zero new dependencies; the gate is ~100 lines of stdlib node that reads the same `npm audit --json` report. Verified locally:
- DC-equivalent tree (`@sasjs/cli` 4.20.1, prod deps): gate exits 0, prints the allow reason.
- Tree with other vulns (e.g. the axios chain): gate exits 1 and lists each blocked advisory.
## Removal
Delete the `GHSA-vwc7-r8mq-g2x9` entry (and revert this commit) once `@sasjs/cli` ships with a patched adm-zip or a replacement extractor - a fix is being prepared upstream (sasjs/cli PR follows).
hermes
changed title from test to chore(ci): scoped allowlist for npm audit gate in sas2026-09-11 00:33:32 +00:00
allan
changed target branch from main to chore/gitleaks-precommit2026-09-11 07:45:26 +00:00
npm audit in ./sas now runs through scripts/audit-gate.js, which fails on
any vulnerability except an explicit, documented allowlist. Plain npm audit
has no way to exempt an advisory with no available fix, so CI is currently
blocked by GHSA-vwc7-r8mq-g2x9 (adm-zip symlink-following on extraction,
CVE-2026-76845):
- no patched adm-zip release exists (first_patched_version is null; the
upstream fix, cthackers/adm-zip#575, is still unmerged)
- npm's proposed remediation (npm audit fix --force) would downgrade
@sasjs/cli to 3.13.6, a 2022 release that reintroduces 2 critical and
several high advisories via its old dependency tree
- the affected code path (adm-zip extractAllTo in the CLI) is only reached
by 'sasjs create' seed-app extraction, which none of the DC build or
deploy scripts invoke
The gate keeps blocking everything else, prints the reason for each allowed
advisory, and flags allowlist entries that no longer apply so they get
removed when @sasjs/cli ships a fixed extractor.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
The
Check auditCI step is red on every push becausesas/package.jsondepends on@sasjs/cli4.20.1, whoseadm-zip0.6.0 dependency is flagged by GHSA-vwc7-r8mq-g2x9 (CVE-2026-76845, moderate: extraction follows destination symlinks).There is no remediation available today:
first_patched_versionis null; the upstream fix, cthackers/adm-zip#575, is still an unmerged draft PR).npm audit fix --force(npm's suggestion) would downgrade@sasjs/clito 3.13.6, a June 2022 release carrying 2 critical + several high advisories (form-data, axios chain via @sasjs/adapter) and lacking 4.x-era config support - strictly worse than the current 2 moderates.adm-zip extractAllToinside the CLI, reached only bysasjs create(seed-app extraction into an empty directory). No DC build, deploy or test script invokes it, so the exposure through this repo is not reachable.Change
scripts/audit-gate.js- npm audit wrapper with an explicit, documentedALLOWEDmap. Fails on everything except allowlisted advisory IDs; prints the justification for each allowed entry; warns when an allowlist entry no longer matches anything (so it gets removed once a fix ships)..gitea/workflows/build.yamlandrelease.yaml- thesasaudit step now runs the gate (node ../scripts/audit-gate.js). Root and client audits are unchanged.Why not audit-ci or similar
Zero new dependencies; the gate is ~100 lines of stdlib node that reads the same
npm audit --jsonreport. Verified locally:@sasjs/cli4.20.1, prod deps): gate exits 0, prints the allow reason.Removal
Delete the
GHSA-vwc7-r8mq-g2x9entry (and revert this commit) once@sasjs/cliships with a patched adm-zip or a replacement extractor - a fix is being prepared upstream (sasjs/cli PR follows).testto chore(ci): scoped allowlist for npm audit gate in saswe can fix this in source, we don't need an exception
Pull request closed