chore(ci): scoped allowlist for npm audit gate in sas #318

Closed
hermes wants to merge 1 commits from chore/audit-gate-allowlist into chore/gitleaks-precommit
pull from: chore/audit-gate-allowlist
Collaborator

Problem

The Check audit CI step is red on every push because sas/package.json depends on @sasjs/cli 4.20.1, whose adm-zip 0.6.0 dependency is flagged by GHSA-vwc7-r8mq-g2x9 (CVE-2026-76845, moderate: extraction follows destination symlinks).

There is no remediation available today:

  • No patched adm-zip release exists (advisory first_patched_version is null; the upstream fix, cthackers/adm-zip#575, is still an unmerged draft PR).
  • npm audit fix --force (npm's suggestion) would downgrade @sasjs/cli to 3.13.6, a June 2022 release carrying 2 critical + several high advisories (form-data, axios chain via @sasjs/adapter) and lacking 4.x-era config support - strictly worse than the current 2 moderates.
  • The affected code path is adm-zip extractAllTo inside the CLI, reached only by sasjs create (seed-app extraction into an empty directory). No DC build, deploy or test script invokes it, so the exposure through this repo is not reachable.

Change

  • scripts/audit-gate.js - npm audit wrapper with an explicit, documented ALLOWED map. Fails on everything except allowlisted advisory IDs; prints the justification for each allowed entry; warns when an allowlist entry no longer matches anything (so it gets removed once a fix ships).
  • .gitea/workflows/build.yaml and release.yaml - the sas audit step now runs the gate (node ../scripts/audit-gate.js). Root and client audits are unchanged.

Why not audit-ci or similar

Zero new dependencies; the gate is ~100 lines of stdlib node that reads the same npm audit --json report. Verified locally:

  • DC-equivalent tree (@sasjs/cli 4.20.1, prod deps): gate exits 0, prints the allow reason.
  • Tree with other vulns (e.g. the axios chain): gate exits 1 and lists each blocked advisory.

Removal

Delete the GHSA-vwc7-r8mq-g2x9 entry (and revert this commit) once @sasjs/cli ships with a patched adm-zip or a replacement extractor - a fix is being prepared upstream (sasjs/cli PR follows).

## Problem The `Check audit` CI step is red on every push because `sas/package.json` depends on `@sasjs/cli` 4.20.1, whose `adm-zip` 0.6.0 dependency is flagged by [GHSA-vwc7-r8mq-g2x9](https://github.com/advisories/GHSA-vwc7-r8mq-g2x9) (CVE-2026-76845, moderate: extraction follows destination symlinks). There is no remediation available today: - No patched adm-zip release exists (advisory `first_patched_version` is null; the upstream fix, cthackers/adm-zip#575, is still an unmerged draft PR). - `npm audit fix --force` (npm's suggestion) would downgrade `@sasjs/cli` to 3.13.6, a June 2022 release carrying 2 critical + several high advisories (form-data, axios chain via @sasjs/adapter) and lacking 4.x-era config support - strictly worse than the current 2 moderates. - The affected code path is `adm-zip extractAllTo` inside the CLI, reached only by `sasjs create` (seed-app extraction into an empty directory). No DC build, deploy or test script invokes it, so the exposure through this repo is not reachable. ## Change - `scripts/audit-gate.js` - npm audit wrapper with an explicit, documented `ALLOWED` map. Fails on everything except allowlisted advisory IDs; prints the justification for each allowed entry; warns when an allowlist entry no longer matches anything (so it gets removed once a fix ships). - `.gitea/workflows/build.yaml` and `release.yaml` - the `sas` audit step now runs the gate (`node ../scripts/audit-gate.js`). Root and client audits are unchanged. ## Why not audit-ci or similar Zero new dependencies; the gate is ~100 lines of stdlib node that reads the same `npm audit --json` report. Verified locally: - DC-equivalent tree (`@sasjs/cli` 4.20.1, prod deps): gate exits 0, prints the allow reason. - Tree with other vulns (e.g. the axios chain): gate exits 1 and lists each blocked advisory. ## Removal Delete the `GHSA-vwc7-r8mq-g2x9` entry (and revert this commit) once `@sasjs/cli` ships with a patched adm-zip or a replacement extractor - a fix is being prepared upstream (sasjs/cli PR follows).
hermes changed title from test to chore(ci): scoped allowlist for npm audit gate in sas 2026-09-11 00:33:32 +00:00
allan changed target branch from main to chore/gitleaks-precommit 2026-09-11 07:45:26 +00:00
allan added 1 commit 2026-09-11 07:45:26 +00:00
chore(ci): scoped allowlist for npm audit gate in sas
Build / Build-and-ng-test (pull_request) Successful in 5m15s
Lighthouse Checks / lighthouse (pull_request) Successful in 20m44s
Build / Build-and-test-development (pull_request) Successful in 24m23s
6f97390145
npm audit in ./sas now runs through scripts/audit-gate.js, which fails on
any vulnerability except an explicit, documented allowlist. Plain npm audit
has no way to exempt an advisory with no available fix, so CI is currently
blocked by GHSA-vwc7-r8mq-g2x9 (adm-zip symlink-following on extraction,
CVE-2026-76845):

- no patched adm-zip release exists (first_patched_version is null; the
  upstream fix, cthackers/adm-zip#575, is still unmerged)
- npm's proposed remediation (npm audit fix --force) would downgrade
  @sasjs/cli to 3.13.6, a 2022 release that reintroduces 2 critical and
  several high advisories via its old dependency tree
- the affected code path (adm-zip extractAllTo in the CLI) is only reached
  by 'sasjs create' seed-app extraction, which none of the DC build or
  deploy scripts invoke

The gate keeps blocking everything else, prints the reason for each allowed
advisory, and flags allowlist entries that no longer apply so they get
removed when @sasjs/cli ships a fixed extractor.
Owner

we can fix this in source, we don't need an exception

we can fix this in source, we don't need an exception
allan closed this pull request 2026-09-11 08:01:11 +00:00
allan deleted branch chore/audit-gate-allowlist 2026-09-11 08:01:17 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.