fix(deps): pin shelljs to clear the braces advisory in the sas audit #336

Merged
allan merged 1 commits from fix/audit-braces into feat/export-dc-library-ddl 2026-10-03 17:26:06 +00:00
Collaborator

What

npm audit --omit=dev in sas/ now fails on a new advisory - braces (GHSA-vfj7-8cjw-p6xm, high, stack exhaustion). It arrives via @sasjs/cli -> shelljs -> fast-glob -> micromatch -> braces, and it has no fixed version: braces 3.0.3 is the latest published, and npm's only offered remedy is downgrading @sasjs/cli to 4.13.1.

This pins the chain away instead, with overrides: { "shelljs": "0.8.5" }. shelljs 0.9.0 was the release that switched to fast-glob; 0.8.5 uses glob and pulls in no braces, micromatch or fast-glob at all.

braces      []      (was 3.0.3)
micromatch  []      (was 4.0.8)
fast-glob   []      (was 3.3.3)
shelljs     0.8.5

Why an override

Because there is nothing to upgrade to. braces has no patched release, both micromatch and fast-glob depend on it, and @sasjs/cli 4.20.6 (latest) still declares shelljs 0.10.0, which still uses fast-glob. The advisory is a stack-exhaustion DoS reachable only by a caller passing a deeply nested brace pattern - in this repo the patterns are ours, so the practical risk is low - but the Check audit step fails on any advisory, and it fails on main and every open PR, so it blocks job2 and therefore all Cypress coverage.

Impact

The CLI uses shelljs for ls, cp, rm and exec only (build/utils/utils.js, commands/docs/generateDocs.js, commands/version/version.js), all of which behave the same in 0.8.5 and 0.10.0. Verified:

  • npm audit --omit=dev in sas/ -> 0 vulnerabilities
  • sasjs lint -> runs, same pre-existing warnings as before
  • sasjs cb -t server -> compiles and builds (this exercises the shelljs ls/cp/rm path in the zip flow)
  • shelljs.ls('-d', './buil*') and shelljs.exec() from inside @sasjs/cli -> both work

This is a workaround, not a fix. The real fix is upstream in @sasjs/cli: it only needs ls, cp, rm and exec, which node's fs and child_process cover, so shelljs could go entirely - or at least be held to a version that does not pull in fast-glob.

Base

Based on feat/export-dc-library-ddl (#333), like #334 and #335 - main still carries the advisories #333 fixes, so this cannot go green off main.

## What `npm audit --omit=dev` in `sas/` now fails on a new advisory - `braces` (GHSA-vfj7-8cjw-p6xm, high, stack exhaustion). It arrives via `@sasjs/cli` -> `shelljs` -> `fast-glob` -> `micromatch` -> `braces`, and it has **no fixed version**: `braces` 3.0.3 is the latest published, and npm's only offered remedy is downgrading `@sasjs/cli` to 4.13.1. This pins the chain away instead, with `overrides: { "shelljs": "0.8.5" }`. shelljs 0.9.0 was the release that switched to fast-glob; 0.8.5 uses `glob` and pulls in no braces, micromatch or fast-glob at all. ``` braces [] (was 3.0.3) micromatch [] (was 4.0.8) fast-glob [] (was 3.3.3) shelljs 0.8.5 ``` ## Why an override Because there is nothing to upgrade to. `braces` has no patched release, both `micromatch` and `fast-glob` depend on it, and `@sasjs/cli` 4.20.6 (latest) still declares `shelljs 0.10.0`, which still uses fast-glob. The advisory is a stack-exhaustion DoS reachable only by a caller passing a deeply nested brace pattern - in this repo the patterns are ours, so the practical risk is low - but the `Check audit` step fails on any advisory, and it fails on `main` and every open PR, so it blocks job2 and therefore all Cypress coverage. ## Impact The CLI uses shelljs for `ls`, `cp`, `rm` and `exec` only (`build/utils/utils.js`, `commands/docs/generateDocs.js`, `commands/version/version.js`), all of which behave the same in 0.8.5 and 0.10.0. Verified: - `npm audit --omit=dev` in `sas/` -> 0 vulnerabilities - `sasjs lint` -> runs, same pre-existing warnings as before - `sasjs cb -t server` -> compiles and builds (this exercises the shelljs `ls`/`cp`/`rm` path in the zip flow) - `shelljs.ls('-d', './buil*')` and `shelljs.exec()` from inside `@sasjs/cli` -> both work This is a workaround, not a fix. The real fix is upstream in `@sasjs/cli`: it only needs `ls`, `cp`, `rm` and `exec`, which node's `fs` and `child_process` cover, so `shelljs` could go entirely - or at least be held to a version that does not pull in `fast-glob`. ## Base Based on `feat/export-dc-library-ddl` (#333), like #334 and #335 - `main` still carries the advisories #333 fixes, so this cannot go green off `main`.
hermes added 1 commit 2026-10-03 12:40:44 +00:00
fix(deps): pin shelljs to clear the braces advisory in the sas audit
Build / Build-and-ng-test (pull_request) Successful in 5m19s
Lighthouse Checks / lighthouse (pull_request) Successful in 21m58s
Build / Build-and-test-development (pull_request) Successful in 29m37s
6e5093858b
braces (GHSA-vfj7-8cjw-p6xm) arrives via @sasjs/cli > shelljs > fast-glob
> micromatch > braces and has no fixed version - braces 3.0.3 is the
latest release, and npm's only remedy is downgrading @sasjs/cli to
4.13.1.  shelljs 0.9.0 is what introduced fast-glob, so pinning shelljs
to 0.8.5 removes braces, micromatch and fast-glob from the tree
entirely.  The CLI only uses shelljs for ls/cp/rm/exec, unchanged
between the two versions - sasjs lint and sasjs cb -t server both still
pass.
hermes left a comment
Author
Collaborator

Reviewed the full base...head diff (sas/package.json plus the regenerated sas/package-lock.json) and repo hardening at this head.

  • .pre-commit-config.yaml (missing) - standing item also raised on #333/#334: the gitleaks scan still runs only from .git-hooks/pre-commit, and a fresh clone gets no hook at all because the root .npmrc sets ignore-scripts=true, which suppresses the prepare script that would set core.hooksPath; CONTRIBUTING.md:14-17 makes activation a manual step. Add a .pre-commit-config.yaml with the gitleaks hook pinned to an exact release tag so the secret scan is discoverable and activatable with pre-commit install.

  • sas/package-lock.json:941 - the override swaps in glob 7.2.3, which upstream marks deprecated ("Old versions of glob are not supported, and contain widely publicized security vulnerabilities"), together with the deprecated inflight 1.0.6 (sas/package-lock.json:1149). The sas audit is clean at this head, so this is a knowingly accepted trade for the unpatched braces advisory rather than a blocker; drop the shelljs override once @sasjs/cli ships without the fast-glob/braces chain.

2 findings above for review.

Reviewed the full base...head diff (sas/package.json plus the regenerated sas/package-lock.json) and repo hardening at this head. - .pre-commit-config.yaml (missing) - standing item also raised on #333/#334: the gitleaks scan still runs only from .git-hooks/pre-commit, and a fresh clone gets no hook at all because the root .npmrc sets ignore-scripts=true, which suppresses the prepare script that would set core.hooksPath; CONTRIBUTING.md:14-17 makes activation a manual step. Add a .pre-commit-config.yaml with the gitleaks hook pinned to an exact release tag so the secret scan is discoverable and activatable with pre-commit install. - sas/package-lock.json:941 - the override swaps in glob 7.2.3, which upstream marks deprecated ("Old versions of glob are not supported, and contain widely publicized security vulnerabilities"), together with the deprecated inflight 1.0.6 (sas/package-lock.json:1149). The sas audit is clean at this head, so this is a knowingly accepted trade for the unpatched braces advisory rather than a blocker; drop the shelljs override once @sasjs/cli ships without the fast-glob/braces chain. 2 findings above for review.
allan merged commit b505e45c6f into feat/export-dc-library-ddl 2026-10-03 17:26:06 +00:00
allan deleted branch fix/audit-braces 2026-10-03 17:26:06 +00:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dc/dc#336