npm audit --omit=dev in sas/ now fails on a new advisory - braces (GHSA-vfj7-8cjw-p6xm, high, stack exhaustion). It arrives via @sasjs/cli -> shelljs -> fast-glob -> micromatch -> braces, and it has no fixed version: braces 3.0.3 is the latest published, and npm's only offered remedy is downgrading @sasjs/cli to 4.13.1.
This pins the chain away instead, with overrides: { "shelljs": "0.8.5" }. shelljs 0.9.0 was the release that switched to fast-glob; 0.8.5 uses glob and pulls in no braces, micromatch or fast-glob at all.
Because there is nothing to upgrade to. braces has no patched release, both micromatch and fast-glob depend on it, and @sasjs/cli 4.20.6 (latest) still declares shelljs 0.10.0, which still uses fast-glob. The advisory is a stack-exhaustion DoS reachable only by a caller passing a deeply nested brace pattern - in this repo the patterns are ours, so the practical risk is low - but the Check audit step fails on any advisory, and it fails on main and every open PR, so it blocks job2 and therefore all Cypress coverage.
Impact
The CLI uses shelljs for ls, cp, rm and exec only (build/utils/utils.js, commands/docs/generateDocs.js, commands/version/version.js), all of which behave the same in 0.8.5 and 0.10.0. Verified:
npm audit --omit=dev in sas/ -> 0 vulnerabilities
sasjs lint -> runs, same pre-existing warnings as before
sasjs cb -t server -> compiles and builds (this exercises the shelljs ls/cp/rm path in the zip flow)
shelljs.ls('-d', './buil*') and shelljs.exec() from inside @sasjs/cli -> both work
This is a workaround, not a fix. The real fix is upstream in @sasjs/cli: it only needs ls, cp, rm and exec, which node's fs and child_process cover, so shelljs could go entirely - or at least be held to a version that does not pull in fast-glob.
Base
Based on feat/export-dc-library-ddl (#333), like #334 and #335 - main still carries the advisories #333 fixes, so this cannot go green off main.
## What
`npm audit --omit=dev` in `sas/` now fails on a new advisory - `braces` (GHSA-vfj7-8cjw-p6xm, high, stack exhaustion). It arrives via `@sasjs/cli` -> `shelljs` -> `fast-glob` -> `micromatch` -> `braces`, and it has **no fixed version**: `braces` 3.0.3 is the latest published, and npm's only offered remedy is downgrading `@sasjs/cli` to 4.13.1.
This pins the chain away instead, with `overrides: { "shelljs": "0.8.5" }`. shelljs 0.9.0 was the release that switched to fast-glob; 0.8.5 uses `glob` and pulls in no braces, micromatch or fast-glob at all.
```
braces [] (was 3.0.3)
micromatch [] (was 4.0.8)
fast-glob [] (was 3.3.3)
shelljs 0.8.5
```
## Why an override
Because there is nothing to upgrade to. `braces` has no patched release, both `micromatch` and `fast-glob` depend on it, and `@sasjs/cli` 4.20.6 (latest) still declares `shelljs 0.10.0`, which still uses fast-glob. The advisory is a stack-exhaustion DoS reachable only by a caller passing a deeply nested brace pattern - in this repo the patterns are ours, so the practical risk is low - but the `Check audit` step fails on any advisory, and it fails on `main` and every open PR, so it blocks job2 and therefore all Cypress coverage.
## Impact
The CLI uses shelljs for `ls`, `cp`, `rm` and `exec` only (`build/utils/utils.js`, `commands/docs/generateDocs.js`, `commands/version/version.js`), all of which behave the same in 0.8.5 and 0.10.0. Verified:
- `npm audit --omit=dev` in `sas/` -> 0 vulnerabilities
- `sasjs lint` -> runs, same pre-existing warnings as before
- `sasjs cb -t server` -> compiles and builds (this exercises the shelljs `ls`/`cp`/`rm` path in the zip flow)
- `shelljs.ls('-d', './buil*')` and `shelljs.exec()` from inside `@sasjs/cli` -> both work
This is a workaround, not a fix. The real fix is upstream in `@sasjs/cli`: it only needs `ls`, `cp`, `rm` and `exec`, which node's `fs` and `child_process` cover, so `shelljs` could go entirely - or at least be held to a version that does not pull in `fast-glob`.
## Base
Based on `feat/export-dc-library-ddl` (#333), like #334 and #335 - `main` still carries the advisories #333 fixes, so this cannot go green off `main`.
braces (GHSA-vfj7-8cjw-p6xm) arrives via @sasjs/cli > shelljs > fast-glob
> micromatch > braces and has no fixed version - braces 3.0.3 is the
latest release, and npm's only remedy is downgrading @sasjs/cli to
4.13.1. shelljs 0.9.0 is what introduced fast-glob, so pinning shelljs
to 0.8.5 removes braces, micromatch and fast-glob from the tree
entirely. The CLI only uses shelljs for ls/cp/rm/exec, unchanged
between the two versions - sasjs lint and sasjs cb -t server both still
pass.
Reviewed the full base...head diff (sas/package.json plus the regenerated sas/package-lock.json) and repo hardening at this head.
.pre-commit-config.yaml (missing) - standing item also raised on #333/#334: the gitleaks scan still runs only from .git-hooks/pre-commit, and a fresh clone gets no hook at all because the root .npmrc sets ignore-scripts=true, which suppresses the prepare script that would set core.hooksPath; CONTRIBUTING.md:14-17 makes activation a manual step. Add a .pre-commit-config.yaml with the gitleaks hook pinned to an exact release tag so the secret scan is discoverable and activatable with pre-commit install.
sas/package-lock.json:941 - the override swaps in glob 7.2.3, which upstream marks deprecated ("Old versions of glob are not supported, and contain widely publicized security vulnerabilities"), together with the deprecated inflight 1.0.6 (sas/package-lock.json:1149). The sas audit is clean at this head, so this is a knowingly accepted trade for the unpatched braces advisory rather than a blocker; drop the shelljs override once @sasjs/cli ships without the fast-glob/braces chain.
2 findings above for review.
Reviewed the full base...head diff (sas/package.json plus the regenerated sas/package-lock.json) and repo hardening at this head.
- .pre-commit-config.yaml (missing) - standing item also raised on #333/#334: the gitleaks scan still runs only from .git-hooks/pre-commit, and a fresh clone gets no hook at all because the root .npmrc sets ignore-scripts=true, which suppresses the prepare script that would set core.hooksPath; CONTRIBUTING.md:14-17 makes activation a manual step. Add a .pre-commit-config.yaml with the gitleaks hook pinned to an exact release tag so the secret scan is discoverable and activatable with pre-commit install.
- sas/package-lock.json:941 - the override swaps in glob 7.2.3, which upstream marks deprecated ("Old versions of glob are not supported, and contain widely publicized security vulnerabilities"), together with the deprecated inflight 1.0.6 (sas/package-lock.json:1149). The sas audit is clean at this head, so this is a knowingly accepted trade for the unpatched braces advisory rather than a blocker; drop the shelljs override once @sasjs/cli ships without the fast-glob/braces chain.
2 findings above for review.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What
npm audit --omit=devinsas/now fails on a new advisory -braces(GHSA-vfj7-8cjw-p6xm, high, stack exhaustion). It arrives via@sasjs/cli->shelljs->fast-glob->micromatch->braces, and it has no fixed version:braces3.0.3 is the latest published, and npm's only offered remedy is downgrading@sasjs/clito 4.13.1.This pins the chain away instead, with
overrides: { "shelljs": "0.8.5" }. shelljs 0.9.0 was the release that switched to fast-glob; 0.8.5 usesgloband pulls in no braces, micromatch or fast-glob at all.Why an override
Because there is nothing to upgrade to.
braceshas no patched release, bothmicromatchandfast-globdepend on it, and@sasjs/cli4.20.6 (latest) still declaresshelljs 0.10.0, which still uses fast-glob. The advisory is a stack-exhaustion DoS reachable only by a caller passing a deeply nested brace pattern - in this repo the patterns are ours, so the practical risk is low - but theCheck auditstep fails on any advisory, and it fails onmainand every open PR, so it blocks job2 and therefore all Cypress coverage.Impact
The CLI uses shelljs for
ls,cp,rmandexeconly (build/utils/utils.js,commands/docs/generateDocs.js,commands/version/version.js), all of which behave the same in 0.8.5 and 0.10.0. Verified:npm audit --omit=devinsas/-> 0 vulnerabilitiessasjs lint-> runs, same pre-existing warnings as beforesasjs cb -t server-> compiles and builds (this exercises the shelljsls/cp/rmpath in the zip flow)shelljs.ls('-d', './buil*')andshelljs.exec()from inside@sasjs/cli-> both workThis is a workaround, not a fix. The real fix is upstream in
@sasjs/cli: it only needsls,cp,rmandexec, which node'sfsandchild_processcover, soshelljscould go entirely - or at least be held to a version that does not pull infast-glob.Base
Based on
feat/export-dc-library-ddl(#333), like #334 and #335 -mainstill carries the advisories #333 fixes, so this cannot go green offmain.Reviewed the full base...head diff (sas/package.json plus the regenerated sas/package-lock.json) and repo hardening at this head.
.pre-commit-config.yaml (missing) - standing item also raised on #333/#334: the gitleaks scan still runs only from .git-hooks/pre-commit, and a fresh clone gets no hook at all because the root .npmrc sets ignore-scripts=true, which suppresses the prepare script that would set core.hooksPath; CONTRIBUTING.md:14-17 makes activation a manual step. Add a .pre-commit-config.yaml with the gitleaks hook pinned to an exact release tag so the secret scan is discoverable and activatable with pre-commit install.
sas/package-lock.json:941 - the override swaps in glob 7.2.3, which upstream marks deprecated ("Old versions of glob are not supported, and contain widely publicized security vulnerabilities"), together with the deprecated inflight 1.0.6 (sas/package-lock.json:1149). The sas audit is clean at this head, so this is a knowingly accepted trade for the unpatched braces advisory rather than a blocker; drop the shelljs override once @sasjs/cli ships without the fast-glob/braces chain.
2 findings above for review.