fix: address brace-expansion, joi, engine.io, webpack-dev-middleware security advisories - #9866
Open
rishikeshdadam136 wants to merge 1 commit into
Open
rishikeshdadam136 wants to merge 1 commit into
rishikeshdadam136 wants to merge 1 commit into
Conversation
…security advisories Ticket: WCI-1715
rishikeshdadam136
force-pushed
the
WCI-XXXXX
branch
from
September 30, 2026 11:34
319ee88 to
5894d41
Compare
kisslove-dewangan
marked this pull request as ready for review
September 30, 2026 11:45
kisslove-dewangan
approved these changes
Sep 30, 2026
akarath
approved these changes
Sep 30, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Problem
The beta publish workflow fails at the Enforce Vulnerability Severity Threshold step — 5 of 52 advisory groups at CVSS ≥ 7.0 (HIGH/CRITICAL):
Run: https://github.com/BitGo/BitGoJS/actions/runs/36701187203/job/109840760234
brace-expansion@5.0.9parseCommaPartsbrace-expansion@5.0.9engine.io@6.6.7joi@17.13.6Joi.string().isoDate()— direct dep ofabstract-substrate,sdk-coin-algo,sdk-coin-dot,sdk-coin-polyxwebpack-dev-middleware@7.4.5publicPath— via webpack-dev-server (dev tooling)These are newly published advisories against versions the repo was already locked to — no code regression.
Goal
Clear the 5 blocking OSV findings so beta publishes again.
Fix
All 5 have upstream fixes within existing semver ranges — version bumps only, no API changes, no new exclusions:
brace-expansion5.0.9 → 5.0.11— bump rootresolutions/overridespin (fixes both 7.5 advisories)joi17.13.6 → 17.13.8,engine.io6.6.7 → 6.6.11,webpack-dev-middleware7.4.5 → 7.4.6—yarn.lockrefresh (in-range)base64idand moves tows ~8.21.0→ newws@8.21.3lock entryGHSA-wcpc-wj8m-hjx6ignore fromosv-scanner.toml(protobufjs7.6.4pin already fixed it; scanner was warning about the unused ignore)Issue Number
Ticket: WCI-1715
Type of change
How Has This Been Tested?
osv-scanner.toml): 0 advisory groups at CVSS ≥ 7.0 (was 5); 47 remaining, all ≤ 6.9, which the gate permits; no unused-ignore warningengine.io@6.6.11,joi@17.13.8,webpack-dev-middleware@7.4.6;brace-expansion@5.0.11only carries GHSA-q2hr-2g5m-vwhr (CVSS 5.3 — below threshold, pre-existing at 5.0.9)yarn install --frozen-lockfilepasses (CI install parity)tscbuild ofmodules/abstract-substrate(direct joi consumer) passesChecklist