Skip to content

fix: address brace-expansion, joi, engine.io, webpack-dev-middleware security advisories - #9866

Open
rishikeshdadam136 wants to merge 1 commit into
masterfrom
WCI-XXXXX
Open

rishikeshdadam136 wants to merge 1 commit into
masterfrom
WCI-XXXXX

Conversation

@rishikeshdadam136

@rishikeshdadam136 rishikeshdadam136 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description

Problem

The beta publish workflow fails at the Enforce Vulnerability Severity Threshold step — 5 of 52 advisory groups at CVSS ≥ 7.0 (HIGH/CRITICAL):

Run: https://github.com/BitGo/BitGoJS/actions/runs/36701187203/job/109840760234

Package CVSS Advisory Vector
brace-expansion@5.0.9 7.5 GHSA-6j4f-fj2g-mc7p stack overflow via uncontrolled recursion in parseCommaParts
brace-expansion@5.0.9 7.5 GHSA-qhr7-859c-m2p7 stack overflow via nested brace groups
engine.io@6.6.7 7.5 GHSA-2gc4-cqfq-p2gv Engine.IO protocol revision mismatch DoS — via karma → socket.io (dev tooling)
joi@17.13.6 7.5 GHSA-6h2x-m376-mqjq quadratic regex backtracking in Joi.string().isoDate() — direct dep of abstract-substrate, sdk-coin-algo, sdk-coin-dot, sdk-coin-polyx
webpack-dev-middleware@7.4.5 7.4 GHSA-g84c-rxfj-3j2c path traversal via non-slash-terminated publicPath — via webpack-dev-server (dev tooling)

These are newly published advisories against versions the repo was already locked to — no code regression.

Goal

Clear the 5 blocking OSV findings so beta publishes again.

Fix

All 5 have upstream fixes within existing semver ranges — version bumps only, no API changes, no new exclusions:

  • brace-expansion 5.0.9 → 5.0.11 — bump root resolutions/overrides pin (fixes both 7.5 advisories)
  • joi 17.13.6 → 17.13.8, engine.io 6.6.7 → 6.6.11, webpack-dev-middleware 7.4.5 → 7.4.6 — yarn.lock refresh (in-range)
  • engine.io 6.6.10+ drops base64id and moves to ws ~8.21.0 → new ws@8.21.3 lock entry
  • Remove stale GHSA-wcpc-wj8m-hjx6 ignore from osv-scanner.toml (protobufjs 7.6.4 pin already fixed it; scanner was warning about the unused ignore)

Issue Number

Ticket: WCI-1715

Type of change

  • Bug fix (non-breaking change which fixes an issue)

How Has This Been Tested?

  • Ran osv-scanner v2.3.8 locally (same image as CI, same osv-scanner.toml): 0 advisory groups at CVSS ≥ 7.0 (was 5); 47 remaining, all ≤ 6.9, which the gate permits; no unused-ignore warning
  • Cross-checked against raw OSV data: 0 advisories affect engine.io@6.6.11, joi@17.13.8, webpack-dev-middleware@7.4.6; brace-expansion@5.0.11 only carries GHSA-q2hr-2g5m-vwhr (CVSS 5.3 — below threshold, pre-existing at 5.0.9)
  • yarn install --frozen-lockfile passes (CI install parity)
  • Clean tsc build of modules/abstract-substrate (direct joi consumer) passes

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • My code compiles correctly for both Node and Browser environments
  • I have commented my code, particularly in hard-to-understand areas
  • My commits follow Conventional Commits and I have properly described any BREAKING CHANGES
  • The ticket or github issue was included in the commit message as a reference
  • I have made corresponding changes to the documentation and on any new/updated functions and/or methods - jsdoc
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes

@rishikeshdadam136 rishikeshdadam136 changed the title fix: address brace-expansion, joi, engine.io, webpack-dev-middleware … fix: address brace-expansion, joi, engine.io, webpack-dev-middleware security advisories Sep 30, 2026
@kisslove-dewangan
kisslove-dewangan marked this pull request as ready for review September 30, 2026 11:45
@kisslove-dewangan
kisslove-dewangan requested review from a team as code owners September 30, 2026 11:45

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants