Skip to content

fix(deps): patch brace-expansion in the extension (node-forge has no fix yet) - #88

Merged
aaronjmars merged 1 commit into
mainfrom
security/dependabot-bumps
Oct 3, 2026
Merged

aaronjmars merged 1 commit into
mainfrom
security/dependabot-bumps

Conversation

@aaronjmars

Copy link
Copy Markdown
Collaborator

Summary

Addresses the two open Dependabot alerts on opendia-extension/package-lock.json. One is fixed; the other has no upstream fix yet and is explained below.

Alerts

node-forge exposure

Low. web-ext is a devDependency used only for local runs and web-ext lint/build, so node-forge never ships in the extension. Inside adbkit, node-forge is only used to parse ADB public keys and print them as PEM/OpenSSH (adb/auth.js, cli.js), and that code only runs for web-ext run --target firefox-android. It never calls the RSA PKCS#1 v1.5 signature verify path the advisory is about. This should be revisited when node-forge ships a fix.

What changed

  • opendia-extension/package.json: brace-expansion override ^1.1.16 -> ^1.1.21
  • opendia-extension/package-lock.json: brace-expansion 1.1.17 -> 1.1.21 (no other changes)

npm audit (opendia-extension)

  • Before: 4 high (brace-expansion, plus the node-forge chain: node-forge, @devicefarmer/adbkit, web-ext)
  • After: 3 high (only the node-forge chain, no upstream fix)
  • opendia-mcp: 0 vulnerabilities, unchanged

Verification (same steps as the CI extension job)

  • npm ci clean
  • npm run build ok (Chrome + Firefox)
  • node build.js validate - all builds validated
  • node test-extension.js - exit 0
  • npx web-ext lint --source-dir=dist/firefox --self-hosted - 0 errors, 0 notices, 3 warnings (existing innerHTML warnings), exit 0

Raise the brace-expansion override from ^1.1.16 to ^1.1.21 so
web-ext > multimatch > minimatch@3 resolves 1.1.21, which fixes
GHSA-q2hr-2g5m-vwhr and the related brace-expansion DoS advisories.

node-forge (GHSA-86w9-cpqp-85rv) has no patched release yet; it comes
in via web-ext > @devicefarmer/adbkit, a dev-only tool, and adbkit
never calls the affected RSA signature verify path.
@aaronjmars aaronjmars changed the title fix(deps): patch node-forge and brace-expansion in the extension fix(deps): patch brace-expansion in the extension (node-forge has no fix yet) Oct 3, 2026
@aaronjmars
aaronjmars merged commit 2de4145 into main Oct 3, 2026
2 checks passed
@aaronjmars
aaronjmars deleted the security/dependabot-bumps branch October 8, 2026 02:19
aaronjmars pushed a commit that referenced this pull request Oct 10, 2026
PR #64's override pinned shell-quote to ^1.9.0 to clear an older advisory,
but that range resolves to 1.10.0 - squarely inside the critical command-
injection advisory GHSA-pqg4-j6r4-53mv (1.8.4-1.10.0, CVE-2026-102422),
which npm audit flags on this repo today. shell-quote only reaches this
extension through web-ext's Firefox-launch chain (a devDependency), so
exposure is bounded, but the override itself no longer does what it was
written for.

1.11.0 (released 2026-10-06) is the first patched release per the
advisory. Bumped the override there; npm ls now resolves 1.12.0 (current
latest), clear of the vulnerable range.

Verified: npm audit no longer flags shell-quote; npm run build, node
build.js validate, node test-extension.js, and npx web-ext lint
--source-dir=dist/firefox --self-hosted all pass clean (same checks
PR #88 used for the adjacent brace-expansion override bump).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant