Repository navigation
fix(deps): patch brace-expansion in the extension (node-forge has no fix yet) - #88
Merged
Merged
Conversation
Raise the brace-expansion override from ^1.1.16 to ^1.1.21 so web-ext > multimatch > minimatch@3 resolves 1.1.21, which fixes GHSA-q2hr-2g5m-vwhr and the related brace-expansion DoS advisories. node-forge (GHSA-86w9-cpqp-85rv) has no patched release yet; it comes in via web-ext > @devicefarmer/adbkit, a dev-only tool, and adbkit never calls the affected RSA signature verify path.
aaronjmars
pushed a commit
that referenced
this pull request
Oct 10, 2026
PR #64's override pinned shell-quote to ^1.9.0 to clear an older advisory, but that range resolves to 1.10.0 - squarely inside the critical command- injection advisory GHSA-pqg4-j6r4-53mv (1.8.4-1.10.0, CVE-2026-102422), which npm audit flags on this repo today. shell-quote only reaches this extension through web-ext's Firefox-launch chain (a devDependency), so exposure is bounded, but the override itself no longer does what it was written for. 1.11.0 (released 2026-10-06) is the first patched release per the advisory. Bumped the override there; npm ls now resolves 1.12.0 (current latest), clear of the vulnerable range. Verified: npm audit no longer flags shell-quote; npm run build, node build.js validate, node test-extension.js, and npx web-ext lint --source-dir=dist/firefox --self-hosted all pass clean (same checks PR #88 used for the adjacent brace-expansion override bump).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses the two open Dependabot alerts on
opendia-extension/package-lock.json. One is fixed; the other has no upstream fix yet and is explained below.Alerts
web-ext > multimatch > minimatch@3 > brace-expansion. The existing override^1.1.16allowed a vulnerable version (lockfile had 1.1.17). The override is raised to^1.1.21and the lockfile now resolves 1.1.21. This also clears the related brace-expansion DoS advisories thatnpm auditreports for<=1.1.20(GHSA-rgw5-rvv9-x895, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p).<= 1.4.0as vulnerable with no patched version, and 1.4.0 is the newest node-forge on npm. Path:web-ext@10.7.0 (latest) > @devicefarmer/adbkit@3.3.9 (latest, pinned by web-ext) > node-forge. There is no newer web-ext or adbkit that drops it, andnpm audit fix --forcewould downgrade web-ext to 5.1.0, which is not an option.node-forge exposure
Low. web-ext is a devDependency used only for local runs and
web-ext lint/build, so node-forge never ships in the extension. Inside adbkit, node-forge is only used to parse ADB public keys and print them as PEM/OpenSSH (adb/auth.js,cli.js), and that code only runs forweb-ext run --target firefox-android. It never calls the RSA PKCS#1 v1.5 signature verify path the advisory is about. This should be revisited when node-forge ships a fix.What changed
opendia-extension/package.json: brace-expansion override^1.1.16->^1.1.21opendia-extension/package-lock.json: brace-expansion 1.1.17 -> 1.1.21 (no other changes)npm audit (opendia-extension)
Verification (same steps as the CI extension job)
npm cicleannpm run buildok (Chrome + Firefox)node build.js validate- all builds validatednode test-extension.js- exit 0npx web-ext lint --source-dir=dist/firefox --self-hosted- 0 errors, 0 notices, 3 warnings (existing innerHTML warnings), exit 0