Skip to content

Commit bd5bea7

Browse files
committed
fix: raise artifact security pins to advisory-patched floors
check-artifacts.mjs pinned DOMPurify 3.4.14, ip-address 10.5.0, fast-uri 3.1.5, and brace-expansion 1.1.18/2.1.4/5.0.9 as safe floors — every one of them inside the advisory ranges fixed by the dependency bump. Raise them to 3.4.16 / 10.7.1 / 3.1.8 / 1.1.21 / 2.1.7 / 5.0.12, and make the Monaco resolved-version check a floor so future patch bumps do not rebreak it.
1 parent 0cd667c commit bd5bea7

1 file changed

Lines changed: 12 additions & 12 deletions

File tree

‎scripts/security/check-artifacts.mjs‎

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ const vulnerableCode = [
1717
/\.version\s*=\s*["']3\.2\.7["']/,
1818
/\.version\s*=\s*["']3\.4\.7["']/,
1919
];
20-
const safeCode = [/@license DOMPurify 3\.4\.14\b/, /\.version\s*=\s*["'`]3\.4\.14["'`]/];
20+
const safeCode = [/@license DOMPurify 3\.4\.16\b/, /\.version\s*=\s*["'`]3\.4\.16["'`]/];
2121

2222
function compareVersions(left, right) {
2323
const parse = (value) => value.split('-')[0].split('.').map((part) => Number.parseInt(part, 10) || 0);
@@ -60,10 +60,10 @@ async function assertTextArtifactsSafe(label, root, requireSafeDomPurify = false
6060
if (safeCode.some((pattern) => pattern.test(content))) safeDomPurify += 1;
6161
}
6262
if (requireSafeDomPurify && safeDomPurify === 0) {
63-
throw new Error(`${label} does not contain the required DOMPurify 3.4.14 implementation.`);
63+
throw new Error(`${label} does not contain the required DOMPurify 3.4.16 implementation.`);
6464
}
6565
process.stdout.write(
66-
`${label}: vulnerable code absent${requireSafeDomPurify ? '; DOMPurify 3.4.14 present' : ''}.\n`,
66+
`${label}: vulnerable code absent${requireSafeDomPurify ? '; DOMPurify 3.4.16 present' : ''}.\n`,
6767
);
6868
}
6969

@@ -116,17 +116,17 @@ async function assertDependencyProof() {
116116
['ws', floor('8.21.3'), '>=8.21.3'],
117117
['protobufjs', floor('7.6.5'), '>=7.6.5'],
118118
['@protobufjs/utf8', floor('1.1.2'), '>=1.1.2'],
119-
['dompurify', floor('3.4.14'), '>=3.4.14'],
119+
['dompurify', floor('3.4.16'), '>=3.4.16'],
120120
['mermaid', floor('11.17.0'), '>=11.17.0'],
121121
['react-router', floor('7.18.2'), '>=7.18.2'],
122122
['find-my-way', floor('9.9.0'), '>=9.9.0'],
123-
['ip-address', floor('10.5.0'), '>=10.5.0'],
124-
['fast-uri', floor('3.1.5'), '>=3.1.5'],
123+
['ip-address', floor('10.7.1'), '>=10.7.1'],
124+
['fast-uri', floor('3.1.8'), '>=3.1.8'],
125125
['brace-expansion', (version) => {
126-
if (major(version) === 1) return compareVersions(version, '1.1.18') >= 0;
127-
if (major(version) === 2) return compareVersions(version, '2.1.4') >= 0;
128-
return major(version) >= 5 && compareVersions(version, '5.0.9') >= 0;
129-
}, '1.1.18, 2.1.4, or >=5.0.9'],
126+
if (major(version) === 1) return compareVersions(version, '1.1.21') >= 0;
127+
if (major(version) === 2) return compareVersions(version, '2.1.7') >= 0;
128+
return major(version) >= 5 && compareVersions(version, '5.0.12') >= 0;
129+
}, '1.1.21, 2.1.7, or >=5.0.12'],
130130
['js-yaml', (version) => major(version) === 3
131131
? compareVersions(version, '3.15.1') >= 0
132132
: major(version) >= 4 && compareVersions(version, '4.3.1') >= 0, '3.15.1 or >=4.3.1'],
@@ -165,8 +165,8 @@ async function assertDependencyProof() {
165165
const domPurifyPackage = JSON.parse(
166166
await readFile(resolve(dirname(domPurifyEntry), '../package.json'), 'utf8'),
167167
);
168-
if (domPurifyPackage.version !== '3.4.14') {
169-
throw new Error(`Monaco resolves DOMPurify ${domPurifyPackage.version}, expected 3.4.14.`);
168+
if (compareVersions(domPurifyPackage.version, '3.4.16') < 0) {
169+
throw new Error(`Monaco resolves DOMPurify ${domPurifyPackage.version}, expected >=3.4.16.`);
170170
}
171171
for (const distribution of ['dev', 'min']) {
172172
try {

0 commit comments

Comments
 (0)