Skip to content

Fix undici and brace-expansion audit advisories - #109

Open
Dilusha-Madushan wants to merge 1 commit into
thunder-id:mainfrom
Dilusha-Madushan:fix/audit-undici-brace-expansion
Open

Dilusha-Madushan wants to merge 1 commit into
thunder-id:mainfrom
Dilusha-Madushan:fix/audit-undici-brace-expansion

Conversation

@Dilusha-Madushan

@Dilusha-Madushan Dilusha-Madushan commented Oct 2, 2026 •

Copy link
Copy Markdown

Purpose

The pnpm audit --audit-level=high CI step fails on main with high-severity findings in four packages:

Approach

  • undici: tests/e2e depends on it directly, so its range is raised from ^7.0.0 to ^7.30.0. nuxt@4.5.2 is already the latest release and declares undici ^8.10.0, which allows the patched 8.11.2, so a lockfile refresh was enough. No override is added.
  • brace-expansion: the repo already overrides all three major lines, so the pins in pnpm-workspace.yaml are raised to the latest patch on each line (1.1.21, 2.1.7, 5.0.12). The justification comment is updated with the new advisories.
  • devalue: a new override pins 5.9.4, with a justification comment. It is transitive via nuxt and @nuxt/nitro-server.
  • node-forge: there is nothing to upgrade to, so GHSA-86w9-cpqp-85rv is added to auditConfig.ignoreGhsas with a justification comment. The advisory concerns RSA PKCS#1 v1.5 signature verification, but listhen only uses node-forge to generate RSA keys and self-signed certificates for the local HTTPS dev server and never verifies signatures. The entry should be revisited once node-forge publishes a fixed release.
  • pnpm-lock.yaml: regenerated with pnpm install and pnpm update undici -r. The diff only touches the entries for these packages and the snapshot keys that reference them.

Related Issues

  • N/A

Related PRs

  • N/A

Checklist

  • Followed the contribution guidelines.
  • Manual test round performed and verified. pnpm audit --audit-level=high exits 0 (the remaining high finding is the ignored node-forge entry). pnpm build passes, and the nuxt package tests (122) and the nuxt quickstart build pass. Tests pass in every package except @thunderid/vue, which fails in my local environment because of duplicate vue copies. The @thunderid/express lint errors and the @thunderid/nuxt vue-tsc typecheck failure are identical without this change.
  • Documentation provided. (Add links if there are any)
  • Tests provided. (Add links if there are any)
    • Unit Tests
    • Integration Tests
  • Breaking changes. (Fill if applicable)
    • Breaking changes section filled.
    • breaking change label added.
  • Cross-SDK parity. Exactly one of parity/prs-raised or parity/prs-not-needed added.
    • If parity/prs-raised, the port links are posted as a reply on the parity check's comment.

Security checks

  • Followed secure coding standards.
  • Confirmed that this PR doesn't commit any keys, passwords, tokens, usernames, or other secrets.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: thunder-id/javascript-sdks/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: f1af9dc1-6684-4ba3-a75e-a115ea7ad60b

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🔀 Cross-SDK feature parity, no ports needed

This pull request is labelled parity/prs-not-needed: nothing here has to ship in the other ThunderID SDKs. If that changes, swap the label for parity/prs-raised.

Signed-off-by: Dilusha-Madushan <dilushamadushan9912@gmail.com>
@Dilusha-Madushan
Dilusha-Madushan force-pushed the fix/audit-undici-brace-expansion branch from 3cfbc85 to df50a0a Compare October 2, 2026 07:42
@DonOmalVindula DonOmalVindula added the parity/prs-not-needed Nothing here reaches another SDK label Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

parity/prs-not-needed Nothing here reaches another SDK

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants