fix(security): clear remaining npm CVE backlog (brace-expansion, js-yaml, nanoid) #29

Merged
A-Guevara merged 1 commit from fix-security-npm-backlog into main 2026-08-12 16:37:56 +00:00
Owner

Clears the last of the 10 vulns that have kept the baseline gate red since 2026-08-05:

  • brace-expansion override 5.0.8 → 5.0.9 (CVE-2026-69152) — supersedes #22, which was a pre-2026-08-06 Renovate artifact (package.json bump with no lockfile rewrite; merging it would have desynced the lockfile).
  • js-yaml 4.3.0 → 4.3.1 (GHSA-5p4m-2wfm-xmqj) and postcss's nested nanoid 3.3.16 → 3.3.18 (CVE-2026-67213) — in-range lockfile-only bumps.
  • The CRITICAL @nuxt/devtools CVE-2026-71319 was already cleared by merging #26 (nuxt 4.5.1 brought its nested devtools to 3.4.1; the direct devDep is the unaffected 2.x line) — supersedes #23.

If the gate on this PR runs green, it is the first green baseline on this repo since 8/5 and main goes green on merge.

Clears the last of the 10 vulns that have kept the baseline gate red since 2026-08-05: - **brace-expansion override 5.0.8 → 5.0.9** (CVE-2026-69152) — supersedes #22, which was a pre-2026-08-06 Renovate artifact (package.json bump with no lockfile rewrite; merging it would have desynced the lockfile). - **js-yaml 4.3.0 → 4.3.1** (GHSA-5p4m-2wfm-xmqj) and **postcss's nested nanoid 3.3.16 → 3.3.18** (CVE-2026-67213) — in-range lockfile-only bumps. - The **CRITICAL @nuxt/devtools CVE-2026-71319** was already cleared by merging #26 (nuxt 4.5.1 brought its nested devtools to 3.4.1; the direct devDep is the unaffected 2.x line) — supersedes #23. If the gate on this PR runs green, it is the first green baseline on this repo since 8/5 and main goes green on merge.
fix(security): clear remaining npm CVE backlog
All checks were successful
scan / trivy-fs (pull_request) Successful in 51s
baseline-security / baseline (pull_request) Successful in 1m27s
scan / trivy-fs (push) Successful in 44s
ai-review / review (pull_request) Successful in 3m47s
baseline-security / baseline (push) Successful in 1m18s
2911a67664
- brace-expansion override 5.0.8 → 5.0.9 (CVE-2026-69152; supersedes
  Renovate #22, which bumped package.json without the lockfile — a
  pre-2026-08-06 artifactError artifact)
- js-yaml 4.3.0 → 4.3.1 (GHSA-5p4m-2wfm-xmqj, in-range lockfile bump)
- postcss's nested nanoid 3.3.16 → 3.3.18 (CVE-2026-67213)

The CRITICAL @nuxt/devtools CVE-2026-71319 was already cleared by the
nuxt 4.5.1 merge (#26): the flagged 3.2.4 was nuxt's nested copy, now
3.4.1; the direct devDependency is the unaffected 2.x line (supersedes
Renovate #23).
ai-review-bot left a comment

AI review · advisory

Verdict: 1 thing worth fixing (1 medium).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct (from 5 reviewer findings), 1 confirmed, 1 refuted · web: 2 queries, 6 results · context: 2 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 2 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (1 finding, confidence 0.88): The only issue is an inconsistent brace‑expansion version in the overrides; align it with the lockfile to ensure the vulnerability is patched.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff correctly updates three vulnerable dependencies (brace-expansion, js-yaml, nanoid) to their patched versions and synchronizes the override in package.json, which is consistent with the PR's s
  • Devstral 2 123B (2 findings, confidence 0.85): The changes in the PR diff are mostly correct but contain a high-severity inconsistency in version pinning for brace-expansion and a medium-severity issue with the removal of potentially required depe
  • Laguna S 2.1 (2 findings, confidence 0.92): The diff correctly addresses the three named CVEs by bumping brace-expansion (5.0.8→5.0.9), js-yaml (4.3.0→4.3.1), and nanoid (3.3.16→3.3.18) in package-lock.json with updated integrity hashes; howeve

Web grounding — web: 2 queries, 6 results: «brace-expansion 5.0.9 CVE»; «brace-expansion 5.0.8 CVE»

Grouping — 5 reviewer findings describe 4 distinct defects; reviewers who found the same defect independently count as support.

Round 2 — cross-examination

  • Devstral 2 123B#1 Inconsistent version pinning for brace-expansion · also raised by: GPT-OSS 120B · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Unnecessary removal of cac and commander dependencies · confirmed: — · refuted: GPT-OSS 120B
  • Laguna S 2.1#2 Removed nested @nuxt/cli cac and commander overrides without verifying replaceme · confirmed: — · refuted: GPT-OSS 120B
  • Laguna S 2.1#1 package.json override pinned to stale 5.0.8 while lockfile bumped to 5.0.9 · confirmed: Devstral 2 123B · refuted: GPT-OSS 120B, Gemma 4 31B

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Inconsistent version pinning for brace-expansion — The reviewer claims the override pins to 5.0.8, but the diff explicitly shows the line being changed from "brace-expansion": "5.0.8" to "brace-expansi

Synthesis — Devstral 2 123B wrote the final review from 1 confirmed finding (+2 unconfirmed).

Transcript rv-20260812163425-345258 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260812163425-345258.

### AI review · advisory **Verdict: 1 thing worth fixing** (1 medium). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct (from 5 reviewer findings), 1 confirmed, 1 refuted · web: 2 queries, 6 results · context: 2 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 2 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (1 finding, confidence 0.88): The only issue is an inconsistent brace‑expansion version in the overrides; align it with the lockfile to ensure the vulnerability is patched. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff correctly updates three vulnerable dependencies (brace-expansion, js-yaml, nanoid) to their patched versions and synchronizes the override in package.json, which is consistent with the PR's s - **Devstral 2 123B** (2 findings, confidence 0.85): The changes in the PR diff are mostly correct but contain a high-severity inconsistency in version pinning for brace-expansion and a medium-severity issue with the removal of potentially required depe - **Laguna S 2.1** (2 findings, confidence 0.92): The diff correctly addresses the three named CVEs by bumping brace-expansion (5.0.8→5.0.9), js-yaml (4.3.0→4.3.1), and nanoid (3.3.16→3.3.18) in package-lock.json with updated integrity hashes; howeve **Web grounding** — web: 2 queries, 6 results: «brace-expansion 5.0.9 CVE»; «brace-expansion 5.0.8 CVE» **Grouping** — 5 reviewer findings describe 4 distinct defects; reviewers who found the same defect independently count as support. **Round 2 — cross-examination** - `Devstral 2 123B#1` Inconsistent version pinning for brace-expansion · also raised by: GPT-OSS 120B · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Unnecessary removal of cac and commander dependencies · confirmed: — · refuted: GPT-OSS 120B - `Laguna S 2.1#2` Removed nested @nuxt/cli cac and commander overrides without verifying replaceme · confirmed: — · refuted: GPT-OSS 120B - `Laguna S 2.1#1` package.json override pinned to stale 5.0.8 while lockfile bumped to 5.0.9 · confirmed: Devstral 2 123B · refuted: GPT-OSS 120B, Gemma 4 31B **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Inconsistent version pinning for brace-expansion — The reviewer claims the override pins to 5.0.8, but the diff explicitly shows the line being changed from "brace-expansion": "5.0.8" to "brace-expansi **Synthesis** — Devstral 2 123B wrote the final review from 1 confirmed finding (+2 unconfirmed). <sub>Transcript `rv-20260812163425-345258` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260812163425-345258`.</sub>
@ -2628,34 +2628,12 @@
}
Member

package-lock.json:2628 · MEDIUM — Removed nested @nuxt/cli cac and commander overrides without verifying replacement resolution
The lockfile removes nested overrides for cac and commander under @nuxt/cli, which were likely added to resolve version conflicts. Without these overrides, future installs might fail if the dependency tree cannot satisfy the required versions.

Fix: Run npm ls cac commander after the change. If conflicts appear, restore the overrides to ensure clean resolution.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2628`** · MEDIUM — Removed nested @nuxt/cli cac and commander overrides without verifying replacement resolution The lockfile removes nested overrides for `cac` and `commander` under `@nuxt/cli`, which were likely added to resolve version conflicts. Without these overrides, future installs might fail if the dependency tree cannot satisfy the required versions. > **Fix:** Run `npm ls cac commander` after the change. If conflicts appear, restore the overrides to ensure clean resolution. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812163425-345258:Laguna S 2.1#2 -->
@ -8468,3 +8446,1 @@
"version": "5.0.8",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
"integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
"version": "5.0.9",
Member

package-lock.json:8446 · MEDIUM — Unnecessary removal of cac and commander dependencies
The lockfile removes cac and commander from @nuxt/cli dependencies, which could break functionality if other parts of the codebase or Nuxt itself rely on them.

Fix: Verify if these packages are required and restore them if needed.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:8446`** · MEDIUM — Unnecessary removal of cac and commander dependencies The lockfile removes `cac` and `commander` from `@nuxt/cli` dependencies, which could break functionality if other parts of the codebase or Nuxt itself rely on them. > **Fix:** Verify if these packages are required and restore them if needed. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812163425-345258:Devstral 2 123B#2 -->
@ -101,6 +101,6 @@
},
"overrides": {
"sharp": "^0.35.0",
Member

package.json:103 · MEDIUM — package.json override pinned to stale 5.0.8 while lockfile bumped to 5.0.9
The package.json override for brace-expansion is still set to version 5.0.8, but the lockfile was updated to 5.0.9. This mismatch means a fresh install will pull the older, vulnerable version, undoing the security fix.

Fix: Update the package.json overrides entry to "brace-expansion": "5.0.9" to match the lockfile.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package.json:103`** · MEDIUM — package.json override pinned to stale 5.0.8 while lockfile bumped to 5.0.9 The package.json override for `brace-expansion` is still set to version 5.0.8, but the lockfile was updated to 5.0.9. This mismatch means a fresh install will pull the older, vulnerable version, undoing the security fix. > **Fix:** Update the `package.json` overrides entry to `"brace-expansion": "5.0.9"` to match the lockfile. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260812163425-345258:Laguna S 2.1#1 -->
A-Guevara deleted branch fix-security-npm-backlog 2026-08-12 16:37:56 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!29
No description provided.