fix(security): @nuxtjs/mdc ^0.22.2 and the lockfile's HIGH/CRITICAL advisories; retire scan.yml #70

Merged
A-Guevara merged 2 commits from fix/lockfile-advisories-20261008 into main 2026-10-08 23:59:56 +00:00
Owner

baseline-security (required) and scan / trivy-fs are red on main. The runs are #1170 and #1172 (global runs 9663 and 9665). A scan with today's trivy database reports 25 HIGH/CRITICAL findings in package-lock.json. After this PR, a gate-equivalent scan reports 0.

What changes

Change Advisories How
@nuxtjs/mdc ^0.21.1 → ^0.22.2 (lock 0.21.1 → 0.22.2) CVE-2026-63671 (GHSA-mxm6-v9r6-r94c) Supersedes #59. #59 held this for 3.0. 3.0.0 shipped without it, so it lands now (maintainer's call, 2026-10-08). There is no nested copy any more: packages/* peer on ^3.0.0, which resolves to the workspace root. The $@nuxtjs/mdc override #59 needed is therefore gone.
overrides.brace-expansion 5.0.9 → 5.0.12 CVE-2026-102276, CVE-2026-102278 Same as Renovate's #62, which this makes redundant.
Lockfile updates within the declared ranges devalue ×4, js-yaml, seroval ×2, shell-quote, sharp ×2, source-map-js, svgo, undici ×3, @vue/server-renderer npm update … with npm 11.19.0, the Node 24 npm that deploy-pages.yml uses. The lockfile keeps its npm 11 shape. svgo 4.1.0 brings css-select 6 and css-what 7, as on nis/atlas. 54 version moves in all, nothing removed.
.security-ignore (new) node-forge CVE-2026-85393, braces CVE-2026-93687, simple-git CVE-2026-102826/7/8, @simple-git/argv-parser CVE-2026-102829 Expires 2026-11-02. The header and braces line are the seed PR #43's verbatim, so #43 merges cleanly after this. node-forge and braces have no fixed release. simple-git is fixed only in 4.x, which @nuxt/devtools 3.x cannot load: an override breaks nuxt prepare (proven in nis/template-service#5). All are dev-server or build-time only. Each comment carries the on-expiry command.
The Python kit is valid Python (scripts/sync-engine.mjs, kit/python/components/) — With SCA cleared, the gate's next blocking step, pyflakes, failed on main's tree. It found 333 undefined names in kit/python/components/*.py, because emitPython wrote JS true/false/null/undefined and unquoted enum defaults, and props named for and as made four files unparseable. The emitter now writes Python literals (pythonDefault()), adds PEP 8's trailing underscore to keyword names (pythonName()), and imports Optional only where it's used. I regenerated the Python target only (177 modules). That includes the four files that had drifted behind their Vue props and the missing tux_hero_canvas_sol.py. pyflakes is clean, and every module imports and instantiates. Maintainer's call, 2026-10-08: fix the emitter and regenerate Python only. The PHP/.NET/Swift/Kotlin emitters share the raw-literal pattern and are a follow-up.
.forgejo/workflows/scan.yml deleted — It ran the same trivy fs as the required baseline-security gate but never read .security-ignore, so an advisory with no fix kept it red forever. It also took a runner slot on every push. Its fresh-forge seed is retired in nis/forgejo-stack in the same change (nis/forgejo-stack#239).
CHANGELOG.md — ## [Unreleased] → Security entry.

Checks (local, Node 24.21.0, 2026-10-08)

  • Install. npm ci passes.
  • MDC parity. All 123 tracked .md files parse to identical output (body, data, toc) under @nuxtjs/mdc 0.21.1 and 0.22.2.
  • Typecheck. nuxt typecheck reports the same 189 errors as main, by file, line and code, with none new. Those 189 are pre-existing on main; nothing on the forge runs typecheck here. tti/tti-ai-studio's CI hit them when it type-checked against main.
  • Tests. vitest run passes 218 files / 677 tests.
  • The gate's later steps, run locally after the kit fix: pyflakes over the gate's file set has no undefined names or syntax errors; the workflow YAML parses; semgrep 1.172.0 with the vendored rules has 0 errors and 0 PartialParsing.
  • Published package. The npm pack tarball (2,061 files) contains no node-forge, simple-git or braces code.
  • Pages build. NUXT_PAGES=1 npm run generate succeeds. The output contains none of that code either; the only hits are this changelog entry rendered on /changelog.

Not covered: npm run lint fails on main and here with Cannot find module 'eslint', because eslint isn't in devDependencies. Separately, publish-package is red on the v3.0.0 tag push (the known missing PACKAGE_TOKEN). Neither is changed here.

After this merges: close #59 and #62, update #43 from main and merge it, and rebase or merge #69 as you prefer. #69 changes only package.json's version among these files.

baseline-security (required) and scan / trivy-fs are red on main. The runs are #1170 and #1172 (global runs 9663 and 9665). A scan with today's trivy database reports 25 HIGH/CRITICAL findings in `package-lock.json`. After this PR, a gate-equivalent scan reports 0. ## What changes | Change | Advisories | How | |---|---|---| | `@nuxtjs/mdc` `^0.21.1` → **`^0.22.2`** (lock 0.21.1 → 0.22.2) | CVE-2026-63671 (GHSA-mxm6-v9r6-r94c) | **Supersedes #59.** #59 held this for 3.0. 3.0.0 shipped without it, so it lands now (maintainer's call, 2026-10-08). There is no nested copy any more: `packages/*` peer on `^3.0.0`, which resolves to the workspace root. The `$@nuxtjs/mdc` override #59 needed is therefore gone. | | `overrides.brace-expansion` `5.0.9` → **`5.0.12`** | CVE-2026-102276, CVE-2026-102278 | Same as Renovate's #62, which this makes redundant. | | Lockfile updates within the declared ranges | devalue ×4, js-yaml, seroval ×2, shell-quote, sharp ×2, source-map-js, svgo, undici ×3, @vue/server-renderer | `npm update …` with npm 11.19.0, the Node 24 npm that `deploy-pages.yml` uses. The lockfile keeps its npm 11 shape. svgo 4.1.0 brings css-select 6 and css-what 7, as on nis/atlas. 54 version moves in all, nothing removed. | | `.security-ignore` (new) | node-forge CVE-2026-85393, braces CVE-2026-93687, simple-git CVE-2026-102826/7/8, @simple-git/argv-parser CVE-2026-102829 | Expires 2026-11-02. The header and braces line are the seed PR #43's verbatim, so #43 merges cleanly after this. node-forge and braces have no fixed release. simple-git is fixed only in 4.x, which `@nuxt/devtools` 3.x cannot load: an override breaks `nuxt prepare` (proven in nis/template-service#5). All are dev-server or build-time only. Each comment carries the on-expiry command. | | **The Python kit is valid Python** (`scripts/sync-engine.mjs`, `kit/python/components/`) | — | With SCA cleared, the gate's next blocking step, pyflakes, failed on main's tree. It found 333 undefined names in `kit/python/components/*.py`, because `emitPython` wrote JS `true`/`false`/`null`/`undefined` and unquoted enum defaults, and props named `for` and `as` made four files unparseable. The emitter now writes Python literals (`pythonDefault()`), adds PEP 8's trailing underscore to keyword names (`pythonName()`), and imports `Optional` only where it's used. I regenerated the Python target only (177 modules). That includes the four files that had drifted behind their Vue props and the missing `tux_hero_canvas_sol.py`. pyflakes is clean, and every module imports and instantiates. Maintainer's call, 2026-10-08: fix the emitter and regenerate Python only. The PHP/.NET/Swift/Kotlin emitters share the raw-literal pattern and are a follow-up. | | `.forgejo/workflows/scan.yml` **deleted** | — | It ran the same `trivy fs` as the required baseline-security gate but never read `.security-ignore`, so an advisory with no fix kept it red forever. It also took a runner slot on every push. Its fresh-forge seed is retired in nis/forgejo-stack in the same change (nis/forgejo-stack#239). | | `CHANGELOG.md` | — | `## [Unreleased]` → Security entry. | ## Checks (local, Node 24.21.0, 2026-10-08) - **Install.** `npm ci` passes. - **MDC parity.** All 123 tracked `.md` files parse to identical output (body, data, toc) under `@nuxtjs/mdc` 0.21.1 and 0.22.2. - **Typecheck.** `nuxt typecheck` reports the same 189 errors as main, by file, line and code, with none new. Those 189 are pre-existing on main; nothing on the forge runs typecheck here. tti/tti-ai-studio's CI hit them when it type-checked against main. - **Tests.** `vitest run` passes 218 files / 677 tests. - The gate's later steps, run locally after the kit fix: pyflakes over the gate's file set has no undefined names or syntax errors; the workflow YAML parses; semgrep 1.172.0 with the vendored rules has 0 errors and 0 PartialParsing. - **Published package.** The `npm pack` tarball (2,061 files) contains no node-forge, simple-git or braces code. - **Pages build.** `NUXT_PAGES=1 npm run generate` succeeds. The output contains none of that code either; the only hits are this changelog entry rendered on `/changelog`. **Not covered:** `npm run lint` fails on main and here with *Cannot find module 'eslint'*, because eslint isn't in devDependencies. Separately, publish-package is red on the v3.0.0 tag push (the known missing `PACKAGE_TOKEN`). Neither is changed here. After this merges: close #59 and #62, update #43 from main and merge it, and rebase or merge #69 as you prefer. #69 changes only `package.json`'s version among these files.
fix(security): @nuxtjs/mdc ^0.22.2 and the lockfile's HIGH/CRITICAL advisories; retire scan.yml
Some checks failed
ai-review / review (pull_request) Successful in 1m25s
baseline-security / baseline (push) Failing after 2m0s
baseline-security / baseline (pull_request) Failing after 1m47s
3fff848a7c
baseline-security and scan/trivy-fs are red on main (runs #1170 and #1172):
a scan with today's trivy database reports 25 findings in package-lock.json.

- @nuxtjs/mdc ^0.21.1 -> ^0.22.2 (CVE-2026-63671). #59 held this for 3.0;
  3.0.0 shipped without it, so it lands now and supersedes #59. All 123
  tracked .md files parse to identical output under 0.21.1 and 0.22.2.
- overrides.brace-expansion 5.0.9 -> 5.0.12 (CVE-2026-102276/8), as
  Renovate's #62.
- Lockfile updates within the declared ranges: devalue, js-yaml, seroval,
  shell-quote, sharp, source-map-js, svgo, undici, vue (npm 11.19.0, the
  Node 24 npm the Pages workflow uses).
- .security-ignore: the seed PR #43's header and braces line verbatim, plus
  node-forge (no fixed release) and simple-git/@simple-git/argv-parser
  (fixed only in simple-git 4, which @nuxt/devtools 3.x cannot load), all
  dev-server or build-time only, expiring 2026-11-02.
- .forgejo/workflows/scan.yml retired: the same trivy scan as the required
  baseline-security gate, minus .security-ignore, so it could not go green.

Checked under Node 24.21.0: `npm ci`; `nuxt typecheck` reports the same 189
errors as main, none new; vitest 218 files / 677 tests pass; `npm pack` and
the Pages build (NUXT_PAGES=1 nuxt generate) contain no node-forge,
simple-git or braces code.

AI review · advisory

The AI panel couldn't review this change right now (it will review the next push). Details for admins: panel HTTP 401: {"error": {"message": "missing Forgejo credential", "type": "auth", "code": 401}}

### AI review · advisory _The AI panel couldn't review this change right now (it will review the next push). Details for admins: panel HTTP 401: {"error": {"message": "missing Forgejo credential", "type": "auth", "code": 401}}_
fix(kit): the Python kit is valid Python; emitPython writes Python literals
All checks were successful
baseline-security / baseline (push) Successful in 2m5s
ai-review / review (pull_request) Successful in 1m6s
baseline-security / baseline (pull_request) Successful in 2m28s
d21ec1fa01
With the SCA findings cleared, baseline-security's next blocking step,
pyflakes, failed on main's tree: 333 undefined names in
kit/python/components/*.py. emitPython wrote the schema's JS values raw
(true, false, null, undefined) and enum defaults unquoted (error, md,
maroon), so importing almost any module raised NameError; props named `for`
and `as` made tux_info_label, tux_page_container, tux_portal_shell and
tux_prose unparseable.

- pythonDefault(): True/False, None for null/undefined/missing, a number
  when the default is numeric, otherwise a quoted string; a None default is
  annotated Optional[...].
- pythonName(): Python's hard keywords get a trailing underscore (for_,
  as_).
- `from typing import Optional` only where a field uses it.

Regenerated the Python target only, with the repo's own parseVue and
emitPython over app/components/Tux*.vue (the other ten targets are
untouched). Before the fix the engine reproduced 172 of the 176 committed
files byte for byte; the other four had drifted behind props added to their
Vue sources, and tux_hero_canvas_sol.py was missing, so those come along.

pyflakes 3.4.0 over the gate's file set reports no undefined names or syntax
errors (only advisory warnings in reference/figma-cache/_scripts/sync.py and
kit/python/tux_tokens.py); all 177 modules import and every dataclass
instantiates with its defaults. The gate's later steps also pass locally:
the workflow YAML parses, and semgrep 1.172.0 with the vendored rules has 0
errors and 0 PartialParsing.

AI review · advisory

The AI panel couldn't review this change right now (it will review the next push). Details for admins: panel HTTP 401: {"error": {"message": "missing Forgejo credential", "type": "auth", "code": 401}}

### AI review · advisory _The AI panel couldn't review this change right now (it will review the next push). Details for admins: panel HTTP 401: {"error": {"message": "missing Forgejo credential", "type": "auth", "code": 401}}_
Author
Owner

Merging on the maintainer's go (2026-10-08), as the admin merge; the branch rule wants one approval.

CI is green on d21ec1f. The baseline-security log shows:

  • Active suppressions: 6 trivy;
  • SCA: no HIGH/CRITICAL findings and no leaks found;
  • OK: no undefined names;
  • 7 workflow files parse;
  • semgrep: 0 errors, 0 PartialParsing.

The AI review panel is paused (TAMUS key, since 2026-10-07), and tti-ux has no non-AI review lane yet. In their place:

  • two independent review agents reviewed the lockfile, the overrides, the suppressions and the scan.yml removal;
  • their path and date corrections are in 3fff848;
  • local verification on Node 24: npm ci; typecheck shows the same 189 errors as main, none new; vitest 677/677; the 123 .md files parse identically under mdc 0.21.1 and 0.22.2; npm pack and the Pages build are clean; the regenerated Python kit is pyflakes-clean and every module imports and instantiates.

This supersedes #59 (mdc) and #62 (brace-expansion). #43 (seed) can be updated from main next; its .security-ignore header and braces line match this one. The tti-ux main typecheck debt (189) and the other emitters' raw literals are follow-ups.

Merging on the maintainer's go (2026-10-08), as the admin merge; the branch rule wants one approval. CI is green on d21ec1f. The baseline-security log shows: - `Active suppressions: 6 trivy`; - `SCA: no HIGH/CRITICAL findings` and `no leaks found`; - `OK: no undefined names`; - 7 workflow files parse; - semgrep: 0 errors, 0 PartialParsing. The AI review panel is paused (TAMUS key, since 2026-10-07), and tti-ux has no non-AI review lane yet. In their place: - two independent review agents reviewed the lockfile, the overrides, the suppressions and the `scan.yml` removal; - their path and date corrections are in 3fff848; - local verification on Node 24: `npm ci`; typecheck shows the same 189 errors as main, none new; vitest 677/677; the 123 `.md` files parse identically under mdc 0.21.1 and 0.22.2; `npm pack` and the Pages build are clean; the regenerated Python kit is pyflakes-clean and every module imports and instantiates. This supersedes #59 (mdc) and #62 (brace-expansion). #43 (seed) can be updated from main next; its `.security-ignore` header and braces line match this one. The tti-ux main typecheck debt (189) and the other emitters' raw literals are follow-ups.
A-Guevara deleted branch fix/lockfile-advisories-20261008 2026-10-09 00:00:09 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!70
No description provided.