Skip to content

Commit 5cb855d

Browse files
author
Release Engineer
committed
fix(deps): cite GHSA-f27v-pv5m-c5g6 as the operative advisory (BLO-39519)
Ally review 5412259637 at 8a82caa, Important (0 Critical). The ledger cited only GHSA-ch52-4w7c-c8xp, which 4.3.0 does not fix and which may be withdrawn: the maintainer closed the upstream report not_planned as bogus and github/advisory-database#10139 is open. Verified against primary sources: /advisories/GHSA-f27v-pv5m-c5g6 is high, CVE-2026-93750, summary names _varyMatches -- the whole 4.2.0 -> 4.3.0 delta -- and carries type: unreviewed with an empty vulnerabilities array, so Dependabot structurally cannot alert on it. If ch52 is withdrawn, f27v is the sole surviving justification for the floor. Also corrects the make-fetch-happen range quoted as load-bearing evidence: the resolved 9.1.0 declares ^4.1.0, not ^4.1.1 (13.x-16.0.1 declare ^4.1.1). Both admit 4.3.0, so the conclusion is unchanged. Comment and ledger only -- no assertion, override or lockfile change. Guard re-run against the real lockfile: green, and still red under both resolution-downgrade and ledger-drift mutations.
1 parent 8a82caa commit 5cb855d

2 files changed

Lines changed: 23 additions & 10 deletions

File tree

‎package.json‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,8 @@
149149
"http-cache-semantics": {
150150
"patchedRange": ">=4.3.0 <5",
151151
"advisories": [
152-
"GHSA-ch52-4w7c-c8xp"
152+
"GHSA-ch52-4w7c-c8xp",
153+
"GHSA-f27v-pv5m-c5g6"
153154
]
154155
}
155156
}

‎scripts/http-cache-semantics-security-override.test.js‎

Lines changed: 21 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -10,10 +10,22 @@ import test from "node:test";
1010
// This advisory was unfixable when it landed, and that is why the floor here is
1111
// worth stating explicitly. 4.2.0 was npm's `latest` and the exact top of the
1212
// vulnerable range, GitHub's advisory carried (and still carries) a null
13-
// first_patched_version, and every make-fetch-happen release through 16.0.1
14-
// pins `http-cache-semantics: ^4.1.1` — so there was no floor to raise and no
15-
// parent to bump. 4.3.0 published 2026-10-04 and is the first release outside
16-
// the range, which turns this back into an ordinary override.
13+
// first_patched_version, and no make-fetch-happen release declared a range that
14+
// excluded it (9.1.0 and 10.2.1 pin `^4.1.0`; 13.x through 16.0.1 pin `^4.1.1`)
15+
// — so there was no floor to raise and no parent to bump. 4.3.0 published
16+
// 2026-10-04 and is the first release outside the range, which turns this back
17+
// into an ordinary override.
18+
//
19+
// GHSA-ch52-4w7c-c8xp is the advisory that makes Dependabot alert, but it is
20+
// NOT the advisory 4.3.0 fixes, and it may not survive: the maintainer closed
21+
// the upstream report `not_planned` as bogus and a withdrawal request is open
22+
// at github/advisory-database#10139. The whole 4.2.0 → 4.3.0 delta is
23+
// `_varyMatches()`, which is GHSA-f27v-pv5m-c5g6 (CVE-2026-93750, high):
24+
// cross-user disclosure via `Vary` wildcard matching. That advisory is
25+
// `type: unreviewed` with an EMPTY `vulnerabilities` array, so no version range
26+
// is mapped and Dependabot structurally cannot alert on it. If ch52 is
27+
// withdrawn, f27v is the sole remaining justification for this floor — do not
28+
// read a closed alert as a reason to drop the override.
1729
//
1830
// Nothing in this repo depends on http-cache-semantics directly. It arrives on
1931
// one thread of optional build-time tooling:
@@ -23,11 +35,11 @@ import test from "node:test";
2335
// -> make-fetch-happen
2436
// -> http-cache-semantics
2537
//
26-
// `make-fetch-happen`'s own `^4.1.1` range already admits 4.3.0, so the pnpm
27-
// override is what pins the floor rather than what makes it reachable: it stops
28-
// a future resolution drifting back down to 4.2.0 while that version is still
29-
// the one most of the ecosystem's integrity hashes point at. The only thing
30-
// that proves the override took is what the lockfile actually resolved.
38+
// `make-fetch-happen@9.1.0`'s own `^4.1.0` range already admits 4.3.0, so the
39+
// pnpm override is what pins the floor rather than what makes it reachable: it
40+
// stops a future resolution drifting back down to 4.2.0 while that version is
41+
// still the one most of the ecosystem's integrity hashes point at. The only
42+
// thing that proves the override took is what the lockfile actually resolved.
3143

3244
const PATCHED_FLOOR = ">=4.3.0 <5";
3345

0 commit comments

Comments
 (0)