From 46e1c2644326866eb97eafd5b157d0a9dee32842 Mon Sep 17 00:00:00 2001 From: Hyan Mandian <5044101+hyanmandian@users.noreply.github.com> Date: Fri, 9 Oct 2026 02:53:27 -0300 Subject: [PATCH 1/3] chore(deps-dev): bump source-map-js past its new advisory GHSA-68fv-2mgg-jv7q (high, event-loop denial of service) affects source-map-js < 1.2.2, which postcss and magicast pull in for the dev toolchain. The lockfile now resolves 1.2.2. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 5c02bdda..90e99504 100644 --- a/package-lock.json +++ b/package-lock.json @@ -11997,9 +11997,9 @@ } }, "node_modules/source-map-js": { - "version": "1.2.1", - "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", - "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "version": "1.2.2", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.2.tgz", + "integrity": "sha512-KGj/8Y43x35aZVDtt+J4mK1hoLGHULMYfSkODJNQjNDC3oW1PqPoxMwo0pLUsWM/UEGzON/NxeHywEfNXNP3Vw==", "dev": true, "license": "BSD-3-Clause", "engines": { From 806920b64bef86ef5ebcd215a5ac94b074ecf16a Mon Sep 17 00:00:00 2001 From: Hyan Mandian <5044101+hyanmandian@users.noreply.github.com> Date: Fri, 9 Oct 2026 03:15:46 -0300 Subject: [PATCH 2/3] chore(deps-dev): bump smol-toml and ignore the unfixable sprintf-js advisory in OSV smol-toml 1.9.0 fixes GHSA-r4xh-jqrq-34v2 (knip). GHSA-hp3w-g68c-fv3c has no patched sprintf-js; it only reaches the dev toolchain through @microsoft/api-extractor, so osv-scanner.toml ignores it with the reason, like the extract-zip entries. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu --- osv-scanner.toml | 4 ++++ package-lock.json | 6 +++--- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/osv-scanner.toml b/osv-scanner.toml index c04c91e5..0cfef287 100644 --- a/osv-scanner.toml +++ b/osv-scanner.toml @@ -5,3 +5,7 @@ reason = "extract-zip is a development-only transitive dependency of webdriverio [[IgnoredVulns]] id = "GHSA-7pqw-9j4j-h8q3" reason = "extract-zip is a development-only transitive dependency of webdriverio (browser tests); no patched release exists and it never runs on user input" + +[[IgnoredVulns]] +id = "GHSA-hp3w-g68c-fv3c" +reason = "sprintf-js is a development-only transitive dependency of @microsoft/api-extractor (through argparse); no patched release exists and it only formats the tool's own messages, never user input" diff --git a/package-lock.json b/package-lock.json index 90e99504..f3e20a19 100644 --- a/package-lock.json +++ b/package-lock.json @@ -11974,9 +11974,9 @@ } }, "node_modules/smol-toml": { - "version": "1.8.0", - "resolved": "https://registry.npmjs.org/smol-toml/-/smol-toml-1.8.0.tgz", - "integrity": "sha512-kCZr2V3ch9i00x8zXRhjUNVcjG9ijES5dDudkXvUVCT5QlJNQWElSJdZqyPemffHoLNUYwOcou0Fy+ojN0uHSQ==", + "version": "1.9.0", + "resolved": "https://registry.npmjs.org/smol-toml/-/smol-toml-1.9.0.tgz", + "integrity": "sha512-hpd+HLON7HdZXqYchMM/+LaTTbdK0AU3NngIJ4KVyWbY9bfQqdL9cD+4yf6dUoU2Ap4VsU0JkQi6FxAI1B2mXQ==", "dev": true, "license": "BSD-3-Clause", "engines": { From 829f9217a2a1e52786a066d3bd2d45deddd3dba3 Mon Sep 17 00:00:00 2001 From: Hyan Mandian <5044101+hyanmandian@users.noreply.github.com> Date: Fri, 9 Oct 2026 03:20:26 -0300 Subject: [PATCH 3/3] chore(vex): account for the sprintf-js advisory in openvex.json and audit-ci check:vex requires every suppressed advisory to have a not_affected statement and to be in every suppression list, so GHSA-hp3w-g68c-fv3c gets its statement and the audit-ci allowlist entry. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01RaUEDkvXY8rVWTJG2GKfhu --- .github/workflows/check.yml | 2 +- openvex.json | 25 +++++++++++++++++++++++-- 2 files changed, 24 insertions(+), 3 deletions(-) diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index 8e4ce5b2..f0cea14d 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -68,4 +68,4 @@ jobs: run: npm run check:vex - name: Audit dependencies - run: npx --yes audit-ci@7.1.0 --high --allowlist GHSA-jmr9-qjv8-65gv GHSA-7pqw-9j4j-h8q3 + run: npx --yes audit-ci@7.1.0 --high --allowlist GHSA-jmr9-qjv8-65gv GHSA-7pqw-9j4j-h8q3 GHSA-hp3w-g68c-fv3c diff --git a/openvex.json b/openvex.json index 55a2a943..41c88c17 100644 --- a/openvex.json +++ b/openvex.json @@ -3,8 +3,8 @@ "@id": "https://github.com/brazilian-utils/javascript/blob/main/openvex.json", "author": "Hyan Mandian", "role": "Maintainer of @brazilian-utils/brazilian-utils, see MAINTAINERS.md", - "timestamp": "2026-09-18T04:45:00Z", - "version": 1, + "timestamp": "2026-10-09T06:30:00Z", + "version": 2, "statements": [ { "vulnerability": { @@ -47,6 +47,27 @@ "status": "not_affected", "justification": "component_not_present", "impact_statement": "extract-zip is a development-only transitive dependency (webdriverio -> @wdio/utils -> @puppeteer/browsers -> extract-zip) used by the browser test runner to unpack browser builds downloaded from the vendors in CI. The published package has zero runtime dependencies, so extract-zip is not present in any released asset and never runs on user input. No patched release of extract-zip exists; the statement is withdrawn when webdriverio drops the dependency." + }, + { + "vulnerability": { + "@id": "https://github.com/advisories/GHSA-hp3w-g68c-fv3c", + "name": "GHSA-hp3w-g68c-fv3c", + "description": "sprintf-js denial of service through unbounded precision specifiers" + }, + "timestamp": "2026-10-09T06:30:00Z", + "products": [ + { + "@id": "pkg:npm/%40brazilian-utils/brazilian-utils", + "subcomponents": [ + { + "@id": "pkg:npm/sprintf-js@1.0.3" + } + ] + } + ], + "status": "not_affected", + "justification": "component_not_present", + "impact_statement": "sprintf-js is a development-only transitive dependency (@microsoft/api-extractor -> @rushstack/ts-command-line -> argparse -> sprintf-js) that formats the tool's own messages while the API report is built in CI. The published package has zero runtime dependencies, so sprintf-js is not present in any released asset and never formats user input. No patched release of sprintf-js exists; the statement is withdrawn when argparse drops the dependency." } ] }