Skip to content

ci: set GHSA-ch52-4w7c-c8xp aside in pnpm audit, by ID, until 2026-11-03 - #86

Merged
bryanfawcett merged 1 commit into
mainfrom
ci/audit-ignore-http-cache-semantics
Oct 3, 2026
Merged

bryanfawcett merged 1 commit into
mainfrom
ci/audit-ignore-http-cache-semantics

Conversation

@bryanfawcett

Copy link
Copy Markdown
Member

Why

The audit job fails on GHSA-ch52-4w7c-c8xp (high, http-cache-semantics max-stale handling can disclose cross-user cached responses). Vulnerable <=4.2.0, no patched release; astro 7.3.x (latest stable 7.3.5) depends on ^4.2.0. Path: site / nyuchi-docs-search -> @astrojs/starlight -> astro -> http-cache-semantics.

Exploitability here

astro imports the package only in dist/assets/build/remote.js (from core/build/static-build -> generate), to cache remote images while astro build runs. The site is static output served from Workers static assets behind site/src/worker/gate.ts, which imports only jose and local modules, not astro. The vulnerable path runs only in our own build, never for a visitor.

Change

  • pnpm-workspace.yaml: auditConfig.ignoreGhsas: [GHSA-ch52-4w7c-c8xp], with the reasoning, the date it was added (2026-10-03) and the recheck date (2026-11-03) in comments. pnpm's own per-advisory ignore; --audit-level=high is unchanged, so any other high advisory still fails.
  • build.yml: a step in the audit job fails once 2026-11-03 passes, so the exception cannot outlive its reasoning.

Tested locally: pnpm audit --audit-level=high -> "1 high (1 ignored)", exit 0; pnpm install --frozen-lockfile unaffected.

Same treatment as nyuchi/learning#63.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq

http-cache-semantics <=4.2.0 has no patched release; astro (via
starlight) depends on it. astro uses it only to cache remote images
during `astro build`, and the site ships as static assets behind a
worker that does not import astro, so the path never runs for a visitor.

pnpm-workspace.yaml's auditConfig.ignoreGhsas sets that one advisory
aside, with its reasoning and dates; a step in the audit job fails once
the recheck date passes. The audit level is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
nyuchi-docs-mcp 844842d Commit Preview URL

Branch Preview URL
Oct 03 2026, 05:55 AM

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
shamwari-docs-ai 844842d Commit Preview URL

Branch Preview URL
Oct 03 2026, 05:55 AM

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
nyuchi-docs 844842d Commit Preview URL

Branch Preview URL
Oct 03 2026, 05:55 AM

@bryanfawcett
bryanfawcett merged commit e394924 into main Oct 3, 2026
20 checks passed
@bryanfawcett
bryanfawcett deleted the ci/audit-ignore-http-cache-semantics branch October 3, 2026 05:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant