Skip to content

fix(deps): resolve shell-quote and other npm audit vulnerabilities (MSDK-4134) - #233

Merged
asadraza-usercentrics merged 2 commits into
masterfrom
security/MSDK-4134-shell-quote-sample-override
Aug 6, 2026
Merged

fix(deps): resolve shell-quote and other npm audit vulnerabilities (MSDK-4134)#233
asadraza-usercentrics merged 2 commits into
masterfrom
security/MSDK-4134-shell-quote-sample-override

Conversation

@asadraza-usercentrics

@asadraza-usercentrics asadraza-usercentrics commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

User description

Summary

  • fix(deps): override shell-quote to >=1.9.0 in sample app — resolves MSDK-4134
    (CVE-2026-9277 Critical + CVE-2026-13311 High in sample/package.json's transitive
    shell-quote dependency, via a package.json override + lockfile regen, mirroring
    the existing pattern from fix(MSDK-3374): resolve npm dependency vulnerabilities  #202/MSDK-3374)
  • fix(deps): resolve npm audit vulnerabilities in root lockfilenpm audit fix at
    the repo root, resolving unrelated pre-existing advisories (body-parser,
    brace-expansion, joi, js-yaml, launch-editor, and a separate newer
    shell-quote DoS CVE GHSA-395f-4hp3-45gv), all via semver-compatible lockfile
    bumps — no package.json ranges changed

Test plan

  • npm audit clean in both sample/ and root (0 vulnerabilities)
  • npm ls shell-quote1.10.0 everywhere in sample/, no 1.8.3 left
  • Package graph diff vs master for sample/ — only shell-quote version/integrity changed
  • Root lockfile diff — only semver-compatible version bumps + one deduped nested content-type; no packages removed unexpectedly
  • Sample app lint: clean; root lint: 0 errors (pre-existing warnings only)
  • Sample app tests: same single pre-existing failure as master (not a regression)
  • Root SDK test suite: 34/34 passing

CodeAnt-AI Description

Close security issues in sample and root dependency locks

What Changed

  • The sample app now forces a safer shell-quote version, removing the vulnerable older release from its installed packages
  • The root and sample lockfiles were refreshed so several known dependency advisories are resolved, including body-parser, brace-expansion, js-yaml, joi, launch-editor, and shell-quote
  • The sample app now also picks up the newer transitive dependency versions needed for the security updates

Impact

✅ Fewer npm audit vulnerabilities
✅ Safer sample app installs
✅ Reduced exposure to dependency security advisories

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Bug Fixes
    • Updated dependency resolution to use a secure version of shell-quote (1.9.0 or newer).

asadraza-usercentrics and others added 2 commits July 24, 2026 17:10
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@codeant-ai

codeant-ai Bot commented Jul 24, 2026

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR dec9ab3 Jul 24, 2026 · 16:14 16:15

@codeant-ai

codeant-ai Bot commented Jul 24, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added the size:M This PR changes 30-99 lines, ignoring generated files label Jul 24, 2026
@coderabbitai

coderabbitai Bot commented Jul 24, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The sample package configuration adds an override requiring shell-quote to resolve to version 1.9.0 or newer.

Changes

Dependency override

Layer / File(s) Summary
Configure shell-quote resolution
sample/package.json
Adds an overrides entry constraining shell-quote to versions >=1.9.0.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: uc-brunosilva

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the dependency vulnerability fix and matches the main audit-related changes.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch security/MSDK-4134-shell-quote-sample-override

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Resolve npm audit vulnerabilities via shell-quote override + lockfile updates

🐞 Bug fix ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Add npm override to force shell-quote >=1.9.0 in the sample app.
• Regenerate sample lockfile to remove vulnerable shell-quote 1.8.3 transitively.
• Apply semver-compatible root lockfile bumps from npm audit fix (no range changes).
Diagram

graph TD
  A(["Security advisories / npm audit"]) --> B["sample/package.json"] --> C["override: shell-quote >=1.9.0"] --> D["sample/package-lock.json"] --> E{{"npm registry"}}
  A --> F["package-lock.json"] --> E
  
  subgraph Legend
    direction LR
    _cmd(["Command / driver"]) ~~~ _file["Config / lockfile"] ~~~ _ext{{"External"}}
  end
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Upgrade direct parents instead of using overrides
  • ➕ Avoids relying on overrides/resolutions semantics
  • ➕ May reduce long-term maintenance if upstream already fixed
  • ➖ May require widening package.json ranges and risk larger behavior changes
  • ➖ Not always possible when vulnerable dep is deeply transitive
2. Use npm audit fix --force (major bumps)
  • ➕ Potentially clears more advisories in one step
  • ➖ Introduces breaking changes via major version upgrades
  • ➖ Higher regression risk than semver-compatible lockfile bumps
3. Pin exact transitive versions (no range) rather than >= constraint
  • ➕ Maximizes reproducibility across environments
  • ➕ Reduces risk of unexpectedly pulling a problematic future patch
  • ➖ Requires more frequent manual updates to stay current
  • ➖ Can conflict with other constraints and increase resolution churn

Recommendation: The chosen approach (sample-level override + semver-compatible lockfile updates) is the best tradeoff for a security hotfix: it removes the vulnerable shell-quote versions without widening top-level dependency ranges or forcing majors. Alternatives were considered, but upgrading parents or forcing majors would increase regression risk relative to the minimal override/lockfile remediation used here.

Files changed (3) +85 / -72

Other (3) +85 / -72
package-lock.jsonApply npm audit fix updates to root dependency graph +78/-68

Apply npm audit fix updates to root dependency graph

• Updates multiple transitive packages to patched versions (e.g., body-parser, brace-expansion, joi, js-yaml, launch-editor, shell-quote) via lockfile-only changes. Includes dependency/dedupe adjustments such as moving to content-type 2.x and removing a redundant nested content-type entry under type-is.

package-lock.json

package-lock.jsonRegenerate sample lockfile with patched shell-quote resolution +4/-4

Regenerate sample lockfile with patched shell-quote resolution

• Bumps transitive shell-quote from 1.8.3 to 1.10.0 in the sample app lockfile to address audit findings. Lockfile regeneration also adjusts some metadata (e.g., typescript marked devOptional).

sample/package-lock.json

package.jsonAdd npm overrides entry to force shell-quote >=1.9.0 +3/-0

Add npm overrides entry to force shell-quote >=1.9.0

• Introduces an npm overrides block in the sample app to constrain transitive resolution of shell-quote to a non-vulnerable version range. This enforces the patched version regardless of upstream transitive requirements.

sample/package.json

@pantoaibot

pantoaibot Bot commented Jul 24, 2026

Copy link
Copy Markdown

PR Summary:

Summary: Add an npm "overrides" entry in sample/package.json to force shell-quote >=1.9.0 to address npm-audit vulnerability (and related transitive dependency issues).

Changes:

  • Added an "overrides" block to sample/package.json:
    • "shell-quote": ">=1.9.0"
  • Purpose: force a safe version of the transitive dependency to resolve the reported vulnerability(s) from npm audit.
  • Scope/impact:
    • Only changes dependency resolution for the sample package; no source code or runtime logic changed.
    • Non-breaking in normal cases, but requires updating lockfile (npm install / npm ci) so CI may show package-lock changes.
  • Recommended follow-ups:
    • Run npm install / npm ci and commit the updated lockfile.
    • Run npm audit to verify the vulnerability is resolved and run relevant tests for the sample project.

Reviewed by Panto AI

Comment thread sample/package.json
Comment thread sample/package.json
@pantoaibot

pantoaibot Bot commented Jul 24, 2026

Copy link
Copy Markdown

Reviewed up to commit:dec9ab36ba7ba5a41951facfb7455b236ea1a5a3

Reviewed by Panto AI

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@sample/package.json`:
- Around line 63-65: Update the shell-quote entry in the overrides configuration
from the open-ended >=1.9.0 range to ^1.10.0, matching the locked 1.10.0 version
while preventing upgrades to major version 2.x.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: dcfba6cc-5244-46b9-ad7e-9a1e2e523fa5

📥 Commits

Reviewing files that changed from the base of the PR and between 3380b40 and dec9ab3.

⛔ Files ignored due to path filters (2)
  • package-lock.json is excluded by !**/package-lock.json
  • sample/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • sample/package.json

Comment thread sample/package.json
@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Node 18 compatibility regression 🐞 Bug ☼ Reliability
Description
The root lockfile now pins brace-expansion@5.0.8 with engines.node set to 20 || >=22, which
contradicts the repo’s documented/support-script requirement of Node.js 18+ and can cause
EBADENGINE warnings or hard install failures in environments that enforce engines. This
effectively raises the minimum supported Node version (at least for dev tooling that depends on
minimatch/brace-expansion) without updating the stated requirements.
Code

package-lock.json[R4571-4582]

    "node_modules/brace-expansion": {
-      "version": "5.0.6",
-      "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
-      "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
+      "version": "5.0.8",
+      "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
+      "integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
      "dev": true,
      "license": "MIT",
      "dependencies": {
        "balanced-match": "^4.0.2"
      },
      "engines": {
-        "node": "18 || 20 || >=22"
+        "node": "20 || >=22"
      }
Evidence
The lockfile explicitly requires Node 20+ for brace-expansion, while the repo requirements
documentation and the requirements-checking script explicitly allow Node 18; additionally,
minimatch still advertises Node 18 support but depends on brace-expansion, making the mismatch
concrete for dev tooling.

package-lock.json[4571-4582]
package-lock.json[8706-8717]
README.md[25-37]
scripts/check-requirements.sh[80-86]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
`package-lock.json` now resolves `brace-expansion` to a version that declares Node `20 || >=22`, while the repo still claims Node 18+ support. This can break contributors and CI variants that use Node 18 (or any package manager/config with strict engine enforcement).

## Issue Context
- Lockfile now pins `brace-expansion@5.0.8` with `engines.node: "20 || >=22"`.
- The repo documentation and `check-requirements` script still treat Node 18 as supported.

## Fix Focus Areas
Choose one of these consistent paths:
1) **Keep Node 18 support**: add an override/resolution to force a Node-18-compatible `brace-expansion` version (and regenerate the lockfile), or adjust the dependency chain so a compatible version is selected.
2) **Drop Node 18 support intentionally**: update the documented minimum Node version everywhere (README, `scripts/check-requirements.sh`, and ideally add an explicit `engines.node` in root `package.json`) to reflect Node 20+.

References:
- package-lock.json[4571-4582]
- README.md[25-37]
- scripts/check-requirements.sh[80-86]
- package-lock.json[8706-8717]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Comment thread package-lock.json
@asadraza-usercentrics
asadraza-usercentrics merged commit fedb5b6 into master Aug 6, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants