Repository navigation
[Security] The three audited Bun lockfiles carry 1 critical and 17 high advisories — the audit gate has been red since 2026-09-30 #1663
Description
Activity
- addedbugSomething isn't workingSomething isn't workinginfrastructureCI / build / live-integration testsCI / build / live-integration testspriority: highTop priority — high impact, plan nextTop priority — high impact, plan nextdependenciesPull requests that update a dependency filePull requests that update a dependency filesecuritySecurity-relevant — see severity label for impact tierSecurity-relevant — see severity label for impact tierseverity: mediumModerate impact or requires specific conditionsModerate impact or requires specific conditions
on Oct 7, 2026 Scope split, as the body says: GHSA-ch52-4w7c-c8xp (
http-cache-semantics,docs/bun.lockonly) moves to #1664.It has no fixed release.
bun audit fixwould move it to 4.3.0, which leaves themax-stalebranch byte-identical; 4.3.0 is outside the advisory's range only because that range predates it, and github/advisory-database#10184 proposes widening the range to<= 4.3.0. The maintainer decided on 2026-10-07 not to take it, sohttp-cache-semanticsstays at 4.2.0 in this refresh. After the fix,bun run lint:auditunderdocs/reports that one advisory and nothing else. This issue closes with the refresh of the other seventeen; #1664 stays open until upstream resolves the advisory.Landed on local
developas merge 9a6a9d97. It is not pushed; theCloses #1663in 48729788 closes this issue on the push.commit lockfile moves c40c7ed8 bun.lockbrace-expansion 5.0.12, fast-uri 3.1.8 / 4.1.5, proxy-addr 2.0.8, smol-toml 1.9.0 3ff4da36 docs/bun.lockbrace-expansion 5.0.12, devalue 5.9.3, dompurify 3.4.16, markdown-it 14.3.1, sharp 0.35.5, source-map-js 1.2.2; http-cache-semanticsheld at 4.2.0 (#1664)e79487f8 devtools-ui/bun.lockfast-uri 3.1.8, source-map-js 1.2.2 48729788 CHANGELOG.mdSecurityentryVerified on the merged tree:
- Root
bun run lint:auditexits 0 (300 packages) and thedevtools-ui/audit exits 0 (377).docs/lint:auditexits 1 on GHSA-ch52-4w7c-c8xp alone. - Frozen installs pass in all three directories. Every lockfile is still
lockfileVersion: 1, and no manifest changed. typecheckandtypecheck:devare green.tests/unit/ci/1068 pass / 0 fail;tests/unit/http/1129 pass / 0 fail (the 9 skips are the file-symlink capability probe inStaticFiles.test.tson Windows).lint:knipis clean, andcheck:uireports the bundle current (source-hash a23bbfc88a178e9d), soUiAssets.tsis untouched.
One acceptance criterion was not verified locally: the docs site build.
bun run buildunderdocs/hung in "Building static entrypoints" three times on the refreshed lockfile, and the same way on develop's owndocs/bun.lock, so the refresh is not the cause.- Astro 7.3.5, Vite 8.1.5 and Rolldown 1.1.5 are unchanged since the last local build that passed (2026-09-28).
- Probed through the inspector, the hung process's event loop held only Chromium's pipes and process handle: no timer, no file request, no socket.
- Outside Astro, the refreshed
node_moduleswork. Playwright launches and evaluates normally. mermaid-isomorphic, using the build's own font CSS and theme, renders 80 diagrams from 40 concurrent calls in 1.8 s. Its browser bundle carries its own DOMPurify, and neither mermaid nor KaTeX moved. - TypeDoc generation (
markdown-it,minimatch > brace-expansion) and the content sync, the stages before the hang, completed in every attempt.
The criterion therefore rests on
docs-checks.yml's build +check:renderedjob, which runs on the same push that closes this issue. If that job goes red, reopen this.The open Dependabot PRs now conflict with
developin exactly these lockfiles: #1662 inbun.lock, #1647 indocs/bun.lockanddocs/package.json, #1643 indevtools-ui/bun.lockanddevtools-ui/package.json. Their lockfiles predate the refresh: #1662 still pins proxy-addr 2.0.7 and fast-uri 3.1.6 / 4.1.3, #1647 pins devalue 5.8.1 and brace-expansion 5.0.6, and #1643 pins fast-uri 3.1.5. A resolution that takes their side wholesale would bring the advisories back, so runbun audit --audit-level=high(orbun audit fix) on the merged tree of each.- Root
Component
bun.lock,docs/bun.lockanddevtools-ui/bun.lock— the three closures.github/workflows/package-health.ymlaudits withbun audit --audit-level=high(#539, #1413).Severity (your assessment)
MEDIUM — one critical and sixteen high advisories with fixes inside the declared ranges, plus one high with no fixed release (split out, see below). Calibrated like #779 and #1413: no lockfile is published, so a consumer installing
actor-tsresolvesfastify: ^5.12.3fresh and already gets a fixedfast-uri. The parties running the vulnerable versions are this repository's CI — including the job that packs the published tarball and runs the suite on it — the Docker integration runners, and anyone who clones and installs. What puts it above #779's LOW is that the gate has been red on every run since 2026-09-30, and that the critical one, published late on 2026-10-05, landed in a gate that was already red. It changed nothing anyone would see.Exploit walkthrough
The finding is the state of the gate, not an exploit against actor-ts.
The scheduled
package-healthrun 37306681661 (2026-10-05,origin/develop0785f82) failed at "bun audit — advisory database over bun.lock". It is not the first: every package-health run since 2026-09-30 failed at that step, on Dependabot branches first and then on the cron and a feature branch, and the 2026-09-28 cron was the last green one. Onorigin/developit is also the job's only audit step. Thedocs/bun.lockanddevtools-ui/bun.locksteps (#1413, 572077df) exist only on the unpushed localdevelop, so CI has not yet read those two closures at all. Oncedevelopis pushed, they run behind the root step, and a red root step keeps them from running.Re-measured with
bun auditv1.4.2 on 2026-10-07 against localdevelop08602688 (none of the three lockfiles or their manifests changed since 9a672b9e, where it was first measured):bun.lock—bun run lint:audit, exit 1, 7 (1 critical, 6 high):docs/bun.lock—bun run lint:auditunderdocs/, exit 1, 8 high:devtools-ui/bun.lock—bun audit --audit-level=highunderdevtools-ui/, exit 1, 3 high:Where an advisory could actually bite:
proxy-addr(critical) — Express'strust proxywith an IPv4 subnet can be spoofed by a peer presenting an IPv4-mapped IPv6 address.expressis a devDependency and an optional peer here (^4.0.0 || ^5.0.0);express@5.2.1declaresproxy-addr: ^2.0.7, so a consumer resolving it fresh gets 2.0.8. The 2.0.7 copy runs only in this repository's tests and CI.fast-uri— authority injection through an unvalidated port inserialize, and host confusion through an unclosed bracket in the authority. It sits in the runtime closure (fastify > fast-json-stringify > ajv), which ajv uses for schema$refresolution, but the lockfile is not published.brace-expansionunder typedoc and glob,source-map-jsunder sass, css-tree and postcss,devalue's quadraticuneval), a serialization and rejection-handling defect indevalue, and a librsvg defect insharp's bundled libvips.Affected files
bun.lock—proxy-addr,fast-uri(both major lines),brace-expansiondocs/bun.lock—brace-expansion,devalue,http-cache-semantics,sharp,source-map-jsdevtools-ui/bun.lock—fast-uri,source-map-js.github/workflows/package-health.yml— the three audit steps (unchanged by the fix)Fix sketch / approach
One of those moves is not a fix, and it is not taken:
http-cache-semantics4.2.0 → 4.3.0. GHSA-ch52-4w7c-c8xp lists no patched version. 4.3.0 (published 2026-10-04) falls outside the advisory's<=4.2.0range only because the range was written before it existed. Diffing the two published tarballs shows changes to Vary matching and a newstatus()accessor, while themax-stalebranch is byte-identical. github/advisory-database#10184 proposes widening the range to<=4.3.0for exactly that reason. Taking it would turn the docs step green on a range artifact, sohttp-cache-semanticsstays at 4.2.0, and the advisory moves to its own issue (linked in a comment below), which tracks the upstream dispute.After the refresh,
docs/bun.lockalso keeps two advisories below the gate's threshold whose fixes the dependents' ranges block: KaTeX 0.16.45 (low, GHSA-238p-pmpm-9mq7, fixed in 0.18.2,mermaiddeclares^0.16.45) and postcss-selector-parser 6.1.3 (moderate, GHSA-rj75-hqrm-r3gf, fixed in 7.1.6,postcss-nesteddeclares^6.1.1). Neither fails--audit-level=high, and both are out of scope here.Acceptance criteria
bun run lint:auditexits 0 at the root.bun audit --audit-level=highexits 0 underdevtools-ui/.bun run lint:auditunderdocs/reports GHSA-ch52-4w7c-c8xp alone, which is tracked separately, and nothing else.bun install --frozen-lockfilepasses in all three directories, and every lockfile stays atlockfileVersion: 1.--ignore,overridesorresolutionsentry is added;tests/unit/ci/is green (SecurityPolicy, WorkflowHygiene).bun run check:uipasses. If the source-hash moved,src/devtools/generated/UiAssets.tsis regenerated in the same commit.sharpanddevalueboth sit on its build path.Disclosure status
From an audit / scan — affected scope already known
Related: #779, #1413, #539. Open Dependabot PRs touch the same lockfiles and will conflict with this refresh: #1662 (root), #1647 (docs), #1643 (devtools-ui).