Skip to content

[Security] The three audited Bun lockfiles carry 1 critical and 17 high advisories — the audit gate has been red since 2026-09-30 #1663

Description

@pathosDev

Component

bun.lock, docs/bun.lock and devtools-ui/bun.lock — the three closures .github/workflows/package-health.yml audits with bun audit --audit-level=high (#539, #1413).

Severity (your assessment)

MEDIUM — one critical and sixteen high advisories with fixes inside the declared ranges, plus one high with no fixed release (split out, see below). Calibrated like #779 and #1413: no lockfile is published, so a consumer installing actor-ts resolves fastify: ^5.12.3 fresh and already gets a fixed fast-uri. The parties running the vulnerable versions are this repository's CI — including the job that packs the published tarball and runs the suite on it — the Docker integration runners, and anyone who clones and installs. What puts it above #779's LOW is that the gate has been red on every run since 2026-09-30, and that the critical one, published late on 2026-10-05, landed in a gate that was already red. It changed nothing anyone would see.

Exploit walkthrough

The finding is the state of the gate, not an exploit against actor-ts.

The scheduled package-health run 37306681661 (2026-10-05, origin/develop 0785f82) failed at "bun audit — advisory database over bun.lock". It is not the first: every package-health run since 2026-09-30 failed at that step, on Dependabot branches first and then on the cron and a feature branch, and the 2026-09-28 cron was the last green one. On origin/develop it is also the job's only audit step. The docs/bun.lock and devtools-ui/bun.lock steps (#1413, 572077df) exist only on the unpushed local develop, so CI has not yet read those two closures at all. Once develop is pushed, they run behind the root step, and a red root step keeps them from running.

Re-measured with bun audit v1.4.2 on 2026-10-07 against local develop 08602688 (none of the three lockfiles or their manifests changed since 9a672b9e, where it was first measured):

bun.lock — bun run lint:audit, exit 1, 7 (1 critical, 6 high):

proxy-addr@2.0.7       express > proxy-addr                                  critical  GHSA-jqcg-44mw-7w3h   <2.0.8
fast-uri@3.1.6, 4.1.3  fastify > fast-json-stringify > ajv > fast-uri        high      GHSA-qw65-cvwx-89v3   <3.1.7, <4.1.4
                       (also @fastify/ajv-compiler)                          high      GHSA-58mr-gqgx-xq4g   =3.1.6, =4.1.3
brace-expansion@5.0.9  @fastify/static > glob > minimatch > brace-expansion  high      GHSA-qhr7-859c-m2p7   <5.0.11
                                                                             high      GHSA-6j4f-fj2g-mc7p   <5.0.10

docs/bun.lock — bun run lint:audit under docs/, exit 1, 8 high:

brace-expansion@5.0.9       typedoc > minimatch > brace-expansion    GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p
devalue@5.9.1               astro > devalue                          GHSA-j22f-vq7h-c4qm, GHSA-mcm9-63f2-9j32, GHSA-x5rw-q4pp-hg5g   <=5.9.2, fixed 5.9.3
http-cache-semantics@4.2.0  astro > http-cache-semantics             GHSA-ch52-4w7c-c8xp   <=4.2.0, no patched release
sharp@0.35.4                direct; astro > sharp                    GHSA-wq5f-xc86-pv6w   <0.35.5
source-map-js@1.2.1         astro > unifont > css-tree; postcss      GHSA-68fv-2mgg-jv7q   <1.2.2

devtools-ui/bun.lock — bun audit --audit-level=high under devtools-ui/, exit 1, 3 high:

fast-uri@3.1.6       @angular-devkit/core > ajv > fast-uri       GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g
source-map-js@1.2.1  @angular/build > sass; jsdom > … > css-tree  GHSA-68fv-2mgg-jv7q

Where an advisory could actually bite:

  • proxy-addr (critical) — Express's trust proxy with an IPv4 subnet can be spoofed by a peer presenting an IPv4-mapped IPv6 address. express is a devDependency and an optional peer here (^4.0.0 || ^5.0.0); express@5.2.1 declares proxy-addr: ^2.0.7, so a consumer resolving it fresh gets 2.0.8. The 2.0.7 copy runs only in this repository's tests and CI.
  • fast-uri — authority injection through an unvalidated port in serialize, and host confusion through an unclosed bracket in the authority. It sits in the runtime closure (fastify > fast-json-stringify > ajv), which ajv uses for schema $ref resolution, but the lockfile is not published.
  • The rest are denial of service in build and test tooling (brace-expansion under typedoc and glob, source-map-js under sass, css-tree and postcss, devalue's quadratic uneval), a serialization and rejection-handling defect in devalue, and a librsvg defect in sharp's bundled libvips.

Affected files

  • bun.lock — proxy-addr, fast-uri (both major lines), brace-expansion
  • docs/bun.lock — brace-expansion, devalue, http-cache-semantics, sharp, source-map-js
  • devtools-ui/bun.lock — fast-uri, source-map-js
  • .github/workflows/package-health.yml — the three audit steps (unchanged by the fix)

Fix sketch / approach

// The shape #779 (5c4d2cfd), 7ade793d and d615d8d5 took: `bun audit fix` in
// each directory, refreshing the lockfile in place. No manifest edit, no
// `--ignore`, no `overrides`. Never regenerate a lockfile from scratch: it
// comes back as lockfileVersion 2, which Dependabot's bun updater cannot read.
//
// `bun audit fix --dry-run`, 2026-10-07:
//   root         brace-expansion 5.0.9 -> 5.0.12, fast-uri 3.1.6 -> 3.1.8 and
//                4.1.3 -> 4.1.5, proxy-addr 2.0.7 -> 2.0.8, smol-toml 1.8.0 -> 1.9.0
//   docs/        brace-expansion 5.0.9 -> 5.0.12, devalue 5.9.1 -> 5.9.3,
//                dompurify 3.4.13 -> 3.4.16, http-cache-semantics 4.2.0 -> 4.3.0,
//                markdown-it 14.3.0 -> 14.3.1, sharp 0.35.4 -> 0.35.5,
//                smol-toml 1.7.1 -> 1.9.0, source-map-js 1.2.1 -> 1.2.2
//   devtools-ui/ fast-uri 3.1.6 -> 3.1.8, source-map-js 1.2.1 -> 1.2.2

One of those moves is not a fix, and it is not taken: http-cache-semantics 4.2.0 → 4.3.0. GHSA-ch52-4w7c-c8xp lists no patched version. 4.3.0 (published 2026-10-04) falls outside the advisory's <=4.2.0 range only because the range was written before it existed. Diffing the two published tarballs shows changes to Vary matching and a new status() accessor, while the max-stale branch is byte-identical. github/advisory-database#10184 proposes widening the range to <=4.3.0 for exactly that reason. Taking it would turn the docs step green on a range artifact, so http-cache-semantics stays at 4.2.0, and the advisory moves to its own issue (linked in a comment below), which tracks the upstream dispute.

After the refresh, docs/bun.lock also keeps two advisories below the gate's threshold whose fixes the dependents' ranges block: KaTeX 0.16.45 (low, GHSA-238p-pmpm-9mq7, fixed in 0.18.2, mermaid declares ^0.16.45) and postcss-selector-parser 6.1.3 (moderate, GHSA-rj75-hqrm-r3gf, fixed in 7.1.6, postcss-nested declares ^6.1.1). Neither fails --audit-level=high, and both are out of scope here.

Acceptance criteria

  • bun run lint:audit exits 0 at the root.
  • bun audit --audit-level=high exits 0 under devtools-ui/.
  • bun run lint:audit under docs/ reports GHSA-ch52-4w7c-c8xp alone, which is tracked separately, and nothing else.
  • bun install --frozen-lockfile passes in all three directories, and every lockfile stays at lockfileVersion: 1.
  • No manifest range is widened, and no --ignore, overrides or resolutions entry is added; tests/unit/ci/ is green (SecurityPolicy, WorkflowHygiene).
  • bun run check:ui passes. If the source-hash moved, src/devtools/generated/UiAssets.ts is regenerated in the same commit.
  • The docs site still builds on the refreshed closure; sharp and devalue both sit on its build path.

Disclosure status

From an audit / scan — affected scope already known


Related: #779, #1413, #539. Open Dependabot PRs touch the same lockfiles and will conflict with this refresh: #1662 (root), #1647 (docs), #1643 (devtools-ui).

Activity

  1. added
    bugSomething isn't working
    infrastructureCI / build / live-integration tests
    priority: highTop priority — high impact, plan next
    dependenciesPull requests that update a dependency file
    securitySecurity-relevant — see severity label for impact tier
    severity: mediumModerate impact or requires specific conditions
    on Oct 7, 2026
  2. pathosDev commented on Oct 7, 2026

    @pathosDev
    OwnerAuthor

    Scope split, as the body says: GHSA-ch52-4w7c-c8xp (http-cache-semantics, docs/bun.lock only) moves to #1664.

    It has no fixed release. bun audit fix would move it to 4.3.0, which leaves the max-stale branch byte-identical; 4.3.0 is outside the advisory's range only because that range predates it, and github/advisory-database#10184 proposes widening the range to <= 4.3.0. The maintainer decided on 2026-10-07 not to take it, so http-cache-semantics stays at 4.2.0 in this refresh. After the fix, bun run lint:audit under docs/ reports that one advisory and nothing else. This issue closes with the refresh of the other seventeen; #1664 stays open until upstream resolves the advisory.

  3. pathosDev commented on Oct 7, 2026

    @pathosDev
    OwnerAuthor

    Landed on local develop as merge 9a6a9d97. It is not pushed; the Closes #1663 in 48729788 closes this issue on the push.

    commit lockfile moves
    c40c7ed8 bun.lock brace-expansion 5.0.12, fast-uri 3.1.8 / 4.1.5, proxy-addr 2.0.8, smol-toml 1.9.0
    3ff4da36 docs/bun.lock brace-expansion 5.0.12, devalue 5.9.3, dompurify 3.4.16, markdown-it 14.3.1, sharp 0.35.5, source-map-js 1.2.2; http-cache-semantics held at 4.2.0 (#1664)
    e79487f8 devtools-ui/bun.lock fast-uri 3.1.8, source-map-js 1.2.2
    48729788 CHANGELOG.md Security entry

    Verified on the merged tree:

    • Root bun run lint:audit exits 0 (300 packages) and the devtools-ui/ audit exits 0 (377). docs/ lint:audit exits 1 on GHSA-ch52-4w7c-c8xp alone.
    • Frozen installs pass in all three directories. Every lockfile is still lockfileVersion: 1, and no manifest changed.
    • typecheck and typecheck:dev are green. tests/unit/ci/ 1068 pass / 0 fail; tests/unit/http/ 1129 pass / 0 fail (the 9 skips are the file-symlink capability probe in StaticFiles.test.ts on Windows). lint:knip is clean, and check:ui reports the bundle current (source-hash a23bbfc88a178e9d), so UiAssets.ts is untouched.

    One acceptance criterion was not verified locally: the docs site build.

    • bun run build under docs/ hung in "Building static entrypoints" three times on the refreshed lockfile, and the same way on develop's own docs/bun.lock, so the refresh is not the cause.
    • Astro 7.3.5, Vite 8.1.5 and Rolldown 1.1.5 are unchanged since the last local build that passed (2026-09-28).
    • Probed through the inspector, the hung process's event loop held only Chromium's pipes and process handle: no timer, no file request, no socket.
    • Outside Astro, the refreshed node_modules work. Playwright launches and evaluates normally. mermaid-isomorphic, using the build's own font CSS and theme, renders 80 diagrams from 40 concurrent calls in 1.8 s. Its browser bundle carries its own DOMPurify, and neither mermaid nor KaTeX moved.
    • TypeDoc generation (markdown-it, minimatch > brace-expansion) and the content sync, the stages before the hang, completed in every attempt.

    The criterion therefore rests on docs-checks.yml's build + check:rendered job, which runs on the same push that closes this issue. If that job goes red, reopen this.

    The open Dependabot PRs now conflict with develop in exactly these lockfiles: #1662 in bun.lock, #1647 in docs/bun.lock and docs/package.json, #1643 in devtools-ui/bun.lock and devtools-ui/package.json. Their lockfiles predate the refresh: #1662 still pins proxy-addr 2.0.7 and fast-uri 3.1.6 / 4.1.3, #1647 pins devalue 5.8.1 and brace-expansion 5.0.6, and #1643 pins fast-uri 3.1.5. A resolution that takes their side wholesale would bring the advisories back, so run bun audit --audit-level=high (or bun audit fix) on the merged tree of each.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdependenciesPull requests that update a dependency fileinfrastructureCI / build / live-integration testspriority: highTop priority — high impact, plan nextsecuritySecurity-relevant — see severity label for impact tierseverity: mediumModerate impact or requires specific conditions

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions