Skip to content

chore(security): bump @humanfs/node in datasheetsChat (closes #79) - #12

Open
benfrank241 wants to merge 1 commit into
mainfrom
chore/security-daily-20260904-rag-101-workshop-npm-datasheetschat
Open

benfrank241 wants to merge 1 commit into
mainfrom
chore/security-daily-20260904-rag-101-workshop-npm-datasheetschat

Conversation

@benfrank241

Copy link
Copy Markdown
Member

Daily security sweep — datasheetsChat (npm), 2026-09-04.

Alerts closed

alert advisory severity package scope fixed by
#79 GHSA-p498-v437-472g moderate @humanfs/node dev 0.16.6 → 0.16.8

No CVE is assigned to this advisory. Vulnerable range < 0.16.8.

Summary: @humanfs/node does not treat symlinks as a separate case during copy
operations. copyAll() passes every non-directory entry to fs.promises.copyFile(),
which dereferences symlinks — so a symlink inside a copied tree yields the contents of
its target rather than the link, letting a recursive copy read files from outside the
source tree. copy() is affected the same way when the source path is itself a symlink.

Fix method — in-range lockfile-only bump, no override

@humanfs/node is a transitive dev dependency, reached only through eslint, which
declares:

"@humanfs/node": "^0.16.6"

0.16.8 is already inside that range, so no overrides entry and no manifest change is
needed — the previous resolution was simply stale. Regenerated with:

npm update @humanfs/node --package-lock-only

No --force, no --legacy-peer-deps. package.json is untouched; the diff is
package-lock.json only, and every changed entry is "dev": true:

@humanfs/node                                  0.16.6 -> 0.16.8
@humanfs/core                                  0.19.1 -> 0.19.2   (^0.19.2 required by the above)
@humanfs/types                                 (new) 0.15.0       (new dep of the above)
@humanfs/node/node_modules/@humanwhocodes/retry  0.3.1 -> removed

That last line is a dedupe, not a downgrade: 0.16.8 widens its requirement from
@humanwhocodes/retry@^0.3.0 to ^0.4.0, which the already-hoisted 0.4.2 satisfies,
so the nested duplicate copy is no longer needed.

Verification

There is no test script in datasheetsChat/package.json (dev, build, start,
lint), so no test step exists to run.

main does not currently build or lint — both are pre-existing failures tracked in #10 —
so this was verified differentially against a clean origin/main worktree at the same
commit (612fed4):

check main (control) this branch
npm ci pass, no ERESOLVE pass, no ERESOLVE
next build — compile Compiled successfully Compiled successfully
next build — type-check fail fail (byte-identical log)
tsc --noEmit 8 errors 8 errors (byte-identical)
npm run lint not runnable not runnable

diff of both the full build logs and the two tsc --noEmit outputs is empty — this
change introduces no new errors. All 8 are the pre-existing errors catalogued in #10
item 2 (ai@^5 paired with v1-line @ai-sdk/* providers against v4-era call sites in
src/app/api/chat/route.ts).

npm run lint remains unusable on both sides: no ESLint config is committed, so
next lint drops into an interactive configuration prompt and never completes
non-interactively (#10 item 3).

ESLint toolchain smoke test

Because the bumped package is the filesystem layer ESLint itself uses to read configs and
source files, the toolchain was exercised directly. Each worktree's own
node_modules/.bin/eslint was run against an identical throwaway flat config and sample
file outside the repo:

control (@humanfs/node 0.16.6):  2 problems (2 errors, 0 warnings)
branch  (@humanfs/node 0.16.8):  2 problems (2 errors, 0 warnings)

Identical output — ESLint 9.39.4 loads and runs correctly on the bumped dependency.

npm audit

control this branch
moderate 1 0
low 8 8
total 9 8

@humanfs/node no longer appears in npm audit output.

Not included

Please review and merge at your discretion — this sweep does not merge its own PRs.

…es #79)

Resolves GHSA-p498-v437-472g (moderate): @humanfs/node copyAll()/copy()
dereference symlinks, allowing a recursive copy to pull in files from
outside the source tree.

Transitive dev dependency of eslint, which declares "@humanfs/node": "^0.16.6".
0.16.8 is inside that range, so this is an in-range lockfile-only bump via
`npm update @humanfs/node --package-lock-only` -- no manifest change and no
overrides entry required.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@benfrank241 benfrank241 added dependencies Pull requests that update a dependency file security labels Sep 4, 2026
@cdbartholomew cdbartholomew self-assigned this Sep 4, 2026
@cdbartholomew cdbartholomew added the p2 Medium severity - remediate within 60 days label Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file p2 Medium severity - remediate within 60 days security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants