rusackas opened a new pull request, #44741:
URL: https://github.com/apache/superset/pull/44741

   ### SUMMARY
   
   Resolves the open Dependabot alerts on `docs/yarn.lock` for `qs`, and 
documents why the third one (`@faker-js/faker`) can't be fixed with a version 
bump yet.
   
   **Resolved: `qs` 6.15.3 -> 6.16.0** (alert #1540 / 
[GHSA-4mjr-xmp4-gh2g](https://github.com/advisories/GHSA-4mjr-xmp4-gh2g), 
medium: DoS via attacker-controlled `isBuffer`; alert #1541 / 
[GHSA-x5fp-wj9c-mxmx](https://github.com/advisories/GHSA-x5fp-wj9c-mxmx), 
medium: array-limit bypass via bracket-key comma parsing).
   - Pulled transitively three ways: `express` and `body-parser` (`qs@~6.15.1`, 
via `@docusaurus/core -> webpack-dev-server -> express`), and `url@^0.11.4` 
(`qs@^6.12.3`, via `docusaurus-theme-openapi-docs`). None of the direct deps 
has a release that moves off the vulnerable range yet, so this adds a `"qs": 
"6.16.0"` entry to the existing `resolutions` block in `docs/package.json` 
(same pattern already used there for `lodash`, `uuid`, `serialize-javascript`, 
etc.) and refreshes the lockfile. 6.16.0 is a drop-in patch release: same two 
runtime deps (`side-channel`, `es-define-property`), and the single lock entry 
now satisfies all three ranges.
   
   **Not resolved (on purpose): `@faker-js/faker` 5.5.3** (alert #1539 / 
[GHSA-qxc2-j82w-r537](https://github.com/advisories/GHSA-qxc2-j82w-r537), high: 
`faker.helpers.fake()` template strings can reach arbitrary code execution; 
patched in 10.5.0).
   - Pulled only by `[email protected]` (already the newest release), 
which pins it *exactly* at `"@faker-js/faker": "5.5.3"` and hasn't moved 
despite 
[postmanlabs/postman-collection#1390](https://github.com/postmanlabs/postman-collection/issues/1390)
 being open since 2024.
   - A `resolutions` pin to 10.5.0+ is not viable: faker 10.x is ESM-only 
(`"type": "module"`, no `require` export condition), its `locale/en` entry 
exports a named `{ faker }` rather than the v5 default export, and the v5 API 
surface `postman-collection` calls (`faker.address.*`, 
`faker.random.arrayElement`, `faker.datatype.number`, 
`faker.phone.phoneNumberFormat`, `faker.company.companyName`) was renamed or 
removed in v8+. I verified this empirically by loading 
`[email protected]` against `@faker-js/[email protected]` on Node 24 (the 
version in `docs/.nvmrc`): it throws at module load, `TypeError: Cannot read 
properties of undefined (reading 'city')` at 
`lib/superstring/dynamic-variables.js:171`. `postman-collection` is required 
eagerly by `docusaurus-plugin-openapi-docs`, so the pin would break the docs 
build outright.
   - Practical exposure here is nil: the docs are a static site, faker is only 
reached through Postman's `{{$randomXxx}}` dynamic-variable generators, and 
nothing in the docs pipeline calls `faker.helpers.fake()` (the vulnerable path, 
which doesn't exist in the 5.x code at all). I'd suggest dismissing #1539 as 
"vulnerable code is not actually used" until `postman-collection` ships a 
release on a modern faker; no code change can close it cleanly today.
   
   No functional changes; only `docs/package.json` and `docs/yarn.lock` are 
touched.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   N/A (dependency-only change)
   
   ### TESTING INSTRUCTIONS
   
   ```bash
   cd docs
   yarn install --check-cache      # same command the docs CI uses; lockfile 
must be consistent
   yarn why qs                     # only [email protected], hoisted, satisfying 
~6.15.1 and ^6.12.3
   yarn why @faker-js/faker        # still 5.5.3 via postman-collection (see 
above)
   ```
   
   Local result after the lockfile refresh:
   
   ```
   $ yarn why qs
   info => Found "[email protected]"
   info Reasons this module exists
      - "docusaurus-theme-openapi-docs#url" depends on it
      - Hoisted from "docusaurus-theme-openapi-docs#url#qs"
      - Hoisted from "@docusaurus#core#webpack-dev-server#express#qs"
      - Hoisted from 
"@docusaurus#core#webpack-dev-server#express#body-parser#qs"
   
   $ yarn why @faker-js/faker
   info => Found "@faker-js/[email protected]"
   info Reasons this module exists
      - "docusaurus-plugin-openapi-docs#postman-collection" depends on it
   ```
   
   The `superset-docs-verify` workflow builds the site for any `docs/**` 
change, which is the real regression check for the consumers of `qs` here 
(`@docusaurus/core`'s webpack dev server via `express`/`body-parser`, and 
`docusaurus-theme-openapi-docs` via `url`).
   
   ### ADDITIONAL INFORMATION
   <!--- Check any relevant boxes with "x" -->
   <!--- HINT: Include "Fixes #nnn" if you are fixing an existing issue -->
   - [ ] Has associated issue:
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to