Repository navigation
Override @xmldom/xmldom to 0.9.12 to clear ten open advisories - #169
Merged
Merged
Conversation
The preview toolchain pulls @xmldom/xmldom 0.9.10 through @djencks/asciidoctor-mathjax 0.0.9 -> mathjax-full 3.2.2 -> speech-rule-engine 4.1.4, which pins it exactly. The exact pin is why Dependabot cannot lift it on its own: nothing in the tree admits a newer version. 0.9.10 currently carries ten open advisories (seven high, three moderate) -- CVE-2026-83605, -83607, -83608, -83609, -83610, -83611, -83613, -83614, -83616, -83618 -- a mix of requireWellFormed validation bypasses and quadratic-time parsing paths. An npm overrides entry lifts it to 0.9.12, which all ten advisories name as patched. Verified by A/B: built the sample spec with 0.9.10 and with 0.9.12 (Antora 3.2, Node 22) and diffed the output trees -- every HTML, CSS, JS and image file is byte-identical, only sitemap.xml's lastmod differs. The MathJax SVG in chapter2.html, which is what speech-rule-engine feeds, is unchanged, so the exact pin was not load-bearing here. These are devDependencies of the local preview, not of the published specification -- the site is built by the central playbook with its own toolchain -- so this is hygiene rather than an exposure. Every repository seeded from this template inherits the same chain, which is why it belongs here rather than in each spec. README.adoc gains a Repository Setup Checklist step for Dependabot security updates. That switch is separate from the version updates dependabot.yml configures, and it is off by default: riscv-high-assurance-cryptography had eleven open alerts and automated-security-fixes disabled, so nothing had been opening PRs for any of them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Bill Traynor <wmat@riscv.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repository currently shows 10 open Dependabot alerts (8 high, 2 moderate), and every repository seeded from it inherits the same ones —
riscv-high-assurance-cryptographyhas 11. Ten of them are one package, reached by one chain.The chain
speech-rule-enginedepends on@xmldom/xmldom@0.9.10as an exact pin, not a range. That is why Dependabot cannot fix this on its own — nothing in the tree admits a newer version, so there is no bump for it to propose.The advisories are CVE-2026-83605, -83607, -83608, -83609, -83610, -83611, -83613, -83614, -83616 and -83618: a mix of
requireWellFormedvalidation bypasses (element, attribute, DocType and PI name injection) and quadratic-time parsing paths. All ten name 0.9.11 or 0.9.12 as the first patched version.The change
An npm
overridesentry lifting it to 0.9.12, plus the resulting one-entry lockfile change:Verification — A/B build
An exact pin sometimes is load-bearing, so I did not assume. I built the sample spec twice with Antora 3.2 on Node 22, once at 0.9.10 and once at 0.9.12, and diffed the output trees:
Every page is byte-identical; the only difference in the whole tree is
sitemap.xml'slastmodtimestamp. That includes the three MathJax SVGs inchapter2.html—speech-rule-engineis what consumes xmldom, so its rendered output is the thing that would have changed if the pin mattered. It did not.Scope — this is hygiene, not an exposure
These are devDependencies of the local
npm run previewtoolchain, whichpackage.jsonitself describes as existing only so local rendering matches production. The published site is built by the central playbook (riscv-admin/antora.riscv.org) with its own Antora, UI and extensions, so none of this reaches the deployed site or the PDF. Exploiting any of it means feeding hostile input to a local preview, where the input is the repository's own spec text.Worth fixing anyway, because the alerts are what a task group sees on its own repository, and 8 permanently-open "high" findings train people to ignore the list.
Also: the switch that should have caught these
README.adoc's Repository Setup Checklist gains a step for Dependabot security updates. That is a separate switch from the version updates.github/dependabot.ymlconfigures, and it is off by default:Eleven open alerts, nothing opening PRs for any of them. The new step gives the UI path, the
gh api -X PUT …/automated-security-fixesequivalent, and the command to check the current state — and notes that an alert in dev-only preview tooling is rarely urgent, so the point is that it gets seen rather than that it gets rushed.Note that it will not fix this one even once enabled, for the exact-pin reason above. It would have fixed
brace-expansion, which is the eleventh alert on the spec repository and is already patched in this repository's lockfile.🤖 Generated with Claude Code