Skip to content

Override @xmldom/xmldom to 0.9.12 to clear ten open advisories - #169

Merged
Bill Traynor (wmat) merged 1 commit into
mainfrom
fix/xmldom-advisories
Sep 30, 2026
Merged

Bill Traynor (wmat) merged 1 commit into
mainfrom
fix/xmldom-advisories

Conversation

@wmat

Copy link
Copy Markdown
Collaborator

This repository currently shows 10 open Dependabot alerts (8 high, 2 moderate), and every repository seeded from it inherits the same ones — riscv-high-assurance-cryptography has 11. Ten of them are one package, reached by one chain.

The chain

@djencks/asciidoctor-mathjax 0.0.9   (devDependency)
  └─ mathjax-full 3.2.2
      └─ speech-rule-engine 4.1.4
          └─ @xmldom/xmldom 0.9.10    ← 10 advisories

speech-rule-engine depends on @xmldom/xmldom@0.9.10 as an exact pin, not a range. That is why Dependabot cannot fix this on its own — nothing in the tree admits a newer version, so there is no bump for it to propose.

The advisories are CVE-2026-83605, -83607, -83608, -83609, -83610, -83611, -83613, -83614, -83616 and -83618: a mix of requireWellFormed validation bypasses (element, attribute, DocType and PI name injection) and quadratic-time parsing paths. All ten name 0.9.11 or 0.9.12 as the first patched version.

The change

An npm overrides entry lifting it to 0.9.12, plus the resulting one-entry lockfile change:

  "overrides": {
    "@xmldom/xmldom": "0.9.12"
  }

Verification — A/B build

An exact pin sometimes is load-bearing, so I did not assume. I built the sample spec twice with Antora 3.2 on Node 22, once at 0.9.10 and once at 0.9.12, and diffed the output trees:

$ diff -r build/site site-with-override --exclude=sitemap.xml
all HTML/CSS/JS/images IDENTICAL (only sitemap lastmod differs)

$ npm ls @xmldom/xmldom
└─┬ @djencks/asciidoctor-mathjax@0.0.9
  └─┬ mathjax-full@3.2.2
    └─┬ speech-rule-engine@4.1.4
      └── @xmldom/xmldom@0.9.12 overridden

Every page is byte-identical; the only difference in the whole tree is sitemap.xml's lastmod timestamp. That includes the three MathJax SVGs in chapter2.html — speech-rule-engine is what consumes xmldom, so its rendered output is the thing that would have changed if the pin mattered. It did not.

Scope — this is hygiene, not an exposure

These are devDependencies of the local npm run preview toolchain, which package.json itself describes as existing only so local rendering matches production. The published site is built by the central playbook (riscv-admin/antora.riscv.org) with its own Antora, UI and extensions, so none of this reaches the deployed site or the PDF. Exploiting any of it means feeding hostile input to a local preview, where the input is the repository's own spec text.

Worth fixing anyway, because the alerts are what a task group sees on its own repository, and 8 permanently-open "high" findings train people to ignore the list.

Also: the switch that should have caught these

README.adoc's Repository Setup Checklist gains a step for Dependabot security updates. That is a separate switch from the version updates .github/dependabot.yml configures, and it is off by default:

$ gh api repos/riscv/riscv-high-assurance-cryptography/automated-security-fixes
{"enabled":false,"paused":false}

Eleven open alerts, nothing opening PRs for any of them. The new step gives the UI path, the gh api -X PUT …/automated-security-fixes equivalent, and the command to check the current state — and notes that an alert in dev-only preview tooling is rarely urgent, so the point is that it gets seen rather than that it gets rushed.

Note that it will not fix this one even once enabled, for the exact-pin reason above. It would have fixed brace-expansion, which is the eleventh alert on the spec repository and is already patched in this repository's lockfile.

🤖 Generated with Claude Code

The preview toolchain pulls @xmldom/xmldom 0.9.10 through @djencks/asciidoctor-mathjax 0.0.9 -> mathjax-full 3.2.2 -> speech-rule-engine 4.1.4, which pins it exactly. The exact pin is why Dependabot cannot lift it on its own: nothing in the tree admits a newer version. 0.9.10 currently carries ten open advisories (seven high, three moderate) -- CVE-2026-83605, -83607, -83608, -83609, -83610, -83611, -83613, -83614, -83616, -83618 -- a mix of requireWellFormed validation bypasses and quadratic-time parsing paths.

An npm overrides entry lifts it to 0.9.12, which all ten advisories name as patched. Verified by A/B: built the sample spec with 0.9.10 and with 0.9.12 (Antora 3.2, Node 22) and diffed the output trees -- every HTML, CSS, JS and image file is byte-identical, only sitemap.xml's lastmod differs. The MathJax SVG in chapter2.html, which is what speech-rule-engine feeds, is unchanged, so the exact pin was not load-bearing here.

These are devDependencies of the local preview, not of the published specification -- the site is built by the central playbook with its own toolchain -- so this is hygiene rather than an exposure. Every repository seeded from this template inherits the same chain, which is why it belongs here rather than in each spec.

README.adoc gains a Repository Setup Checklist step for Dependabot security updates. That switch is separate from the version updates dependabot.yml configures, and it is off by default: riscv-high-assurance-cryptography had eleven open alerts and automated-security-fixes disabled, so nothing had been opening PRs for any of them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Bill Traynor <wmat@riscv.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant