Skip to content

frontend: scope snyk security dismissals - #2664

Merged
malinskibeniamin merged 1 commit into
masterfrom
ben-malinski/snyk/console-ui-security
Oct 6, 2026
Merged

malinskibeniamin merged 1 commit into
masterfrom
ben-malinski/snyk/console-ui-security

Conversation

@malinskibeniamin

Copy link
Copy Markdown
Contributor

What and why

Draft: temporary Snyk dismissals, not dependency patches. Console frontend/security maintainers get versioned, non-wildcard rules with advisory-specific reasons and a common 2027-01-03 18:00 UTC expiry.

  • 0 patched; 71 IDs dismissed across 171 dependency paths. Revisited the existing PostCSS rule, replaced its wildcard, and added 70 IDs. No package, lockfile, application, or workflow changes.
  • Raw Snyk still reports 71 IDs / 171 paths; Bun still reports 89 advisory records. Strict Snyk scanning fails on a Yarn alias; Socket results are inconclusive.
  • Security + UX Console review required before ready, especially Zod's unbounded form/storage arrays. This draft does not establish full security clearance.

Examples and verification

Lane: Keep the lights on. Benefit: reviewable, expiring triage instead of an unrestricted PostCSS ignore or speculative transitive overrides. No claim of reduced underlying vulnerabilities.

All scans below include development dependencies:

snyk test --file=yarn.lock --package-manager=yarn --dev \
  --strict-out-of-sync=false --json
# Before: exit 1, 70 IDs / 170 paths outstanding; 1 wildcard ignore.
# After: exit 0, 0 outstanding; 71 IDs / 171 paths in filtered.ignore.
# With --ignore-policy: exit 1, 71 IDs / 171 paths, unchanged.
  • Policy contract: failed before (1 != 171), passes after; 71 IDs, 171 audited versioned rules, no wildcard, valid expiry within 90 days, intact reasons, no patches.
  • Policy dogfood: PASS, real Snyk CLI entrypoint. Break attempts on untracked policy copies: changing one DOMPurify leaf version and one gRPC parent yields exactly those 2 findings; expiring one Zod path yields exactly 1 finding. Restoring the actual policy replays successfully. Scans took 10–16 seconds.
  • Matching caveat: Snyk can match a reported chain contained inside a longer rule. An initial Module Federation parent-mismatch probe stayed ignored through another overlapping audited chain. These are versioned path rules, not an exact-equality allowlist; new parent/feature usage still needs re-triage. Snyk matcher.
  • bun run type:check and bun run build: pass. Rstest: 1,065 unit + 1,605 integration + 1 federation = 2,671 passed, no failed/skipped tests.
  • bun run lint and bun run lint:check: exit 0 but report 2,554 existing errors. Not lint-clean; neither command changed tracked source.
  • bun audit --json: exit 1, 89 records / 21 package keys, unchanged (47 high, 32 moderate, 10 low).
  • Strict Snyk: 422, string-width-cjs@npm:string-width@^4.2.0 missing from the Yarn mirror. Bun mirror regeneration did not resolve it; only relaxed scans succeeded. Complete strict graph validation remains unproven.
  • Package manifest and both lockfiles remain byte-identical to base. Existing Bun release-age gate: 72 hours, four existing internal BSR exemptions; no age override, new dependency, or React migration.
  • snyk monitor / workflow dispatch: not requested, not run. No Snyk project created or cloud state updated. No issue publication.
  • No visible UI effect: only frontend/.snyk changes; screenshots/video are not applicable.

Reviewer focus and merge danger

Two-way door: revert this commit/remove the new rules to expose raw findings again. Blast radius: Snyk reporting for frontend/yarn.lock, not browser behavior. Bad reachability judgments can hide real risk until expiry. No owner risk acceptance is implied.

Riskiest assumptions:

  • Zod: unbounded arrays exist in forms and autosave localStorage recovery. No cross-user delivery of a huge invalid array was demonstrated, and the advisory lists no fix. This is explicitly an uncertain, time-bounded dismissal—not proof of bounded parsing. Security should confirm the data boundaries before accepting it.
  • DOMPurify: used at runtime by Registry SanitizedHtml and Monaco. Neither audited caller uses IN_PLACE plus the containing-element removal hook required by this advisory. Do not interpret the dismissal as “sanitization unused.”
  • Dockerode/gRPC: there IS a gRPC server on an injected Docker /session socket, not a client-only dependency. It uses insecure credentials, no public listener/mTLS authorization, and a fixed Credentials handler; a remotely controlled throwing handler was not found.
  • Module Federation: production and federation-test configs disable DTS; the installed Rstest plugin defaults DTS off. Re-enabling archive download/extraction changes the adm-zip/Undici assessment.
  • Rsdoctor: disableClientServer:true and brief JSON mode prevent the audited Engine.IO/ws/editor endpoints from starting. Tooling still executes in CI; “dev-only” alone is not the justification.

Resilience review: PASS for valid expiry, no wildcard, raw-scan visibility and rollback; full release clearance remains unproven. Inline review: policy write/readback, expiry, CLI negative cases, manifest admission, rollback, and no dependency-surface growth checked. No proven diff-introduced blocker for draft review. Merge readiness not proven: strict graph, Socket visibility, and Zod threat-model review remain open. Team review inferred from frontend ownership because this repo has no CODEOWNERS; requests target UX Console and Security. No cleaned-up label exists; cleanup is recorded above.

Reachability and dismissal ledger

Claim challenged: “Every finding needs a transitive bump.” Strongest dismissal case: the vulnerable operation requires a disabled feature, non-default option, or external input boundary not found in audited callers. Contrary evidence: direct DOMPurify/Zod runtime use, unbounded Zod arrays, actual Dockerode server, and build/test execution. Verdict: expiring dismissals under the requested skill's unproven-reachability default; not exploit-free or supply-chain-safe certification. No package.json admission, override, dependency removal, major hop, or changelog migration was needed.

Policy with full parent/version chains, vulnerable-symbol conditions, usage checks, reasons, and expiry. All additions were written through snyk ignore; the old wildcard was removed manually because CLI 1.1305.1 does not implement ignore --remove. IO issue links are unavailable: no cloud publication was requested.

Package Advisory / CVE Severity Paths
@grpc/grpc-js SNYK-JS-GRPCGRPCJS-20251007 · CVE-2026-101915 medium 1
@grpc/grpc-js SNYK-JS-GRPCGRPCJS-20251010 · CVE-2026-101916 critical 1
adm-zip SNYK-JS-ADMZIP-17954277 · CVE-2026-39244 high 2
adm-zip SNYK-JS-ADMZIP-19276676 · CVE-2026-76845 high 3
adm-zip SNYK-JS-ADMZIP-19846655 · CVE-2026-92000 high 3
adm-zip SNYK-JS-ADMZIP-19963965 · CVE-2026-77301 high 3
adm-zip SNYK-JS-ADMZIP-20335412 · No CVE listed high 3
adm-zip SNYK-JS-ADMZIP-20335417 · No CVE listed high 3
adm-zip SNYK-JS-ADMZIP-20335419 · CVE-2026-102282 high 3
adm-zip SNYK-JS-ADMZIP-20335421 · No CVE listed medium 3
brace-expansion SNYK-JS-BRACEEXPANSION-18512280 · CVE-2026-69152 high 3
brace-expansion SNYK-JS-BRACEEXPANSION-20244948 · CVE-2026-102278 high 3
brace-expansion SNYK-JS-BRACEEXPANSION-20244950 · CVE-2026-102277 medium 3
brace-expansion SNYK-JS-BRACEEXPANSION-20244952 · CVE-2026-102276 high 3
braces SNYK-JS-BRACES-19963945 · CVE-2026-93687 high 2
browserslist SNYK-JS-BROWSERSLIST-18854715 · CVE-2026-73088 high 4
browserslist SNYK-JS-BROWSERSLIST-18856271 · CVE-2026-73089 high 4
deepmerge SNYK-JS-DEEPMERGE-19964053 · CVE-2026-93753 high 4
dompurify SNYK-JS-DOMPURIFY-18593782 · CVE-2026-75838 medium 1
elliptic SNYK-JS-ELLIPTIC-14908844 · CVE-2025-14505 medium 2
engine.io SNYK-JS-ENGINEIO-17900543 · CVE-2026-59725 high 1
engine.io SNYK-JS-ENGINEIO-17900560 · CVE-2026-59724 high 1
engine.io SNYK-JS-ENGINEIO-20335255 · CVE-2026-102599 high 1
fast-uri SNYK-JS-FASTURI-18506908 · CVE-2026-18446 high 3
fast-uri SNYK-JS-FASTURI-19256867 · CVE-2026-75931 high 3
fast-uri SNYK-JS-FASTURI-19256869 · CVE-2026-76172 high 3
fast-uri SNYK-JS-FASTURI-19256871 · CVE-2026-75975 high 3
fast-uri SNYK-JS-FASTURI-19256873 · CVE-2026-75899 high 3
fast-uri SNYK-JS-FASTURI-19502739 · CVE-2026-84292 high 3
fast-uri SNYK-JS-FASTURI-19846649 · CVE-2026-86472 medium 3
immutable SNYK-JS-IMMUTABLE-17900558 · CVE-2026-59880 high 2
immutable SNYK-JS-IMMUTABLE-17900573 · CVE-2026-59879 high 2
js-yaml SNYK-JS-JSYAML-18593780 · No CVE listed high 1
js-yaml SNYK-JS-JSYAML-19496768 · CVE-2026-84375 high 1
nanoid SNYK-JS-NANOID-18506894 · CVE-2026-67214 high 1
nanoid SNYK-JS-NANOID-18506897 · CVE-2026-67213 high 1
pbkdf2 SNYK-JS-PBKDF2-20251013 · CVE-2026-102414 medium 2
postcss SNYK-JS-POSTCSS-18313038 · CVE-2026-73646 high 1
postcss SNYK-JS-POSTCSS-18512282 · CVE-2026-69153 medium 1
protobufjs SNYK-JS-PROTOBUFJS-17900550 · CVE-2026-59877 high 3
qs SNYK-JS-QS-19432017 · CVE-2026-82562 medium 1
qs SNYK-JS-QS-19432019 · CVE-2026-82417 medium 1
shell-quote SNYK-JS-SHELLQUOTE-20250993 · CVE-2026-102422 critical 1
smol-toml SNYK-JS-SMOLTOML-19643959 · CVE-2026-85730 high 1
svgo SNYK-JS-SVGO-19498536 · CVE-2026-84369 medium 1
svgo SNYK-JS-SVGO-19498539 · CVE-2026-84370 low 1
undici SNYK-JS-UNDICI-17372609 · CVE-2026-9697 medium 2
undici SNYK-JS-UNDICI-17372658 · CVE-2026-9679 critical 2
undici SNYK-JS-UNDICI-17372667 · CVE-2026-6734 high 2
undici SNYK-JS-UNDICI-17372697 · CVE-2026-9678 high 2
undici SNYK-JS-UNDICI-17372752 · CVE-2026-6733 medium 2
undici SNYK-JS-UNDICI-17372754 · CVE-2026-12151 high 2
undici SNYK-JS-UNDICI-17372758 · CVE-2026-11525 high 2
undici SNYK-JS-UNDICI-18426061 · CVE-2026-16729 medium 2
undici SNYK-JS-UNDICI-18426063 · CVE-2026-16728 medium 2
undici SNYK-JS-UNDICI-18426065 · CVE-2026-14643 high 2
undici SNYK-JS-UNDICI-18426067 · CVE-2026-15157 low 2
undici SNYK-JS-UNDICI-18426521 · CVE-2026-13697 high 2
undici SNYK-JS-UNDICI-19635206 · CVE-2026-18149 high 4
undici SNYK-JS-UNDICI-19635208 · CVE-2026-84890 high 4
undici SNYK-JS-UNDICI-19635210 · CVE-2026-19534 high 4
undici SNYK-JS-UNDICI-19635212 · CVE-2026-18540 medium 4
undici SNYK-JS-UNDICI-19635214 · CVE-2026-84947 medium 4
undici SNYK-JS-UNDICI-19635216 · CVE-2026-84933 high 4
undici SNYK-JS-UNDICI-19635218 · CVE-2026-84961 critical 4
undici SNYK-JS-UNDICI-19635220 · CVE-2026-85008 medium 4
undici SNYK-JS-UNDICI-19635222 · CVE-2026-85014 high 4
undici SNYK-JS-UNDICI-19635226 · CVE-2026-85024 high 2
ws SNYK-JS-WS-16722635 · CVE-2026-45736 medium 2
ws SNYK-JS-WS-17344547 · CVE-2026-48779 high 2
zod SNYK-JS-ZOD-20510278 · CVE-2023-54404 high 6

Additional Bun-only findings (not suppressible with Snyk IDs): @humanfs/node@0.16.7 GHSA-p498-v437-472g requires copy/copyAll symlink traversal; ESLint uses hfs for glob/directory operations, not those copy APIs. baseline-browser-mapping@2.10.33 GHSA-w5vr-8v7q-w6rv requires invalid caller-controlled targets causing process exit; audited use is repository build targets. Neither was patched, and raw Bun findings remain.

Socket.dev and supply-chain limits

Package overviews and installed-version alert pages were attempted using the web, not Socket CLI. Returned pages were incomplete/navigation-only or unavailable; deepmerge was inaccessible. Highest alerts and install/shell/env/filesystem/network capabilities are unknown, not “none.” No credible vector was established from those responses; equally, these checks do not rule one out. Security must complete this check before accepting the dismissals. No new versions were installed.

The same unknown-alert/vector/decision-impact status applies to every row:

Package Socket page Highest alert / attack vector Decision impact
@grpc/grpc-js Overview Unknown / inconclusive Draft-only; security review needed
@humanfs/node Overview Unknown / inconclusive Draft-only; security review needed
adm-zip Overview Unknown / inconclusive Draft-only; security review needed
baseline-browser-mapping Overview Unknown / inconclusive Draft-only; security review needed
brace-expansion Overview Unknown / inconclusive Draft-only; security review needed
braces Overview Unknown / inconclusive Draft-only; security review needed
browserslist Overview Unknown / inconclusive Draft-only; security review needed
deepmerge Overview Unknown / inconclusive Draft-only; security review needed
dompurify Overview Unknown / inconclusive Draft-only; security review needed
elliptic Overview Unknown / inconclusive Draft-only; security review needed
engine.io Overview Unknown / inconclusive Draft-only; security review needed
fast-uri Overview Unknown / inconclusive Draft-only; security review needed
immutable Overview Unknown / inconclusive Draft-only; security review needed
js-yaml Overview Unknown / inconclusive Draft-only; security review needed
nanoid Overview Unknown / inconclusive Draft-only; security review needed
pbkdf2 Overview Unknown / inconclusive Draft-only; security review needed
postcss Overview Unknown / inconclusive Draft-only; security review needed
protobufjs Overview Unknown / inconclusive Draft-only; security review needed
qs Overview Unknown / inconclusive Draft-only; security review needed
shell-quote Overview Unknown / inconclusive Draft-only; security review needed
smol-toml Overview Unknown / inconclusive Draft-only; security review needed
svgo Overview Unknown / inconclusive Draft-only; security review needed
undici Overview Unknown / inconclusive Draft-only; security review needed
ws Overview Unknown / inconclusive Draft-only; security review needed
zod Overview Unknown / inconclusive Draft-only; security review needed

Replace the broad PostCSS rule with versioned dependency paths and add
expiring, advisory-specific dismissals for unproven vulnerable surfaces.
Record 71 IDs across 171 paths, all expiring on 2027-01-03. No dependency
versions or application behavior change; raw audit findings remain.

Reasons retain direct DOMPurify usage, unbounded Zod arrays and the
Dockerode gRPC server instead of claiming these packages are unused.
Strict Yarn scanning and Socket clearance remain unproven. Publish as a
draft for security and UX Console review, not as patched dependencies.
@malinskibeniamin malinskibeniamin added frontend security Pull requests that address a security vulnerability team/ux dependencies snyk Snyk security sweep lang/ts TypeScript/JavaScript dismissals Snyk policy dismissals included labels Oct 5, 2026
@malinskibeniamin malinskibeniamin self-assigned this Oct 5, 2026
@malinskibeniamin
malinskibeniamin requested review from a team October 5, 2026 18:27
@malinskibeniamin
malinskibeniamin marked this pull request as ready for review October 6, 2026 03:18
@malinskibeniamin
malinskibeniamin merged commit be806e3 into master Oct 6, 2026
16 checks passed
@malinskibeniamin
malinskibeniamin deleted the ben-malinski/snyk/console-ui-security branch October 6, 2026 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies dismissals Snyk policy dismissals included frontend lang/ts TypeScript/JavaScript security Pull requests that address a security vulnerability snyk Snyk security sweep team/ux

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants