Repository navigation
frontend: scope snyk security dismissals - #2664
Merged
Merged
Conversation
Replace the broad PostCSS rule with versioned dependency paths and add expiring, advisory-specific dismissals for unproven vulnerable surfaces. Record 71 IDs across 171 paths, all expiring on 2027-01-03. No dependency versions or application behavior change; raw audit findings remain. Reasons retain direct DOMPurify usage, unbounded Zod arrays and the Dockerode gRPC server instead of claiming these packages are unused. Strict Yarn scanning and Socket clearance remain unproven. Publish as a draft for security and UX Console review, not as patched dependencies.
malinskibeniamin
marked this pull request as ready for review
October 6, 2026 03:18
malinskibeniamin
enabled auto-merge
October 6, 2026 03:18
Mateoc
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Draft: temporary Snyk dismissals, not dependency patches. Console frontend/security maintainers get versioned, non-wildcard rules with advisory-specific reasons and a common 2027-01-03 18:00 UTC expiry.
Examples and verification
Lane: Keep the lights on. Benefit: reviewable, expiring triage instead of an unrestricted PostCSS ignore or speculative transitive overrides. No claim of reduced underlying vulnerabilities.
All scans below include development dependencies:
1 != 171), passes after; 71 IDs, 171 audited versioned rules, no wildcard, valid expiry within 90 days, intact reasons, no patches.bun run type:checkandbun run build: pass. Rstest: 1,065 unit + 1,605 integration + 1 federation = 2,671 passed, no failed/skipped tests.bun run lintandbun run lint:check: exit 0 but report 2,554 existing errors. Not lint-clean; neither command changed tracked source.bun audit --json: exit 1, 89 records / 21 package keys, unchanged (47 high, 32 moderate, 10 low).string-width-cjs@npm:string-width@^4.2.0missing from the Yarn mirror. Bun mirror regeneration did not resolve it; only relaxed scans succeeded. Complete strict graph validation remains unproven.snyk monitor/ workflow dispatch: not requested, not run. No Snyk project created or cloud state updated. No issue publication.frontend/.snykchanges; screenshots/video are not applicable.Reviewer focus and merge danger
Two-way door: revert this commit/remove the new rules to expose raw findings again. Blast radius: Snyk reporting for
frontend/yarn.lock, not browser behavior. Bad reachability judgments can hide real risk until expiry. No owner risk acceptance is implied.Riskiest assumptions:
IN_PLACEplus the containing-element removal hook required by this advisory. Do not interpret the dismissal as “sanitization unused.”/sessionsocket, not a client-only dependency. It uses insecure credentials, no public listener/mTLS authorization, and a fixed Credentials handler; a remotely controlled throwing handler was not found.disableClientServer:trueand brief JSON mode prevent the audited Engine.IO/ws/editor endpoints from starting. Tooling still executes in CI; “dev-only” alone is not the justification.Resilience review: PASS for valid expiry, no wildcard, raw-scan visibility and rollback; full release clearance remains unproven. Inline review: policy write/readback, expiry, CLI negative cases, manifest admission, rollback, and no dependency-surface growth checked. No proven diff-introduced blocker for draft review. Merge readiness not proven: strict graph, Socket visibility, and Zod threat-model review remain open. Team review inferred from frontend ownership because this repo has no CODEOWNERS; requests target UX Console and Security. No
cleaned-uplabel exists; cleanup is recorded above.Reachability and dismissal ledger
Claim challenged: “Every finding needs a transitive bump.” Strongest dismissal case: the vulnerable operation requires a disabled feature, non-default option, or external input boundary not found in audited callers. Contrary evidence: direct DOMPurify/Zod runtime use, unbounded Zod arrays, actual Dockerode server, and build/test execution. Verdict: expiring dismissals under the requested skill's unproven-reachability default; not exploit-free or supply-chain-safe certification. No
package.jsonadmission, override, dependency removal, major hop, or changelog migration was needed.Policy with full parent/version chains, vulnerable-symbol conditions, usage checks, reasons, and expiry. All additions were written through
snyk ignore; the old wildcard was removed manually because CLI 1.1305.1 does not implementignore --remove. IO issue links are unavailable: no cloud publication was requested.@grpc/grpc-js@grpc/grpc-jsadm-zipadm-zipadm-zipadm-zipadm-zipadm-zipadm-zipadm-zipbrace-expansionbrace-expansionbrace-expansionbrace-expansionbracesbrowserslistbrowserslistdeepmergedompurifyellipticengine.ioengine.ioengine.iofast-urifast-urifast-urifast-urifast-urifast-urifast-uriimmutableimmutablejs-yamljs-yamlnanoidnanoidpbkdf2postcsspostcssprotobufjsqsqsshell-quotesmol-tomlsvgosvgoundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciundiciwswszodAdditional Bun-only findings (not suppressible with Snyk IDs):
@humanfs/node@0.16.7GHSA-p498-v437-472g requires copy/copyAll symlink traversal; ESLint uses hfs for glob/directory operations, not those copy APIs.baseline-browser-mapping@2.10.33GHSA-w5vr-8v7q-w6rv requires invalid caller-controlled targets causing process exit; audited use is repository build targets. Neither was patched, and raw Bun findings remain.Socket.dev and supply-chain limits
Package overviews and installed-version alert pages were attempted using the web, not Socket CLI. Returned pages were incomplete/navigation-only or unavailable; deepmerge was inaccessible. Highest alerts and install/shell/env/filesystem/network capabilities are unknown, not “none.” No credible vector was established from those responses; equally, these checks do not rule one out. Security must complete this check before accepting the dismissals. No new versions were installed.
The same unknown-alert/vector/decision-impact status applies to every row:
@grpc/grpc-js@humanfs/nodeadm-zipbaseline-browser-mappingbrace-expansionbracesbrowserslistdeepmergedompurifyellipticengine.iofast-uriimmutablejs-yamlnanoidpbkdf2postcssprotobufjsqsshell-quotesmol-tomlsvgoundiciwszod