Skip to content

fix(deps): force simple-git ^4.0.2 to clear critical audit CVEs - #2617

Open
rohit-sourcefuse wants to merge 2 commits into
masterfrom
fix/cli-remove-unused-simple-git
Open

rohit-sourcefuse wants to merge 2 commits into
masterfrom
fix/cli-remove-unused-simple-git

Conversation

@rohit-sourcefuse

@rohit-sourcefuse rohit-sourcefuse commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What

Force simple-git to ^4.0.2 via a root overrides entry, and remove the unused simple-git direct dependency from packages/cli.

Why

The audit workflow on master is failing (exit 1). npm audit reports two critical simple-git advisories plus two high command-execution ones:

Advisory Severity Affected range
GHSA-v5rq-49vh-5v5c — @simple-git/argv-parser unsafe-editor detection omits VISUAL critical < 2.0.1
GHSA-x6jw-m9v5-85vh — unsafe-operation guard doesn't block trailer-command config critical >=3.15.0 <4.0.1
GHSA-g4wm-2vf7-vfgr — command execution via unblocked git config includes high (8.1) <=3.36.0
GHSA-858h-whjf-mvg5 — unsafe-operations bypass via git long-option abbreviation high (8.1) <=3.36.0

simple-git reaches the tree two ways, so just one change doesn't clear it:

  1. An unused direct dependency in packages/cli/package.json (^3.36.0) — grepped the whole packages/cli tree (src, lib, generators, templates); there are zero references to it, it's dead.
  2. A transitive ^3.2.6 pulled by cz-format-extension (commit-message tooling, dev-only).

The fix for all four advisories only ships in simple-git@4.0.2, which is a semver-major, so overrides/dedup to <4 can't reach it. This PR therefore:

  • Adds "simple-git": "^4.0.2" to the root overrides block (there was no existing entry) so every copy — direct and transitive — resolves to the patched major. As a result @simple-git/argv-parser is pulled up to the patched 2.0.1.
  • Removes the dead simple-git dependency from packages/cli (cleanup; no code uses it).

Why the major bump is safe here

  • engines across the monorepo are node: 22 || 24 — well above simple-git v4's Node floor, so there's no runtime incompatibility.
  • simple-git is only reachable through commit-time tooling (cz-format-extension) now that the dead packages/cli dep is gone — nothing in shipped code calls it, so the v3→v4 API change has no runtime impact.

Verification

The audit gate runs at high (audit.yml passes high as the trailing arg to the checker). The node_matrix_audit (22) and (24) jobs on this PR run that exact command and pass — simple-git resolves to a single 4.0.2 and @simple-git/argv-parser to the patched 2.0.1, so the simple-git criticals/highs are cleared and the audit workflow is green again.

Note: trivy is red, but that's pre-existing on master (red since Aug 2025) and unrelated to this change — it's flagging basic-ftp CVE-2026-102990 (a separate transitive dep). Worth a follow-up PR (basic-ftp ^6.2.1), out of scope here.

cc @yeshamavani @piyushsinghgaur1 @sf-sahil-jassal

The audit workflow on master fails on critical simple-git advisories
(GHSA-v5rq-49vh-5v5c, GHSA-x6jw-m9v5-85vh) plus two high command-execution
ones. simple-git reaches the tree two ways: an unused direct dependency in
packages/cli, and a transitive ^3.2.6 pulled by cz-format-extension (commit
tooling). The patch only ships in simple-git 4.0.2 (semver-major), which the
override now enforces repo-wide; @simple-git/argv-parser is pulled up to the
patched 2.0.1 as a result. The unused packages/cli dependency is also removed.

Node 22/24 already satisfies simple-git v4, and the package is only used by
commit-time tooling, so the major bump carries no runtime risk.

Claude-Session: https://claude.ai/code/session_019ZFAXKzNmtYSHfu7j4QhRH
@rohit-sourcefuse
rohit-sourcefuse requested a review from a team as a code owner October 6, 2026 10:16
Copilot AI balanced review requested due to automatic review settings October 6, 2026 10:16

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The claimed audit verification uses critical, but the workflow actually checks high, and the description states that high-severity findings remain.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates simple-git to remediate security advisories and removes its unused CLI dependency.

Changes:

  • Forces simple-git 4.0.2 or newer through root overrides.
  • Removes the direct CLI dependency.
  • Regenerates the lockfile with patched transitive packages.
File Description
package.json Adds the security override.
packages/​cli/​package.json Removes the unused dependency.
package-lock.json Records the updated dependency tree.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
},
"underscore": "^1.13.8"
"underscore": "^1.13.8",
"simple-git": "^4.0.2"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch on the level — the gate runs at high, not critical; I've corrected the description. The important part holds though: the node_matrix_audit (22) and (24) jobs run that exact command with high and both pass on this PR, so the audit workflow is restored at the real gate level — simple-git resolves to a single 4.0.2 and @simple-git/argv-parser to the patched 2.0.1. The remaining trivy failure is pre-existing on master (basic-ftp CVE-2026-102990, unrelated to simple-git) and best handled in a separate PR.

- add basic-ftp ^6.2.1 to overrides in root, notifications-service (pubnub sandbox)
  and notification-service (telemed sandbox) package.json
- regenerate the three package-lock.json files, basic-ftp 5.3.1 -> 6.2.2
- remediates HIGH CVE-2026-102990 flagged by trivy
- lint, build and tests verified green in all three packages
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants