Repository navigation
fix(deps): force simple-git ^4.0.2 to clear critical audit CVEs - #2617
rohit-sourcefuse wants to merge 2 commits into
Conversation
The audit workflow on master fails on critical simple-git advisories (GHSA-v5rq-49vh-5v5c, GHSA-x6jw-m9v5-85vh) plus two high command-execution ones. simple-git reaches the tree two ways: an unused direct dependency in packages/cli, and a transitive ^3.2.6 pulled by cz-format-extension (commit tooling). The patch only ships in simple-git 4.0.2 (semver-major), which the override now enforces repo-wide; @simple-git/argv-parser is pulled up to the patched 2.0.1 as a result. The unused packages/cli dependency is also removed. Node 22/24 already satisfies simple-git v4, and the package is only used by commit-time tooling, so the major bump carries no runtime risk. Claude-Session: https://claude.ai/code/session_019ZFAXKzNmtYSHfu7j4QhRH
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The claimed audit verification uses critical, but the workflow actually checks high, and the description states that high-severity findings remain.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates simple-git to remediate security advisories and removes its unused CLI dependency.
Changes:
- Forces
simple-git4.0.2 or newer through root overrides. - Removes the direct CLI dependency.
- Regenerates the lockfile with patched transitive packages.
| File | Description |
|---|---|
package.json |
Adds the security override. |
packages/cli/package.json |
Removes the unused dependency. |
package-lock.json |
Records the updated dependency tree. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| }, | ||
| "underscore": "^1.13.8" | ||
| "underscore": "^1.13.8", | ||
| "simple-git": "^4.0.2" |
There was a problem hiding this comment.
Good catch on the level — the gate runs at high, not critical; I've corrected the description. The important part holds though: the node_matrix_audit (22) and (24) jobs run that exact command with high and both pass on this PR, so the audit workflow is restored at the real gate level — simple-git resolves to a single 4.0.2 and @simple-git/argv-parser to the patched 2.0.1. The remaining trivy failure is pre-existing on master (basic-ftp CVE-2026-102990, unrelated to simple-git) and best handled in a separate PR.
- add basic-ftp ^6.2.1 to overrides in root, notifications-service (pubnub sandbox) and notification-service (telemed sandbox) package.json - regenerate the three package-lock.json files, basic-ftp 5.3.1 -> 6.2.2 - remediates HIGH CVE-2026-102990 flagged by trivy - lint, build and tests verified green in all three packages
|




What
Force
simple-gitto^4.0.2via a rootoverridesentry, and remove the unusedsimple-gitdirect dependency frompackages/cli.Why
The
auditworkflow onmasteris failing (exit 1).npm auditreports two criticalsimple-gitadvisories plus two high command-execution ones:@simple-git/argv-parserunsafe-editor detection omitsVISUAL< 2.0.1>=3.15.0 <4.0.1<=3.36.0<=3.36.0simple-gitreaches the tree two ways, so just one change doesn't clear it:packages/cli/package.json(^3.36.0) — grepped the wholepackages/clitree (src, lib, generators, templates); there are zero references to it, it's dead.^3.2.6pulled bycz-format-extension(commit-message tooling, dev-only).The fix for all four advisories only ships in
simple-git@4.0.2, which is a semver-major, so overrides/dedup to<4can't reach it. This PR therefore:"simple-git": "^4.0.2"to the rootoverridesblock (there was no existing entry) so every copy — direct and transitive — resolves to the patched major. As a result@simple-git/argv-parseris pulled up to the patched2.0.1.simple-gitdependency frompackages/cli(cleanup; no code uses it).Why the major bump is safe here
enginesacross the monorepo arenode: 22 || 24— well above simple-git v4's Node floor, so there's no runtime incompatibility.simple-gitis only reachable through commit-time tooling (cz-format-extension) now that the deadpackages/clidep is gone — nothing in shipped code calls it, so the v3→v4 API change has no runtime impact.Verification
The audit gate runs at
high(audit.ymlpasseshighas the trailing arg to the checker). Thenode_matrix_audit (22)and(24)jobs on this PR run that exact command and pass —simple-gitresolves to a single4.0.2and@simple-git/argv-parserto the patched2.0.1, so the simple-git criticals/highs are cleared and the audit workflow is green again.cc @yeshamavani @piyushsinghgaur1 @sf-sahil-jassal