Repository navigation
fix(site): override vulnerable serialize-javascript and uuid - #1536
Merged
Merged
Conversation
Docusaurus 3.10.2 (latest) still pulls in copy-webpack-plugin 11 and css-minimizer-webpack-plugin 5, which depend on serialize-javascript 6, and webpack-dev-server's sockjs, which depends on uuid 8. Override them to patched versions: - serialize-javascript ^7.0.5 (resolves 7.1.2): GHSA-5c6j-r48x-rmvq (high, RCE) and GHSA-qj8w-gfj5-8c6v (moderate, DoS). The latest majors of both webpack plugins already depend on ^7. - uuid ^11.1.1: GHSA-w5hq-g745-h8pq (moderate). sockjs only calls `require('uuid').v4()`, which uuid 11 still supports from CommonJS. These are build/dev-server dependencies of the docs site only; nothing here ships in purecss. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves the three open Dependabot alerts (#162, #198, #201). All three are in
site/package-lock.json.RegExp.flags/Date.prototype.toISOString()@docusaurus/bundler→copy-webpack-plugin@11,css-minimizer-webpack-plugin@5@docusaurus/core→webpack-dev-server→sockjs@0.3.24These are build-time and dev-server dependencies of the docs site only. Nothing here ships in the
purecsspackage or runs in visitors' browsers.Why overrides
There's no upstream release that fixes these:
sockjshasn't had a release since 0.3.24, which requiresuuid@^8.So this adds
overridestosite/package.json, the same approach the rootpackage.jsonuses for lodash:copy-webpack-plugin@14,css-minimizer-webpack-plugin@8) depend on^7themselves, so the 7.x API matches how they call it. It also drops therandombytesdependency.sockjsonly usesrequire('uuid').v4(), which uuid 11 still supports from CommonJS. uuid 12+ is ESM-only, so the range is capped at 11 via^.The lockfile diff only touches these two packages, plus
randombytesbeing dropped.Testing
npm audit --omit=devinsite/: 0 vulnerabilities.npm run pure && npm run build: succeeds. This runscopy-webpack-pluginandcss-minimizer-webpack-pluginwith serialize-javascript 7.1.2.sockjsserver and opened an xhr-polling session. It got auuidv4 session id from uuid 11.1.1.When Docusaurus moves to the newer plugin majors, these overrides can be removed.
🤖 Generated with Claude Code