fix(deps): patch HIGH/CRITICAL advisories (postcss CVE-2026-45623, CVE-2026-73646) #16

Open
admin wants to merge 1 commits from fix/cve-lockfile-2026-09-30 into main
Owner

Summary

Patches the only HIGH/CRITICAL advisories in the c0py dependency tree: two HIGH findings, both on postcss@8.4.31.

Advisory Package Before Fixed in After
CVE-2026-45623 (HIGH) postcss 8.4.31 8.5.12 8.5.28
CVE-2026-73646 (HIGH) postcss 8.4.31 8.5.18 8.5.28

brace-expansion, fast-uri and @xhmikosr/decompress are not present in this repo's lockfile; the scan reports nothing for them.

Why an override

postcss@8.4.31 comes only from next@15.5.25, and every next@15.5.x release (checked up to 15.5.26) pins postcss to exactly 8.4.31. A plain lockfile update therefore cannot reach the fix, and moving to a different next major is out of scope.

The change adds "postcss@<8.5.18": "8.5.28" to pnpm.overrides in the root package.json, next to the existing nanoid override. It stays within the same major (8.x), and 8.5.28 is already resolved for vite, so the tree ends up with one postcss version.

The lockfile diff is limited to three changes: the new overrides line, next now pointing at postcss@8.5.28, and the removal of the postcss@8.4.31 entries. No other package moved and no direct dependency was bumped.

Scan results

  • Before: trivy fs --scanners vuln --severity HIGH,CRITICAL reported 2 findings (both listed above); the result was the same with --include-dev-deps.
  • After: trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 1 . reports 0 vulnerabilities and exits 0. With --include-dev-deps it also reports 0. (Trivy DB was cached and current, updated 2026-09-30.)
  • pnpm audit --prod --audit-level high: no known vulnerabilities found.

Checks run (Node 22.23.2 via mise, pnpm 9.15.9)

  • pnpm install --frozen-lockfile: OK (lockfile consistent)
  • pnpm run validate:architecture: OK
  • pnpm run typecheck: OK (5 workspace projects)
  • pnpm run test: OK (config 1, web 1, c0py-core 11, api 34 tests, all passing)
  • pnpm run build: OK (next build on 15.5.25 and tsc for the api)

Not run: pnpm run lint (not part of the CI gates and not required for a lockfile change).

Notes

  • Note for reviewers: .gitea/workflows/ci.yml currently runs Trivy with --exit-code 0, so it does not block on findings; that is unchanged here.
  • No production deploy, no branch-protection or secret changes are involved.

🤖 Generated with Claude Code

## Summary Patches the only HIGH/CRITICAL advisories in the c0py dependency tree: two HIGH findings, both on `postcss@8.4.31`. | Advisory | Package | Before | Fixed in | After | |---|---|---|---|---| | CVE-2026-45623 (HIGH) | postcss | 8.4.31 | 8.5.12 | 8.5.28 | | CVE-2026-73646 (HIGH) | postcss | 8.4.31 | 8.5.18 | 8.5.28 | `brace-expansion`, `fast-uri` and `@xhmikosr/decompress` are not present in this repo's lockfile; the scan reports nothing for them. ## Why an override `postcss@8.4.31` comes only from `next@15.5.25`, and every `next@15.5.x` release (checked up to 15.5.26) pins `postcss` to exactly `8.4.31`. A plain lockfile update therefore cannot reach the fix, and moving to a different `next` major is out of scope. The change adds `"postcss@<8.5.18": "8.5.28"` to `pnpm.overrides` in the root `package.json`, next to the existing `nanoid` override. It stays within the same major (8.x), and 8.5.28 is already resolved for `vite`, so the tree ends up with one postcss version. The lockfile diff is limited to three changes: the new overrides line, `next` now pointing at `postcss@8.5.28`, and the removal of the `postcss@8.4.31` entries. No other package moved and no direct dependency was bumped. ## Scan results - Before: `trivy fs --scanners vuln --severity HIGH,CRITICAL` reported 2 findings (both listed above); the result was the same with `--include-dev-deps`. - After: `trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 1 .` reports 0 vulnerabilities and exits 0. With `--include-dev-deps` it also reports 0. (Trivy DB was cached and current, updated 2026-09-30.) - `pnpm audit --prod --audit-level high`: no known vulnerabilities found. ## Checks run (Node 22.23.2 via mise, pnpm 9.15.9) - `pnpm install --frozen-lockfile`: OK (lockfile consistent) - `pnpm run validate:architecture`: OK - `pnpm run typecheck`: OK (5 workspace projects) - `pnpm run test`: OK (config 1, web 1, c0py-core 11, api 34 tests, all passing) - `pnpm run build`: OK (`next build` on 15.5.25 and `tsc` for the api) Not run: `pnpm run lint` (not part of the CI gates and not required for a lockfile change). ## Notes - Note for reviewers: `.gitea/workflows/ci.yml` currently runs Trivy with `--exit-code 0`, so it does not block on findings; that is unchanged here. - No production deploy, no branch-protection or secret changes are involved. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
admin added 1 commit 2026-09-30 10:06:49 +00:00
fix(deps): patch HIGH advisories in postcss (CVE-2026-45623, CVE-2026-73646)
CI (SIAX Cloud) / sonar (push) Skipped
CI (SIAX Cloud) / sonar (pull_request) Skipped
CI (SIAX Cloud) / security (push) Successful in 23s
CI (SIAX Cloud) / security (pull_request) Successful in 16s
CI (SIAX Cloud) / contracts (pull_request) Successful in 21s
CI (SIAX Cloud) / contracts (push) Successful in 1m5s
CI (SIAX Cloud) / quality (push) Successful in 1m26s
CI (SIAX Cloud) / quality (pull_request) Successful in 1m22s
1258903289
next@15.5.x hard-pins postcss 8.4.31, so a plain lockfile update cannot
reach the fix. Add a pnpm override (postcss@<8.5.18 -> 8.5.28, same major,
already resolved for vite) so the whole tree uses one patched postcss.

Lockfile diff is limited to dropping postcss 8.4.31 and repointing next.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Author
Owner

OSV re-verification of this branch (head 1258903) against api.osv.dev, 2026-09-30.

Before (main 15cf3ee lockfile): CRITICAL 0, HIGH 2 (postcss@8.4.31: GHSA-6g55-p6wh-862q fixed 8.5.12, GHSA-r28c-9q8g-f849 fixed 8.5.18; pulled in by next@15.5.25, which hard-pins 8.4.31).

After (this branch): CRITICAL 0, HIGH 0 (322 lockfile pairs scanned). No further commits were needed; no other CRITICAL/HIGH advisories exist in pnpm-lock.yaml. Next.js is 15.5.25, so the next/og ImageResponse advisory for 16.3.4/16.3.5 does not apply.

Consistency checks run on the branch (node 22.23.2, pnpm 9.15.9, nice -n 10):

  • pnpm install --frozen-lockfile: OK
  • pnpm run validate:architecture: OK
  • pnpm run typecheck (5 workspace projects): OK
  • pnpm run test: 5 packages, 54 tests, all passed
  • pnpm run build (next build with postcss 8.5.28 + tsc for api): OK

Not run / not passing, unrelated to this change: pnpm run lint (root eslint .) exits with code 2 because the repo has no eslint.config.* file (ESLint 9 needs one); it is not part of CI and no config was added here since this lane only touches manifests and lockfiles. Trivy in CI was not run locally.

No guard/pin file changes, no workflow changes, nothing merged.

🤖 Generated with Claude Code

OSV re-verification of this branch (head 1258903) against api.osv.dev, 2026-09-30. **Before (main 15cf3ee lockfile):** CRITICAL 0, HIGH 2 (postcss@8.4.31: GHSA-6g55-p6wh-862q fixed 8.5.12, GHSA-r28c-9q8g-f849 fixed 8.5.18; pulled in by next@15.5.25, which hard-pins 8.4.31). **After (this branch):** CRITICAL 0, HIGH 0 (322 lockfile pairs scanned). No further commits were needed; no other CRITICAL/HIGH advisories exist in pnpm-lock.yaml. Next.js is 15.5.25, so the next/og ImageResponse advisory for 16.3.4/16.3.5 does not apply. Consistency checks run on the branch (node 22.23.2, pnpm 9.15.9, nice -n 10): - `pnpm install --frozen-lockfile`: OK - `pnpm run validate:architecture`: OK - `pnpm run typecheck` (5 workspace projects): OK - `pnpm run test`: 5 packages, 54 tests, all passed - `pnpm run build` (next build with postcss 8.5.28 + tsc for api): OK Not run / not passing, unrelated to this change: `pnpm run lint` (root `eslint .`) exits with code 2 because the repo has no eslint.config.* file (ESLint 9 needs one); it is not part of CI and no config was added here since this lane only touches manifests and lockfiles. Trivy in CI was not run locally. No guard/pin file changes, no workflow changes, nothing merged. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
All checks were successful
CI (SIAX Cloud) / sonar (push) Skipped
CI (SIAX Cloud) / sonar (pull_request) Skipped
CI (SIAX Cloud) / security (push) Successful in 23s
CI (SIAX Cloud) / security (pull_request) Successful in 16s
Required
Details
CI (SIAX Cloud) / contracts (pull_request) Successful in 21s
Required
Details
CI (SIAX Cloud) / contracts (push) Successful in 1m5s
CI (SIAX Cloud) / quality (push) Successful in 1m26s
CI (SIAX Cloud) / quality (pull_request) Successful in 1m22s
Required
Details
This pull request doesn't have enough required approvals yet. 0 of 1 official approvals granted.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin fix/cve-lockfile-2026-09-30:fix/cve-lockfile-2026-09-30
git checkout fix/cve-lockfile-2026-09-30
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: admin/c0py#16