Skip to content

fix: remediate remaining trivy-reported npm vulnerabilities (resolves #41) - #68

Open
kavix wants to merge 1 commit into
siddhi-io:masterfrom
kavix:fix/remediate-vulnerabilities-issue-41
Open

kavix wants to merge 1 commit into
siddhi-io:masterfrom
kavix:fix/remediate-vulnerabilities-issue-41

Conversation

@kavix

@kavix kavix commented Sep 11, 2026 •

Copy link
Copy Markdown

Purpose

Resolves #41

Remediates the remaining unaddressed npm dependency vulnerabilities reported by Trivy following PR #40.

Goals

  1. Resolve 2 HIGH CVEs in serialize-javascript (6.0.2 → ^7.0.3) by overriding transitive versions via Rush globalOverrides.
  2. Resolve 5 HIGH CVEs in undici (5.29.0 → ^6.24.0, resolving to 6.28.1) via Rush globalOverrides without breaking Node 20 runtime compatibility.
  3. Resolve 2 MEDIUM CVEs in webpack-dev-server (4.15.2 → ^5.2.1, resolving to 5.2.6) in @wso2/si-visualizer.
  4. Regenerate common/config/rush/pnpm-lock.yaml using rush update so that all transitive security overrides take effect in Trivy scans.
  5. Fix SVG XML encoding in HTTPEndpoint.svg (iso-8859-1 → utf-8) and Axios header type conversion in fileOperations.ts to ensure clean monorepo builds.

Approach

  • Transitive Overrides (common/config/rush/pnpm-config.json):
    Populated globalOverrides with:
    • "serialize-javascript": "^7.0.3": Fixes code injection CVEs in Webpack's terser-webpack-plugin.
    • "undici": "^6.24.0": Pinned to the LTS 6.x line (resolves to 6.28.1), fixing SSRF and request smuggling CVEs while avoiding Node 22+ webidl incompatibilities.
    • Re-enforced all PR fix: remediate trivy-reported npm dependency vulnerabilities #40 security overrides: sha.js, form-data, tar, node-forge, dompurify, minimatch, picomatch, brace-expansion, qs, path-to-regexp, js-yaml, yaml, ajv, prismjs, mdast-util-to-hast, on-headers, min-document, and tmp.
  • Direct Dev Server Bump (workspaces/si/si-visualizer/package.json):
    Bumped webpack-dev-server to ^5.2.1 (resolved to 5.2.6).
  • Lockfile Regeneration:
    Executed node common/scripts/install-run-rush.js update --full to bake all version resolutions into pnpm-lock.yaml.
  • Build Fixes:
    • HTTPEndpoint.svg: Changed declaration to encoding="utf-8" so svgicons2svgfont compiles without SAX stream encoding mismatch.
    • fileOperations.ts: Handled Axios AxiosHeaders typing for content-length with safe String() conversion before parseInt.

UI Component Development

  • N/A — No new UI components added. Existing ui-toolkit components unaffected.

Manage Icons

  • Corrected XML encoding on existing workspaces/common-libs/font-wso2-vscode/src/icons/HTTPEndpoint.svg from iso-8859-1 to utf-8 to allow font generation.

User stories

N/A

Release note

Remediated remaining Trivy-reported npm dependency vulnerabilities:

  • Upgraded serialize-javascript to 7.x
  • Upgraded undici to 6.28.1
  • Upgraded webpack-dev-server to 5.2.x
  • Regenerated Rush PNPM lockfile with all transitive overrides applied

Documentation

N/A — Security and internal build dependency remediation; no changes to user-facing functionality or extension APIs.

Training

N/A

Certification

N/A

Marketing

N/A

Automation tests

  • Unit & Monorepo Build:
    • node common/scripts/install-run-rush.js build passes across all 6 workspaces (@wso2/si-core, @wso2/font-wso2-vscode, @wso2/si-rpc-client, @wso2/ui-toolkit, @wso2/si-visualizer, streaming-integrator).
    • VSIX package generation verified via vsce package.

Security checks

Samples

N/A

Related PRs

Migrations (if applicable)

N/A

Test environment

  • Node.js: v20.11.0 (LTS)
  • OS: macOS (Darwin arm64) / Ubuntu Linux
  • Rush: 5.153.2
  • PNPM: 10.11.0

Learning

  • undici v8 requires Node.js 22+ built-in webidl.util.markAsUncloneable. For Node 20 environments, undici must be constrained to ^6.24.0 (resolves to 6.28.1) to avoid runtime TypeErrors while eliminating all 5 CVEs.
  • svgicons2svgfont uses sax-js which strictly checks the XML declaration against the detected stream encoding and rejects iso-8859-1 on UTF-8 streams.

@CLAassistant

CLAassistant commented Sep 11, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

- Add Rush globalOverrides for serialize-javascript (^7.0.3), undici (^6.24.0), and PR siddhi-io#40 transitive dependencies
- Upgrade webpack-dev-server to ^5.2.1 in si-visualizer
- Regenerate common/config/rush/pnpm-lock.yaml with minimal churn resolving all CVEs
- Fix XML declaration encoding in HTTPEndpoint.svg from iso-8859-1 to utf-8
- Fix AxiosHeaders type conversion for content-length in fileOperations.ts
- Verified monorepo build passes cleanly across all 6 workspaces
@kavix
kavix force-pushed the fix/remediate-vulnerabilities-issue-41 branch from c5c1e0f to 85f4108 Compare September 13, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: remediate remaining npm vulnerabilities

2 participants