Skip to content

fix(security): establish canonical npm, PDF.js, and Undici baseline - #783

Draft
seonghobae wants to merge 37 commits into
developfrom
fix/high-security-dependency-baseline
Draft

fix(security): establish canonical npm, PDF.js, and Undici baseline#783
seonghobae wants to merge 37 commits into
developfrom
fix/high-security-dependency-baseline

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator

Problem

Protected develop carries two high-severity JavaScript dependency findings and does not make the lockfile generator an enforceable repository contract:

  • pdfjs-dist@6.1.200, affected by arbitrary JavaScript execution on malicious PDFs and fixed in 6.2.108;
  • undici@7.28.0, affected by cache-control disclosure/crash, header injection, retry desynchronization, and cookie-attribute injection findings fixed in 7.29.0; and
  • dependency updates produced by inconsistent npm serialization paths, including unrelated removal of peer: true from @esbuild/* locations.

Atomic baseline

This PR now targets protected develop directly and combines the npm-generator provenance slice from #782 with the coordinated PDF.js/Undici remediation. It is the intended atomic supply-chain baseline rather than a child stacked on #782.

The implementation:

  • declares and enforces npm@10.9.8 as the package-lock generator;
  • verifies Node 22.22.3 and npm 10.9.8 before install;
  • regenerates package-lock.json with scripts, audit, and funding disabled and rejects any replay diff;
  • pins pdfjs-dist exactly to 6.2.108;
  • pins Undici exactly to 7.29.0 through the root override;
  • imports the complete npm-generated lock artifact byte-for-byte and preserves unrelated @esbuild/* peer metadata;
  • constrains the PDF loader to copied in-memory bytes and a same-origin bundled worker;
  • uses only members supported by PDF.js 6.2.108 DocumentInitParameters rather than passing the removed legacy isEvalSupported option;
  • adds manifest, registry/SRI, lock-provenance, loader-boundary, and npm-toolchain regression contracts; and
  • updates CHANGELOG and APA 7 doctoring with impact, provenance, rollback, and claim boundaries.

Verified lock evidence

The exact npm 10.9.8 reproduction artifact from workflow run 31161313485 was imported unchanged:

  • artifact ID: 8989562185;
  • artifact SHA-256: 31dd2661eca864e3da46f86629a2535dc181d01449bd3a50fa3cdbd6c58e7971;
  • npm replay: byte-clean;
  • npm audit --workspaces --audit-level=high: zero vulnerabilities;
  • desktop strict typecheck and lint: successful;
  • focused PDF.js boundary tests: 2 passed; and
  • the one-shot importer removed itself from the final tree.

Exact-head gate

Current exact head: e6b48ca58e5c481e4b0bef8961338b5a3967e6c6.
Current protected base: acdbea6344fe1231c39535b575f4de35e4c607c9.

Keep Draft until the exact-current-head desktop, Rust/Tauri, package, release, security, SAST, SBOM, central coverage, CodeRabbit, OpenCode, and Noema gates complete; every actionable thread is resolved; a qualifying independent non-author approval is anchored to this exact head; and branch protection permits merge without administrative bypass. Queued, skipped-required, action-required, author-only, prior-head, or wrapper-only evidence is not success.

After this PR merges, close #782, #751, and #765 as superseded. No predecessor review or check is reused.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 6 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8236a624-cdf3-4504-8fb4-2c031f483a54

📥 Commits

Reviewing files that changed from the base of the PR and between acdbea6 and 459abdd.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (10)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • apps/desktop/package.json
  • apps/desktop/src/features/score/pdfjs.test.ts
  • apps/desktop/src/features/score/pdfjs.ts
  • docs/doctoring/high-security-pdf-http-baseline.md
  • docs/doctoring/npm-lockfile-generator-provenance.md
  • package.json
  • services/analysis-engine/tests/test_high_security_dependency_baseline.py
  • services/analysis-engine/tests/test_npm_toolchain_contract.py

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae changed the base branch from fix/npm-lock-toolchain-provenance to develop August 7, 2026 08:11
Comment thread .github/workflows/ci.yml

Copy link
Copy Markdown
Collaborator Author

@opencode-agent address

Finalize the generated security lock on exact current head e2c0c2dfee35c19d1e9156ad0a7d9324fdefd1fb; stop without writing if the live head differs.

CI run 31161313485, job 92812058810, successfully generated and uploaded artifact npm-lock-reproduction-e2c0c2dfee35c19d1e9156ad0a7d9324fdefd1fb (artifact ID 8987188177, archive digest sha256:703f8effec0b517a6c56bf40922e43ac3a35418e052adde912685d6074842cf0) before intentionally failing on lock drift. Download that exact artifact through the GitHub Actions API, verify the archive digest, extract exactly one regular package-lock.json, and verify the extracted lock SHA-256 is 31dd2661eca864e3da46f86629a2535dc181d01449bd3a50fa3cdbd6c58e7971.

Before committing, fail closed unless the generated lock proves all of the following:

  • lockfileVersion 3 and one root npm workspace lock only;
  • root devDependencies.undici is exactly 7.29.0;
  • node_modules/undici is exactly 7.29.0 with public npm registry tarball and SHA-512 SRI sha512-IDxfleLmmbSskfWSUATiN1nfn2rDuvnMOqb5CWR92iIfojA0Ud+ulOAAEQ57LPr9rWmsreUyf5lwyao+7GNNVw==;
  • desktop dependency pdfjs-dist is exactly 6.2.108 and the npm-generated location apps/desktop/node_modules/pdfjs-dist has public registry tarball plus SHA-512 SRI sha512-YxFb+SQcodN2rnX9Tn3dHYlqfb7NjlzzfONPpJd+AKoKtUjEdevTfbC07d5TcczzOK6261auRkP/M8OBHs9vFQ==;
  • every existing node_modules/@esbuild/* location retains peer: true; and
  • no manifest, source, workflow, test, or documentation file is modified by this lock-import commit.

Replace the branch lock byte-for-byte with the verified artifact and commit normally. Do not regenerate it locally, hand-edit it, create another branch/PR/workflow/helper, or include the ZIP. The next exact-head CI must reproduce a zero diff before any build/security success is accepted.

Copy link
Copy Markdown
Collaborator Author

/oc Refetch the live pull request and abort without writing unless it is still PR #783 on branch fix/high-security-dependency-baseline, its current head is dd93f962d367e3a5b56ee171708bf4877a054541, and its base branch is fix/npm-lock-toolchain-provenance. The prerequisite base moved to exact head f7adc803b6db795eb78aa154ff033d12688b88fb after a lint-only contract repair. Merge that latest base into this existing branch with a normal merge commit; do not rebase or force-push. Then regenerate the complete root lock on the new exact head using only Node 22.22.3 and npm 10.9.8 with npm install --package-lock-only --ignore-scripts --no-audit --no-fund, and commit the exact generated package-lock.json unchanged. Prior exact-head run 31168248160, job 92833945077, is authoritative RED evidence: lock reproduction failed after uploading artifact ID 8989872876, name npm-lock-reproduction-dd93f962d367e3a5b56ee171708bf4877a054541, digest 07dad922109f956a9339e2edc55da390922c1c4d0af868ee7eb52fe2163716e9; its diff proves the checked-in lock omitted the exact root Undici 7.29.0 record and still represented PDF.js 6.1.200 instead of the manifest-required 6.2.108 location. Treat that artifact only as diagnostic evidence because the base has since moved; regenerate and prove byte-stable output twice on the new exact head. Preserve every unrelated @esbuild/* peer: true location flag and reject all unrelated lock churn. Keep exact pdfjs-dist@6.2.108, exact undici@7.29.0, verified registry/SRI records, local PDF worker use, copied in-memory bytes, and isEvalSupported: false. Run focused dependency and PDF boundary tests first, then lock reproduction twice, npm audit --workspaces --audit-level=high, desktop lint/typecheck/measured tests/build, Python/Ruff/docstrings/coverage, Rust numeric/Tauri gates, package/release, SBOM, Security Scan, SAST, and git diff --check. Do not create another branch, PR, one-shot/self-modifying workflow, patch artifact, or encoded patch. Keep Draft until the new exact head is fully green, current-head review threads are zero, and a qualifying independent non-author approval exists.

@seonghobae seonghobae changed the title fix(security): coordinate PDF.js and Undici high-severity remediation fix(security): establish canonical npm, PDF.js, and Undici baseline Aug 7, 2026

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants