Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 37 additions & 15 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ npm run lint
npm run typecheck
npm test
npm audit --omit=dev
npm audit --audit-level=high
npm run check-package
git diff --check
```
Expand Down Expand Up @@ -51,13 +52,13 @@ alone does not establish npm publishing authority. Do not bypass lifecycle check
or repository approval rules. Verify npm provenance, tarball integrity and a fresh
registry install after publishing. Rehearsal does not prove OIDC permission.

The current dependency queue is #23, #20, #21, then #22. Refresh and test each PR
after the preceding merge. #22 subsumes the vulnerable brace-expansion path;
verify the final lockfile rather than assuming an overlapping PR is unnecessary.
Use `npm audit --json` to inspect the full tooling tree as well as the production
audit in validate. CI retains that report. Require a full-tree high/critical audit
gate once the existing queue clears; do not hide advisories or force unsupported
major overrides to produce a green audit.
The security updates in #23, #20, #21 and #22 remove the existing high-severity
findings. `npm run validate` checks production dependencies and rejects high or
critical findings anywhere in the installed tree, including development tooling.
CI and the release wrapper both run this command. Moderate tooling findings stay
visible in the audit output and the full JSON report retained by CI; passing the
severity gate does not accept their risk. Do not hide advisories or force
unsupported major overrides to produce a green audit.

### Unresolved development dependency findings

Expand All @@ -69,11 +70,32 @@ packages still pin the affected qs and stream-json versions. This repository's
package validator prohibits overrides, including scoped overrides. A tested qs
6.16.0 override therefore cannot be shipped under the current package contract.

The stream-json consumer imports its parser and `stream-json/Assembler` through
CommonJS; forcing version 3 would change the module/export contract. The uuid
consumers include LangChain v1/v4 usage in both CommonJS and ESM. These packages
are development dependencies, not libraries shipped in this node's tarball;
the separately installed n8n host has its own dependency tree. This distinction
is not risk acceptance. The release owner must disposition these findings or
wait for compatible upstream repairs before publishing. Reevaluate when the
n8n tooling updates its pinned dependencies; retain audit evidence in the PR.
Source inspection and bounded local checks found:

- `stream-json`: backend-common uses its parser and CommonJS
`stream-json/Assembler`, not the filter APIs implicated by the advisory. A
circular-data roundtrip through the actual consumer passed. Forcing version 3
would change the module/export contract.
- `uuid`: the inspected LangChain callers use v1/v4 without external buffers.
Those calls returned valid IDs. Installed uuid 10 silently accepts undersized
external buffers in both v4 and v5, so other call signatures are not cleared.
- `qs`: backend-network calls stringify for query and form serialization.
Ordinary serialization passed, but a crafted JSON object with a non-callable
`constructor.isBuffer` reproduced the error through its actual query
serializer. That trigger does not require a preceding qs.parse call. The
separate array-limit parse advisory also reproduced in a small fixture.

The CLI's executable source does not directly import its AI SDK dependency;
scaffolding templates reference it. A CommonJS module-load trace during build,
validation and release rehearsal did not load the vulnerable uuid 10, qs or
stream-json copies. This is evidence for those commands, not proof about ESM
loads, interactive development, scaffolding, or every possible input.

These packages are development dependencies, not libraries shipped in this
node's tarball; the separately installed n8n host has its own dependency tree.
No release owner has accepted the remaining risk. The npm release owner must
record a disposition of these findings or wait for compatible upstream repairs
before publishing. Reevaluate when n8n tooling updates its pinned dependencies,
when these packages become reachable through a changed command or consumer, or
when advisory severity changes. Retain current audit and consumer evidence in
the maintenance PR.
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@
"release": "node scripts/release.mjs",
"prepublishOnly": "n8n-node prerelease && npm run check-package",
"format:check": "prettier --check .",
"validate": "npm run format:check && npm run lint && npm run typecheck && npm test && npm audit --omit=dev && npm run check-package",
"validate": "npm run format:check && npm run lint && npm run typecheck && npm test && npm audit --omit=dev && npm audit --audit-level=high && npm run check-package",
"release:rehearse": "node scripts/release.mjs --dry-run"
},
"files": [
Expand Down
Loading