Skip to content

[SPARK-59893][INFRA][TEST] Fix npm vulnerabilities in dev and ui-test - #59156

Closed
LuciferYang wants to merge 1 commit into
apache:masterfrom
LuciferYang:SPARK-59893
Closed

LuciferYang wants to merge 1 commit into
apache:masterfrom
LuciferYang:SPARK-59893

Conversation

@LuciferYang

Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?

This regenerates the two package-lock.json files with npm audit fix --package-lock-only, moving brace-expansion past the advisory range in both npm projects. Only the lockfiles change; no package.json and no direct dependency is touched.

Version moves:

  • dev: brace-expansion 1.1.18 -> 1.1.21, fast-uri 3.1.7 -> 3.1.8.
  • ui-test: brace-expansion 1.1.18 -> 1.1.21 (under test-exclude), 2.1.4 -> 2.1.7 (under @jest/reporters, jest-config, jest-runtime), and 5.0.9 -> 5.0.12 (top level).

Why are the changes needed?

brace-expansion GHSA-q2hr-2g5m-vwhr: quadratic-time expansion of the {a},b} rewrite causes a CPU denial of service. npm audit also flags two recursion advisories that the same patched releases close: GHSA-qhr7-859c-m2p7 (stack exhaustion on nested brace groups) and GHSA-6j4f-fj2g-mc7p (stack exhaustion in parseCommaParts). All resolve in range.

This addresses https://github.com/apache/spark/security/dependabot/246, https://github.com/apache/spark/security/dependabot/254, https://github.com/apache/spark/security/dependabot/255 and https://github.com/apache/spark/security/dependabot/256.

The dev run also carries fast-uri 3.1.7 -> 3.1.8, which clears GHSA-hrr3-gc8f-f4qj (inconsistent host case normalization via percent-encoded octets, moderate) so the audit comes back clean.

These are dev/test-only dependencies, but it is worth keeping the audit clean.

Does this PR introduce any user-facing change?

No.

How was this patch tested?

npm audit reports 0 vulnerabilities in both projects afterward, and npm ci reproduces both lockfiles unmodified. GitHub Actions does not run npm audit or npm ci.

Was this patch authored or co-authored using generative AI tooling?

Generated-by: Claude Opus 4.8

@LuciferYang

Copy link
Copy Markdown
Contributor Author

Merge Summary:

Posted by merge_spark_pr.py

@LuciferYang

Copy link
Copy Markdown
Contributor Author

Thank you @HyukjinKwon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants