fix(security): move @grpc/grpc-js past GHSA-m9gg-hp2v-232j - #1239
mrthankyou wants to merge 1 commit into
Conversation
The dependency advisory gate fails on main and every PR since the High advisory GHSA-m9gg-hp2v-232j was published on 2026-09-30. @grpc/grpc-js comes from the modal SDK through nice-grpc; pnpm update moves it from 1.14.4 to 1.14.5 within the existing range. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Lockfile verificationLockfiles are a common place to slip in a malicious package: a changed 1. The diff is only the version bump
No other package, resolution, tarball URL, or registry changes. No 2. The integrity hash matches the registry and the actual tarball
All three match. The removed 1.14.4 hash ( 3. The package itself
Things reviewers should know
Reproduce# lockfile diff
gh pr diff 1239 | sed -n '/pnpm-lock.yaml/,$p'
# integrity: lockfile vs registry vs tarball
npm view @grpc/[email protected] dist.integrity
curl -sO https://registry.npmjs.org/@grpc/grpc-js/-/grpc-js-1.14.5.tgz
echo "sha512-$(openssl dgst -sha512 -binary grpc-js-1.14.5.tgz | base64)"
# published src vs upstream at gitHead
mkdir pub up && tar -xzf grpc-js-1.14.5.tgz -C pub
curl -sL https://codeload.github.com/grpc/grpc-node/tar.gz/56567d9604b4e45cdca0d2e3c2a60ac227ee659d | tar -xz -C up
diff -r --strip-trailing-cr up/*/packages/grpc-js/src pub/package/src && echo identical |
|
Thanks, @mrthankyou. The same update landed in #1241, merged as 371c04d: |
|
Closing as a duplicate of #1241 (merged as 371c04d), which makes the same lockfile-only |
Problem
Since 2026-09-30 15:35 UTC, the dependency advisory gate fails on every PR (and will on the next
mainrun):GHSA-m9gg-hp2v-232j (High): in certain configurations
getAuthContextcan return unauthorized certificates as though they were authorized. Affected:< 1.13.6and>= 1.14.0 < 1.14.5. The advisory was published three minutes after the last greenmainrun (c1bd7361).On #1162, #1224 and #1225 this is the only failure: Build gates and Package, dependency, and policy gates fail at the advisory step, and release-gates fails only because it requires those two; the other 14 checks pass.
Where it comes from
@ultrafuzz/modal→[email protected]→[email protected]→@grpc/[email protected]Change
pnpm update -r @grpc/grpc-jsmoves it from 1.14.4 to 1.14.5, withinnice-grpc's existing range. The lockfile diff is only that bump.Verification
pnpm -w security:dependency-advisories:0 High/Critical production advisories; 0 active exceptions(fails onmainwith the error above).pnpm -w buildpasses;pnpm peers checkoutput is unchanged frommain.@ultrafuzz/modaltests give identical results with and without the bump locally.🤖 Generated with Claude Code
The PR appears safe to merge; no actionable issue was identified.
Summary
The PR updates the Modal SDK’s transitive
@grpc/grpc-jslockfile resolution from 1.14.4 to 1.14.5 and records the advisory remediation in the changelog.Reviews (1) · Last reviewed commit: "fix(security): move @grpc/grpc-js past G..."