Skip to content

fix(security): move @grpc/grpc-js past GHSA-m9gg-hp2v-232j - #1239

Closed
mrthankyou wants to merge 1 commit into
mainfrom
fix/grpc-js-advisory
Closed

mrthankyou wants to merge 1 commit into
mainfrom
fix/grpc-js-advisory

Conversation

@mrthankyou

@mrthankyou mrthankyou commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Since 2026-09-30 15:35 UTC, the dependency advisory gate fails on every PR (and will on the next main run):

dependency advisory policy: unapproved high production advisory GHSA-m9gg-hp2v-232j in @grpc/grpc-js

GHSA-m9gg-hp2v-232j (High): in certain configurations getAuthContext can return unauthorized certificates as though they were authorized. Affected: < 1.13.6 and >= 1.14.0 < 1.14.5. The advisory was published three minutes after the last green main run (c1bd7361).

On #1162, #1224 and #1225 this is the only failure: Build gates and Package, dependency, and policy gates fail at the advisory step, and release-gates fails only because it requires those two; the other 14 checks pass.

Where it comes from

@ultrafuzz/modal → [email protected] → [email protected] → @grpc/[email protected]

Change

  • pnpm update -r @grpc/grpc-js moves it from 1.14.4 to 1.14.5, within nice-grpc's existing range. The lockfile diff is only that bump.
  • CHANGELOG (Unreleased > Other changes).
  • No override or advisory exception was needed.

Verification

  • pnpm -w security:dependency-advisories: 0 High/Critical production advisories; 0 active exceptions (fails on main with the error above).
  • pnpm -w build passes; pnpm peers check output is unchanged from main.
  • @ultrafuzz/modal tests give identical results with and without the bump locally.

🤖 Generated with Claude Code

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no actionable issue was identified.

Summary

The PR updates the Modal SDK’s transitive @grpc/grpc-js lockfile resolution from 1.14.4 to 1.14.5 and records the advisory remediation in the changelog.

Reviews (1) · Last reviewed commit: "fix(security): move @grpc/grpc-js past G..."

The dependency advisory gate fails on main and every PR since the High
advisory GHSA-m9gg-hp2v-232j was published on 2026-09-30. @grpc/grpc-js
comes from the modal SDK through nice-grpc; pnpm update moves it from
1.14.4 to 1.14.5 within the existing range.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@mrthankyou
mrthankyou requested a review from a team as a code owner September 30, 2026 19:34
@mrthankyou

Copy link
Copy Markdown
Collaborator Author

Lockfile verification

Lockfiles are a common place to slip in a malicious package: a changed integrity hash or resolution is easy to miss in review. So here is exactly what this PR's lockfile change does, checked against the npm registry and the upstream source. Every check below can be re-run by any reviewer.

1. The diff is only the version bump

pnpm-lock.yaml at PR head 7ce1429b vs base e45076a4: +4 / −4, in three places, all @grpc/grpc-js 1.14.4 → 1.14.5

Location Change
packages: entry key 1.14.4 → 1.14.5, and its integrity hash
snapshots: entry key 1.14.4 → 1.14.5; its dependency list (@grpc/proto-loader 0.8.1, @js-sdsl/ordered-map 4.4.2) is unchanged
[email protected] snapshot dependency 1.14.4 → 1.14.5

No other package, resolution, tarball URL, or registry changes. No tarball: field is added, so the package resolves from the default registry. The repo configures no registry override.

2. The integrity hash matches the registry and the actual tarball

Source sha512
pnpm-lock.yaml at 7ce1429b 7VZM+SVdEcUUqSQeNI3zM8Qs/BhQKZndPo2h5VkYkAM8Iz0wJIa8mKV5ekQGqG8UUsnkQ0NMxIxwkIHYvj0qOw==
registry dist.integrity for 1.14.5 7VZM+SVdEcUUqSQeNI3zM8Qs/BhQKZndPo2h5VkYkAM8Iz0wJIa8mKV5ekQGqG8UUsnkQ0NMxIxwkIHYvj0qOw==
computed from downloaded grpc-js-1.14.5.tgz (444,937 bytes) 7VZM+SVdEcUUqSQeNI3zM8Qs/BhQKZndPo2h5VkYkAM8Iz0wJIa8mKV5ekQGqG8UUsnkQ0NMxIxwkIHYvj0qOw==

All three match. The removed 1.14.4 hash (k9Dj3DV/…) also matches the registry's value for 1.14.4.

3. The package itself

  • Publisher: murgatroid99, the same npm account that published 1.14.4 (grpc-js maintainer). Published 2026-09-17.
  • Built from upstream: gitHead is 56567d96 in grpc/grpc-node ("Merge pull request #3086 from murgatroid99/grpc-js_1.14.5"). The published src/ (68 entries) and package.json are identical to packages/grpc-js at that commit, ignoring line endings.
  • Dependencies and engines are unchanged from 1.14.4.
  • No install-time scripts. The only lifecycle script is prepare, the same one 1.14.4 has, and npm/pnpm do not run it when installing from the registry.
  • Compiled build/: same 504-file list as 1.14.4. A scan for child_process, eval(, new Function, fetch(, and http/https/net/dns requires shows the same counts as 1.14.4. There is one new process.env read, GRPC_NODE_DEBUG_SEND_ERROR_DETAILS (defaults to false), which also appears in the upstream source.

Things reviewers should know

  • The code change is larger than the lockfile change. Ignoring line endings, 1.14.5 changes 13 source files (+728 / −403), mainly the call and transport code (transport.ts, subchannel-call.ts, load-balancing-call.ts, retrying-call.ts, …), not just the certificate check in the advisory. All of it matches upstream.
  • A raw tarball diff looks alarming. 1.14.5 was published with CRLF line endings (1.14.4 used LF), so a plain diff of the tarballs shows ~21k changed lines. Use diff --strip-trailing-cr.
  • No npm provenance attestation. Neither 1.14.4 nor 1.14.5 has one, so nothing proves the published build/ JS was compiled from that source. I verified that src/ matches upstream and scanned build/ as above, but did not rebuild it and compare byte-for-byte.

Reproduce

# lockfile diff
gh pr diff 1239 | sed -n '/pnpm-lock.yaml/,$p'

# integrity: lockfile vs registry vs tarball
npm view @grpc/[email protected] dist.integrity
curl -sO https://registry.npmjs.org/@grpc/grpc-js/-/grpc-js-1.14.5.tgz
echo "sha512-$(openssl dgst -sha512 -binary grpc-js-1.14.5.tgz | base64)"

# published src vs upstream at gitHead
mkdir pub up && tar -xzf grpc-js-1.14.5.tgz -C pub
curl -sL https://codeload.github.com/grpc/grpc-node/tar.gz/56567d9604b4e45cdca0d2e3c2a60ac227ee659d | tar -xz -C up
diff -r --strip-trailing-cr up/*/packages/grpc-js/src pub/package/src && echo identical

@aviggiano

Copy link
Copy Markdown
Collaborator

Thanks, @mrthankyou. The same update landed in #1241, merged as 371c04d: @grpc/grpc-js 1.14.4 → 1.14.5, lockfile-only, plus a CHANGELOG entry. main already passes the advisory gate, so this PR can probably be closed unless it covers something #1241 doesn't.

@mrthankyou

Copy link
Copy Markdown
Collaborator Author

Closing as a duplicate of #1241 (merged as 371c04d), which makes the same lockfile-only @grpc/grpc-js 1.14.4 → 1.14.5 update plus a CHANGELOG entry. This PR changes the same two files and nothing beyond that bump. Thanks @aviggiano.

@mrthankyou mrthankyou closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants