Pin transitive picomatch to patched versions via npm overrides - #4
Merged
Conversation
Dependabot's own fix for these two picomatch advisories (ReDoS via extglob quantifiers, ID/method injection in POSIX character classes) bumped tailwindcss from 3.4.19 to 4.3.3 as a side effect, since v4 drops picomatch as a dependency entirely. That's a major, breaking version - v4 uses a completely different config/CSS-import format (no more tailwind.config.js + @tailwind directives) and the CLI moved to a separate package, so `npx tailwindcss` no longer resolves at all post-bump. Migrating to v4 is a real project on its own, not something to pull in silently via a security-patch PR. Fixed the actual vulnerability without the major bump instead: two different picomatch versions (2.3.1 via chokidar/micromatch, 4.0.3 via tinyglobby/fdir) are pulled in transitively by tailwindcss@3's own dependency tree. Added targeted npm `overrides` keyed by the exact vulnerable version (`picomatch@2.3.1` -> `^2.3.2`, `picomatch@4.0.3` -> `^4.0.4`) so only those two specific resolutions get bumped, without touching tailwindcss or forcing an incompatible major version onto either consumer. Verified: `npm audit` reports 0 vulnerabilities, and the Tailwind CSS build (`npx tailwindcss -i ... -o ...`) still runs correctly.
Xenne93
added a commit
that referenced
this pull request
Aug 16, 2026
* Fix GitHub Code Scanning alerts (Security and quality) - Add explicit permissions blocks to build-check.yml and remove-old-packages.yml workflows (actions/missing-workflow-permissions) - Add missing admin check to PanelSettingsController.PurgeData, which previously let any authenticated user (including moderators) purge all logged data including audit logs - Add path-containment validation to MapStorageService (GetServerImageFilePath) using Path.GetFullPath + base-directory prefix check, closing an unauthenticated arbitrary-file-read via PublicImagesController's fast disk-read path using an unvalidated instanceHash route parameter (cs/path-injection) - Harden Discord webhook URL validation in ServerWebhookController.TestWebhook to check uri.Host/AbsolutePath explicitly instead of a raw substring .Contains() match - Clean up RconController.DeleteServer to return NotFound on a missing/ non-owned server instead of relying on a NullReferenceException falling through to a broad catch block - Add a shared LogSanitizer helper and use it to strip CR/LF from every user-controlled string value before it reaches a logger call across 18 files (cs/log-forging), converting any remaining string-interpolated log calls to structured logging with named placeholders along the way - Replace User.GetEmail() with a non-PII user identifier (resolved user object's Id, or the NameIdentifier claim) in every log call that previously logged the user's email address (cs/exposure-of-sensitive-information) - Mask the recipient address in EmailService's log calls instead of logging it in full - Dismiss 4 alerts confirmed as false positives via the Code Scanning API, each with a documented reason (cs/cleartext-storage-of-sensitive-information #7, cs/user-controlled-bypass #4, #5, #6) * test: inline Replace() sanitizer instead of helper method to validate CodeQL barrier recognition * Replace LogSanitizer helper with inline .Replace() calls CodeQL's cs/log-forging barrier recognition requires the sanitizing .Replace() call to appear directly in the tainted expression, not routed through a custom static helper method - validated empirically via a live re-scan (helper-based fix cleared only 1/65 alerts, one inlined call site cleared immediately). Converted every remaining call site accordingly and removed the now-dead LogSanitizer helper. * Fix remaining 4 alerts: sanitize steamId logging, drop email from EmailService diagnostics - PanelSettingsController: sanitize steamId in VAC-ban override log calls (cs/log-forging) - EmailService: stop logging even a masked form of the recipient address, since CodeQL treats any value derived from the tainted parameter as still-sensitive regardless of transformation (cs/exposure-of-sensitive-information); removed the now-unused MaskEmail helper
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the 2 remaining picomatch Dependabot alerts without pulling in tailwindcss v4 (a breaking major bump that Dependabot's own PR did as a side effect - see commit message for details).