Repository navigation
chore: upgrade simple-git to ^4.0.2 to address CVE-2026-102826, CVE-2026-102827, CVE-2026-102828, CVE-2026-102829 - #1715
Merged
Conversation
- Switch default simple-git imports to the named simpleGit export (v4 removed the default export). - Allow-list the explicitly constructed git environment in the backend client. v4 throws when a git-related env var is supplied without being in allowEnvironment; unsafe values remain gated by the existing unsafe options. - Declare @simple-git/argv-parser as a direct backend dependency since git.ts imports it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Contributor
License Audit
Weak Copyleft Packages (informational)
Resolved Packages (8)
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes SOU-2466
Fixes SOU-2467
Fixes SOU-2468
Fixes SOU-2469
Summary
Upgrades
simple-gitfrom^3.36.0to^4.0.2in@sourcebot/backendand@sourcebot/web. This also pulls in@simple-git/argv-parser@2.0.1. None of these CVEs have a fix on the 3.x line.trailer.<token>.cmdnot classified as unsafeVISUALomitted from unsafe editor detectionBreaking changes handled
import simpleGit from 'simple-git'. They now use the namedsimpleGitexport, and thegetFileSourceApitest mock is updated to match.GIT_*,PAGER,SSH_ASKPASS, ...) is passed through.env()without being listed inallowEnvironment.createGitClientForPathpassesprocess.envplusGIT_CEILING_DIRECTORIES,GIT_TERMINAL_PROMPT, and the credential-session variables, so without a change every backend git operation would fail. The client now setsallowEnvironmentto the keys of the environment it builds. This keeps the v3 behaviour: dangerous values are still gated by the existingunsafeoptions, which v4 checks separately.@simple-git/argv-parser.git.tsimportsparseEnvfrom it directly but only got it transitively. It is now a declared backend dependency at^2.0.1, andparseEnvkeeps the same API.raw()calls. None use abbreviated long options or-C/--git-dir/--work-treebefore the subcommand. The only global option used is-c core.quotePath=false, which isn't flagged as unsafe.On the web side,
simpleGit()is called without.env(). v4 silently drops ambient guarded variables there, and the web app doesn't rely on any.Testing
yarn workspace @sourcebot/backend test: 29 files, 309 tests pass.git.test.tsruns real git, including an authenticated HTTP clone and fetch through the credential session.allowEnvironmentline and re-rangit.test.ts, and it fails withUse of "PAGER" is blocked by the environment guard. So the test covers this.yarn vitest run src/features/git(web): 5 files, 139 tests pass.tsc --noEmit(web) shows no errors outside the generated.next/types, andyarn workspace @sourcebot/backend buildpasses.🤖 Generated with Claude Code
Note
Medium Risk
Touches all backend and web git subprocess usage; misconfigured
allowEnvironmentwould break cloning and browse APIs, though tests cover the guard behavior.Overview
Upgrades
simple-gitto^4.0.2in backend and web to address several CVEs that are only fixed on the 4.x line, and records the change in the changelog.Backend:
createGitClientForPathnow builds the git environment object once, passes it through.env(), and setsallowEnvironmentto every key in that object so v4’s environment guard does not block normal operations (e.g.GIT_CEILING_DIRECTORIES, inheritedPAGER).@simple-git/argv-parser@^2.0.1is declared explicitly on the backend package.Web: Git browse APIs switch from the removed default export to the named
simpleGitimport; the file-source API test mock is updated to match.Reviewed by Cursor Bugbot for commit fee4b79. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by CodeRabbit