chore(cve): Update node-forge to 1.3.3 (#4289)
Some checks failed
SqlStore Integration Tests / test-postgres (3.12) (push) Failing after 0s
SqlStore Integration Tests / test-postgres (3.13) (push) Failing after 1s
Integration Auth Tests / test-matrix (oauth2_token) (push) Failing after 1s
Test External Providers Installed via Module / test-external-providers-from-module (venv) (push) Has been skipped
Integration Tests (Replay) / generate-matrix (push) Successful in 3s
API Conformance Tests / check-schema-compatibility (push) Successful in 11s
Python Package Build Test / build (3.12) (push) Successful in 18s
Python Package Build Test / build (3.13) (push) Successful in 19s
Test External API and Providers / test-external (venv) (push) Failing after 28s
UI Tests / ui-tests (22) (push) Successful in 33s
Vector IO Integration Tests / test-matrix (push) Failing after 40s
Unit Tests / unit-tests (3.13) (push) Failing after 1m19s
Unit Tests / unit-tests (3.12) (push) Failing after 1m46s
Pre-commit / pre-commit (push) Successful in 2m49s
Integration Tests (Replay) / Integration Tests (, , , client=, ) (push) Failing after 2m42s

https://github.com/digitalbazaar/forge/security/advisories/GHSA-554w-wpv2-vw27

Taking on a direct dependency is not great
1. We don't actually use node-forge - it's only needed by
webpack-dev-server's dependency (selfsigned) for generating self-signed
certificates during development
2. Adding a direct dependency would be misleading - it suggests our code
uses node-forge when it doesn't

In the dependency chain:

```
@docusaurus/core@3.8.1
  └─ webpack-dev-server@4.15.2
      └─ selfsigned@2.4.1
          └─ node-forge@1.3.1
```
Latest Docusaurus (3.9.2) uses webpack-dev-server 5.2.2, which still
uses selfsigned 2.4.1

So, overriding dependency on node-forge is the only option
This commit is contained in:
raghotham 2025-12-03 11:58:33 -06:00 committed by GitHub
parent 3c2d74f39a
commit aa3898f486
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 5 additions and 4 deletions

View file

@ -15217,9 +15217,9 @@
} }
}, },
"node_modules/node-forge": { "node_modules/node-forge": {
"version": "1.3.1", "version": "1.3.3",
"resolved": "https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz", "resolved": "https://registry.npmjs.org/node-forge/-/node-forge-1.3.3.tgz",
"integrity": "sha512-dPEtOeMvF9VMcYV/1Wb8CPoVAXtp6MKMlcbAt4ddqmGqUJ6fQZFXkNZNkNlfevtNkGtaSoXf/vNNNSvgrdXwtA==", "integrity": "sha512-rLvcdSyRCyouf6jcOIPe/BgwG/d7hKjzMKOas33/pHEr6gbq18IK9zV7DiPvzsz0oBJPme6qr6H6kGZuI9/DZg==",
"license": "(BSD-3-Clause OR GPL-2.0)", "license": "(BSD-3-Clause OR GPL-2.0)",
"engines": { "engines": {
"node": ">= 6.13.0" "node": ">= 6.13.0"

View file

@ -32,7 +32,8 @@
"remark-code-import": "^1.2.0" "remark-code-import": "^1.2.0"
}, },
"overrides": { "overrides": {
"glob": "^10.5.0" "glob": "^10.5.0",
"node-forge": "^1.3.2"
}, },
"browserslist": { "browserslist": {
"production": [ "production": [