Skip to content

fix(web): patch source-map-js denial of service - #171

Merged
erichare merged 1 commit into
mainfrom
fix/source-map-js-security
Oct 7, 2026
Merged

erichare merged 1 commit into
mainfrom
fix/source-map-js-security

Conversation

@erichare

@erichare erichare commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Tailwind's CSS tooling resolved source-map-js@1.2.1, which accepts malformed indexed source-map offsets that can block the event loop (CVE-2026-93749, GHSA-68fv-2mgg-jv7q). Add a pnpm override for versions below 1.2.2 and regenerate the lockfile so every dependency path resolves to the patched 1.2.2 release.

Addresses Dependabot alert #132. Upstream advisory.

Validation with the repository's pinned pnpm 10.33.0:

  • Frozen-lockfile install succeeds and pnpm audit reports no known vulnerabilities.
  • pnpm why source-map-js reports only 1.2.2.
  • Confirmed the Tailwind dependency accepted an excessive indexed-map offset before the update. After the update, excessive, invalid, and excessive nested offsets are rejected, while a valid large offset processes short source code correctly.
  • Web regression tests pass (9 tests), type checking passes, and the production build succeeds.

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
verity Ready Ready Preview Oct 7, 2026 8:38pm UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T20:39:36.854478Z 32010aa PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@erichare
erichare merged commit d3936b8 into main Oct 7, 2026
18 checks passed
@erichare
erichare deleted the fix/source-map-js-security branch October 7, 2026 20:39

This branch was successfully deployed

1 active deployment
Preview — 32010aa0 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant