Skip to content

[MINOR] Backport braces depth guard for React tooling - #5528

Open
voidmatcha wants to merge 1 commit into
apache:masterfrom
voidmatcha:fix/zeppelin-react-braces-patch-audit
Open

voidmatcha wants to merge 1 commit into
apache:masterfrom
voidmatcha:fix/zeppelin-react-braces-patch-audit

Conversation

@voidmatcha

@voidmatcha voidmatcha commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

What is this PR for?

The React npm audit job fails because braces@3.0.3 is affected by GHSA-vfj7-8cjw-p6xm. The upstream fix is under review in micromatch/braces#72, but there is no patched release or confirmed release date.

A downstream project pins a fork containing the fix. This PR instead uses patch-package to apply the depth-limit fix from micromatch/braces#72 at 28d440b to the published braces@3.0.3, without taking unrelated unpublished changes. The local, version-pinned patch keeps the workaround confined to this package and makes it straightforward to remove when an official release is available.

CI explicitly applies and verifies the patch. The audit policy temporarily allows only the two affected development-dependency paths, until December 4, 2026. Other high- and critical-severity findings still fail the job. If this approach is accepted, I will open a follow-up Jira issue to remove the patch and audit exceptions once an official fixed release is available.

What type of PR is it?

Improvement

Todos

  • Open a follow-up Jira issue for removing the temporary patch and audit exceptions if this approach is accepted

What is the Jira issue?

N/A

How should this be tested?

From zeppelin-web-angular/projects/zeppelin-react:

npm ci --ignore-scripts --no-audit
npm run apply:patches
npm run audit
npm run lint
npm test
npm run build

The patch check fails before the patch is applied and passes afterward. Locally, the audit policy, lint, build, and all 89 React tests passed. GitHub Actions has not yet been verified on this branch.

Screenshots (if appropriate)

N/A

Questions:

  • Does the license files need to update? No
  • Is there breaking changes for older versions? No
  • Does this needs documentation? Yes, documented in the React README

@voidmatcha
voidmatcha force-pushed the fix/zeppelin-react-braces-patch-audit branch from db9e22e to 6a279b3 Compare October 4, 2026 08:52
@voidmatcha
voidmatcha force-pushed the fix/zeppelin-react-braces-patch-audit branch from 6a279b3 to c6d6f77 Compare October 4, 2026 09:13

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant