Skip to content

fix(security): harden database-controller HTTP and YAML parsers - #5833

Merged
fan yang (fanyangCS) merged 1 commit into
masterfrom
security/argus-001-db-parsers-20260917
Sep 17, 2026
Merged

fan yang (fanyangCS) merged 1 commit into
masterfrom
security/argus-001-db-parsers-20260917

Conversation

@fanyangCS

Copy link
Copy Markdown
Collaborator

Scope

Narrow database-controller HTTP/YAML parser security update: Express 4.22.3, body-parser 1.20.8, parser-owned qs 6.16.0/path-to-regexp 0.1.13, cookie/send/serve-static and js-yaml 3.15.2. Preserve Express 4/YAML 3 APIs, Node 8 runtime, SDK/ORM and unrelated work. Genuine Yarn-generated lock; no cross-major transitive override. Adds bounded parser and real handler/Snapshot regressions.

Exact independently Argus-reviewed and locally validated head: 1b05a72d6535e33fb0a284411e8300a7f6e15592; base 276cb4b2a3e2ea73a4a6d625a2c83e826cbdbd8e. Independent local review is not a substitute for required GitHub approval.

Local validation

  • Strict Node 8.17.0/Yarn 1.22.22 lifecycle install plus separate frozen offline lifecycle install; lock/source hashes unchanged.
  • Eight bounded regressions pass in each installation, including malformed/oversized HTTP, YAML merge budgets and mocked write-merger/Snapshot conversion.
  • Existing lint, fixture lint, native diskusage build/invocation, SDK copy/import identity, syntax checks for 20 JavaScript files, selected dependency ranges/tarball integrity pass.
  • Native build used task-local Python 3.9; original host Python 3.12 build incompatibility reproduced. Baseline missing test script and parser failures recorded; fixture development failures corrected before final validation.

Remaining alerts and limits

Predicted addressed alert IDs: #346, #448, #758, #759, #760, #761, #762, #763, #765, #773, #781, #794, #802, #805, #806, #810, #1067. These are predictions, not confirmed closures. Request-owned qs remains affected: #347, #778, #1045.

Node 8 remains EOL. No Docker image, browser, cluster, real database or migration testing; database/cluster interactions are mocked. No permission workaround.

CI was not inspected or verified, by explicit task instruction. Required repository rules still apply; no admin/force/rule bypass authorized. No workflow changes.

Fresh concurrent PR file-scope review found only the stale broad 2022 PR #5774 overlapping these dependency files; it is not a duplicate focused deliverable and remains untouched. Only three paths change in this PR.

Add bounded Node 8 regressions for parser limits and mocked write-merger Snapshot conversion. Retain request-owned qs outside the incoming parser closure.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@fanyangCS
fan yang (fanyangCS) merged commit bd7503b into master Sep 17, 2026
12 of 24 checks passed
@fanyangCS
fan yang (fanyangCS) deleted the security/argus-001-db-parsers-20260917 branch September 17, 2026 07:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant