1
0
mirror of https://github.com/lancedikson/bowser synced 2026-09-23 20:44:24 +00:00
Commit Graph

26 Commits

Author SHA1 Message Date
naorpeled
982a91d5e8 fix: resolve open GitHub security findings
Code scanning (js/polynomial-redos, alerts #16 and #17)
-------------------------------------------------------
bowser applies these regexps to attacker-controlled User-Agent strings, and
four of them ran in quadratic time:

  * The "Something else" fallback used /^(.*)\/(.*) / and
    /^(.*)\/(.*)[ \t]\((.*)/. Two unbounded `.*` before a required literal
    make the split ambiguous, so a UA of "/a" repeated backtracks O(n^2).
    Greedy `(.*)` always picks the last `/` that still has the delimiter
    after it, so the second group can never span a `/` -- narrowing it to
    `[^/]*` is exactly equivalent and removes the ambiguity. Verified
    identical on 1,000,000 fuzzed inputs and on the full acceptance corpus.

  * The Linespider and SlackBot version regexps used `(?:-[-\w]+)?` before a
    required `[\s/]`. Since `[-\w]` and `[\s/]` are disjoint the backtracking
    is pure waste, but the engine still walks it once per start position, so
    "linespider-" repeated is quadratic. Bounding the run to `{1,64}` makes
    it linear; no real bot-name suffix approaches 64 characters.

A sweep of all 253 regexp literals in src/ (fuzzed for superlinear scaling,
with the four pre-fix patterns used to confirm the detector works) reports no
remaining superlinear regexps. test/unit/redos.js locks this in.

Actions (actions/missing-workflow-permissions, alerts #5 and #15)
-----------------------------------------------------------------
merge-to-master.yml and draft-or-update-next-release.yml had no `permissions`
block and so inherited the default token. Both now declare least privilege,
matching publish.yml and pull-request.yml.

Dependabot (22 open alerts, all development scope)
--------------------------------------------------
bowser ships no runtime dependencies, so none of these reached consumers, but
they were live in CI. `pnpm audit` goes from 29 advisories to 0:

  * jsdoc 3 -> 4 (with docdash 1 -> 2) drops taffydb, which has no patched
    release, and picks up current markdown-it/linkify-it.
  * coveralls -> coveralls-next 6 drops `request`, which is deprecated with no
    patched release, along with form-data, qs 6.5.x, uuid 3 and tough-cookie 2.
    Same `coveralls` bin and same stdin contract; lcov conversion verified.
  * gh-pages 3 -> 6 clears the critical prototype pollution advisory.
  * pnpm overrides pin the remaining transitive-only advisories to the lowest
    patched release on each existing major.

Verified: pnpm audit clean, lint clean, 346 tests pass (the acceptance corpus
runs against both src/ and the built es5.js), build, package smoke test, and
doc generation.
2026-08-30 21:00:59 +03:00
Naor Peled
a88622557d Dual packaging, without breaking existing consumers (#628)
Co-authored-by: Yasumasa Ashida <ys.ashida@gmail.com>
2026-08-30 00:10:11 +03:00
naorpeled
507b205791 chore: remove github copilot instructions file 2026-02-13 22:31:33 +02:00
naorpeled
f11700291a Replace .github/copilot-instructions.md with AGENTS.md 2026-02-13 22:30:26 +02:00
Denis Demchenko
740d6c4844 Update npm to latest version before publishing to npm registry (#603)
Co-authored-by: Claude <noreply@anthropic.com>
2026-02-08 23:37:11 +02:00
naorpeled
382bc22397 chore: update publish flow 2026-02-07 19:43:20 +02:00
naorpeled
e2318ef12d fix: attemp to resolve NPM publish issues 2026-02-07 19:12:34 +02:00
naorpeled
8f9badd27f chore: update publish flow 2026-02-07 19:05:32 +02:00
naorpeled
fbccc9616a docs: add naorpeled to Funding.yml 2026-01-31 19:07:46 +02:00
Copilot
a4d0b828e4 chore: add Copilot instructions for repository (#574)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: naorpeled <6171622+naorpeled@users.noreply.github.com>
2025-11-22 13:31:12 +02:00
Naor Peled
3c25806efe ci(publish): add manual trigger and retry logic for npm publish 2025-08-09 21:27:38 +03:00
Naor Peled
8ac2f6a1ec chore(deps): change nyc version to 15 for Node 12 to work (#565) 2025-08-09 21:05:17 +03:00
Naor Peled
20fc037785 fix: resolve CI failures (#560) 2025-08-09 20:51:00 +03:00
Naor Peled
afc0fbf131 ci(release): bump all deps 2025-07-06 19:24:07 +03:00
Naor Peled
e0ee0e7baf ci: bump cache action to v4 2025-07-06 19:21:23 +03:00
Naor Peled
16c9f22546 ci: attempt to resolve merge to master errors (#546) 2024-04-20 14:54:03 +03:00
Naor Peled
327e6f5e51 ci: add release drafter (#545) 2024-04-20 14:35:56 +03:00
Naor Peled
69bc6c2dbf revert(workflows): rollback to Node 12.16.3 (#537) 2023-11-17 20:45:54 +02:00
Naor Peled
9c1588a43e chore: add CodeQL config 2023-11-13 11:56:25 +02:00
Naor Peled
efb8e612a5 ci: move to Github Actions (#530) 2023-11-13 11:11:28 +02:00
Denis Demchenko
41c30ec722 fix(chore): bug with babel/helper-compilation on build
No "exports" main resolved in /home/runner/work/bowser/bowser/node_modules/@babel/helper-compilation-targets/package.json
2020-07-09 21:27:15 +03:00
Denis Demchenko
ea8d9c5427 npm i → npm ci 2019-10-02 21:50:47 +03:00
Denis Demchenko
8fb6e3a080 Update nodejs.yml 2019-08-27 20:17:55 +03:00
Denis Demchenko
40c6be6654 Activate github actions 2019-08-27 20:13:33 +03:00
Denis Demchenko
71d4904d20 chore(.github): move github related files 2019-08-04 23:51:07 +03:00
Denis Demchenko
976518e524 Add FUNDING.yml 2019-07-16 21:39:38 +03:00