Skip to content

Prepare Issue #62 dependency patch candidate with audit block intact - #68

Draft
OziinG wants to merge 2 commits into
cc-315-driver-policy-candidatefrom
cc-315-driver-issue62-security
Draft

OziinG wants to merge 2 commits into
cc-315-driver-policy-candidatefrom
cc-315-driver-issue62-security

Conversation

@OziinG

@OziinG OziinG commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Issue #62의 braces 깊이 제한 누락과 node-forge RSA 검증 문제에 최소 소스 패치를 적용한 검토 후보입니다. 취약 입력은 거부하고 기존 정상 입력과 Expo 도구 호환성을 검사했습니다. 기존 audit는 high 20으로 실패합니다. 출시 차단과 Issue #62를 유지합니다.

Related: #62, EVNSolution/clever-change-control#315. PR #67에 쌓은 별도 Draft PR입니다. base는 cc-315-driver-policy-candidate이며 PR #67을 변경하거나 병합하지 않습니다.

적용 방식

  • 기준: PR Prepare Driver 0.2.0 with verified UI and explicit release gates #67 4618905e19ee8229b5baab059d3527ceb34585aa.
  • 구현: b596688d7c0bf0e754a5787b7b9c4fece6166431.
  • 최종 HEAD: 4b14bb379c5e7a7a9529a21d8f04a6edb80d0f0c (후속 commit은 검증 기록만 변경).
  • 공식 registry와 advisory를 재확인했습니다. braces 3.0.3 / node-forge 1.4.0의 공식 수정 릴리스는 없습니다. Expo SDK 56 경로에도 해당 수정이 없습니다.
  • braces PR #78 97308a01d091b211cf015314a2d0696da28a5392의 깊이 제한 6개 소스 파일만 적용합니다. 관련 없는 PR parent의 parser 변경은 제외합니다.
  • Forge PR #1152 ceba34402e329f0365134f23fe19898756527d65의 lib/rsa.js만 적용합니다.
  • 설치 후 원본·수정본·패치 SHA256을 확인합니다. 모든 locked copy를 검사하며 버전·내용이 다르면 실패합니다. workspace 검사도 패치 상태를 확인합니다.
  • 원래 package 이름·버전·resolved·integrity와 audit 기준을 보존합니다. 새 npm 의존성은 없습니다. lockfile에는 root install-script 표시만 추가합니다.
  • 라이선스·출처·고정 SHA·재현·원복 절차는 patches/에 있습니다. 제품 화면·업무 기능·앱 버전은 변경하지 않습니다.

검증

저장소 CI 기준 Node 20.19.4 / npm 10.8.2로 실행했습니다.

검사 결과
깨끗한 npm ci / 패치 해시 PASS
workspace typecheck 및 기존 테스트 PASS, 418/418
취약 입력·정상 입력·설치 무결성 회귀 PASS, 31/31; 패치 전 취약 입력 검사 실패 확인
lint / Expo dependency alignment PASS
Android / iOS export PASS
Android native assembleRelease PASS, arm64-v8a, 608 tasks, 임시 테스트 키 사용
Expo 인증서·서명 도구 PASS: PEM, X509, CSR, manifest 서명·변조 거부, ASN.1, PKCS#12
braces 배포 버전 전체 suite PASS, 764/764
braces PR의 보안 깊이 suite PASS, 14/14 (원본 2 pass / 12 fail)
braces 고정 PR 전체 suite 866 pass / 42 fail. 원본 854 pass / 54 fail. 남은 42개는 미포함 parent 변경에 대한 기존 실패이며 제목·메시지 동일. 신규 실패 없음
Forge 전체 Node suite 기본·pureJS 각각 829 pass / 4 upstream pending / 0 fail (원본 보안 실패 1개 해결)
npm audit --audit-level=moderate FAIL, exit 1, high 20 / critical 0
최종 HEAD 원격 CI FAIL: 설치·workspace·lint·Android/iOS export PASS, audit FAIL. 후속 alignment/diff 단계는 skipped (로컬 별도 PASS)

Forge PR의 describe.only는 외부 검증용 사본에서만 제거하여 전체 suite를 실행했습니다. assertion을 제외하지 않았습니다. 초기 검사 도구 오류와 수정 후 결과도 보존했습니다. Node >=22를 요구하는 기존 @mapbox/jsonlint-lines-primitives@2.0.3 engine 경고는 유지했습니다.

native 증거와 출시 경계

검사용 APK는 구현 SHA b596688d7c0bf0e754a5787b7b9c4fece6166431에서 생성했습니다.

  • SHA256: 402cf0726400524665fd27287a45fee3cfb24c0c405d3dbd07dc98b4944b5065.
  • com.evnsolution.clever.driver.integration, 로컬 설정 0.2.0(28), arm64-v8a.
  • 새 임시 인증서 SHA256: 766371d7ebe43f7bd3e1a99821a962365f769239aba3a78934c43dcfed8a85e7.
  • 실제 앱 서명 키는 사용하지 않았습니다. 기기에 설치하지 않았습니다. 이 APK는 native 호환성 검사 전용이며 정식 업데이트 산출물이 아닙니다.
  • 기존 PR #67의 HEAD, 미커밋 문서와 기존 28번 APK 해시를 보존했습니다. 기존 28번은 새 의존성 후보의 증거가 아닙니다.

남은 조건

  1. audit 실패로 출시 차단을 유지합니다. upstream 패치는 아직 미병합이며 공식 수정 또는 승인된 지원 경로가 필요합니다.
  2. Forge browser dist와 별도 EAS CLI / 원격 worker 의존성은 이번 소스 패치 범위 밖입니다.
  3. 채택 시 정식 AAB/APK를 새로 생성하고 서명·버전·내용을 검증해야 합니다. 새 산출물의 실기기 검사와 Play 서명 업데이트 검사는 별도로 필요합니다.
  4. 원격 EAS 버전·자격 증명 변경, 실기기 조작, Play/Drive 게시, 운영 배포, 병합, Issue 종료는 하지 않았습니다.

상세 보고: docs/driver-issue62-security-candidate-20261008.md.
로컬 증거: /Users/jiin/.codex/artifacts/dsv-driver-issue62-20261008/.
원복은 후보 commit을 함께 revert한 뒤 npm ci로 수행합니다. 원복하면 취약한 기준 상태와 출시 차단으로 돌아갑니다.

최종 HEAD CI: run 37767445449, 4b14bb379c5e7a7a9529a21d8f04a6edb80d0f0c. 기존 audit 단계의 exit 1을 그대로 유지했습니다. 최종 worktree는 clean이며 Issue #62는 OPEN입니다.

OziinG added 2 commits October 8, 2026 19:09
Apply the reviewed upstream depth and RSA validation patches to exact npm
source bytes after installation. Preserve registry identities and fail on
version or source drift so adoption remains explicit.

Constraint: Keep Expo 56, PR67 product behavior and the original audit gate.
Rejected: Package aliases or invented fixed versions | They can hide advisories without proving a supported fix.
Confidence: medium
Scope-risk: narrow
Directive: Keep Issue62 blocked until the unchanged audit and remaining release checks pass.
Tested: Node20 clean npm ci; 418 workspace tests; 31 security tests; lint; Expo alignment; Android and iOS exports.
Not-tested: Native build and real devices; Forge browser dist and external EAS CLI are outside this patch.
Record complete upstream comparisons, app compatibility, native test signing,
and retained release gates. This evidence does not change runtime patch bytes.

Constraint: No device use, real signing credentials, or change to the audit gate.
Confidence: high
Scope-risk: narrow
Directive: Do not use the validation APK or existing APK28 as release approval.
Tested: Node20 clean install; 418 workspace and 31 security tests; lint; Expo alignment; Android/iOS exports; Android native build; upstream suites with recorded limits.
Not-tested: Real devices, Play updates, browser Forge distributions, and external EAS dependencies; audit remains failed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant