Repository navigation
Conversation
Apply the reviewed upstream depth and RSA validation patches to exact npm source bytes after installation. Preserve registry identities and fail on version or source drift so adoption remains explicit. Constraint: Keep Expo 56, PR67 product behavior and the original audit gate. Rejected: Package aliases or invented fixed versions | They can hide advisories without proving a supported fix. Confidence: medium Scope-risk: narrow Directive: Keep Issue62 blocked until the unchanged audit and remaining release checks pass. Tested: Node20 clean npm ci; 418 workspace tests; 31 security tests; lint; Expo alignment; Android and iOS exports. Not-tested: Native build and real devices; Forge browser dist and external EAS CLI are outside this patch.
Record complete upstream comparisons, app compatibility, native test signing, and retained release gates. This evidence does not change runtime patch bytes. Constraint: No device use, real signing credentials, or change to the audit gate. Confidence: high Scope-risk: narrow Directive: Do not use the validation APK or existing APK28 as release approval. Tested: Node20 clean install; 418 workspace and 31 security tests; lint; Expo alignment; Android/iOS exports; Android native build; upstream suites with recorded limits. Not-tested: Real devices, Play updates, browser Forge distributions, and external EAS dependencies; audit remains failed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue #62의 braces 깊이 제한 누락과 node-forge RSA 검증 문제에 최소 소스 패치를 적용한 검토 후보입니다. 취약 입력은 거부하고 기존 정상 입력과 Expo 도구 호환성을 검사했습니다. 기존 audit는 high 20으로 실패합니다. 출시 차단과 Issue #62를 유지합니다.
Related: #62, EVNSolution/clever-change-control#315. PR #67에 쌓은 별도 Draft PR입니다. base는
cc-315-driver-policy-candidate이며 PR #67을 변경하거나 병합하지 않습니다.적용 방식
4618905e19ee8229b5baab059d3527ceb34585aa.b596688d7c0bf0e754a5787b7b9c4fece6166431.4b14bb379c5e7a7a9529a21d8f04a6edb80d0f0c(후속 commit은 검증 기록만 변경).97308a01d091b211cf015314a2d0696da28a5392의 깊이 제한 6개 소스 파일만 적용합니다. 관련 없는 PR parent의 parser 변경은 제외합니다.ceba34402e329f0365134f23fe19898756527d65의lib/rsa.js만 적용합니다.patches/에 있습니다. 제품 화면·업무 기능·앱 버전은 변경하지 않습니다.검증
저장소 CI 기준 Node 20.19.4 / npm 10.8.2로 실행했습니다.
Forge PR의
describe.only는 외부 검증용 사본에서만 제거하여 전체 suite를 실행했습니다. assertion을 제외하지 않았습니다. 초기 검사 도구 오류와 수정 후 결과도 보존했습니다. Node >=22를 요구하는 기존@mapbox/jsonlint-lines-primitives@2.0.3engine 경고는 유지했습니다.native 증거와 출시 경계
검사용 APK는 구현 SHA
b596688d7c0bf0e754a5787b7b9c4fece6166431에서 생성했습니다.402cf0726400524665fd27287a45fee3cfb24c0c405d3dbd07dc98b4944b5065.com.evnsolution.clever.driver.integration, 로컬 설정0.2.0(28), arm64-v8a.766371d7ebe43f7bd3e1a99821a962365f769239aba3a78934c43dcfed8a85e7.남은 조건
dist와 별도 EAS CLI / 원격 worker 의존성은 이번 소스 패치 범위 밖입니다.상세 보고:
docs/driver-issue62-security-candidate-20261008.md.로컬 증거:
/Users/jiin/.codex/artifacts/dsv-driver-issue62-20261008/.원복은 후보 commit을 함께 revert한 뒤
npm ci로 수행합니다. 원복하면 취약한 기준 상태와 출시 차단으로 돌아갑니다.최종 HEAD CI: run 37767445449,
4b14bb379c5e7a7a9529a21d8f04a6edb80d0f0c. 기존 audit 단계의 exit 1을 그대로 유지했습니다. 최종 worktree는 clean이며 Issue #62는 OPEN입니다.