Skip to content

fix(deps): raise chalk floor to ^5.6.2 to exclude malicious 5.6.1 (GHSA-2v46-p5h4-248w) - #255

Open
kamal-kaur04 wants to merge 2 commits into
mainfrom
security/chalk-mal-2025-46969
Open

kamal-kaur04 wants to merge 2 commits into
mainfrom
security/chalk-mal-2025-46969

Conversation

@kamal-kaur04

@kamal-kaur04 kamal-kaur04 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

What is this about?

Raises the chalk dependency floor of @wdio/browserstack-service from ^5.3.0 to ^5.6.2 so the range can no longer resolve chalk@5.6.1, the version published by a hijacked maintainer account in the September 2025 npm supply-chain attack (GHSA-2v46-p5h4-248w / MAL-2025-46969).

chalk is kept external in the esbuild bundle, so consumers resolve it against this package's declared range. npm has unpublished 5.6.1, but a registry mirror or cache that kept it could still serve it for ^5.3.0. The lockfile already resolves 5.6.2, so the installed tree is unchanged. The only change is the range in package.json plus the matching lockfile line.

Verified locally: npm ci + npm ls chalk --all (only 5.6.2 / 4.1.2, no 5.6.1), npm run build passes, npm test shows 59 files / 1345 tests passing.

Related Jira task/s

N/A (tracked internally). Advisory: GHSA-2v46-p5h4-248w

Release (mandatory for every PR — required for the ready-for-review label)

Version bump: (required — tick exactly one)

  • minor (backwards-compatible feature)
  • patch (bug fix or other small change)

Release notes type: (optional)

  • New Feature
  • Bug Fix
  • Other Improvement

Release notes (customer-facing): (optional but encouraged)

  • Raised the minimum chalk version to 5.6.2 so installs can never resolve the compromised chalk@5.6.1 (GHSA-2v46-p5h4-248w).

Release notes (internal): (required — engineer-facing; what actually changed / why)

  • chalk range ^5.3.0 → ^5.6.2 in packages/browserstack-service/package.json (+ lockfile range line); resolved version unchanged at 5.6.2. The v8 line carries the same ^5.3.0 range and needs the same bump.

Checklist

  • Ready to review
  • Has it been tested locally?

PR Validations

Run Tests: Comment RUN_TESTS to trigger sanity tests.

🤖 Generated with Claude Code

chalk@5.6.1 was published by a hijacked maintainer account
(GHSA-2v46-p5h4-248w / MAL-2025-46969). chalk is an external runtime
dependency of the service, so consumers resolve it against our declared
range; ^5.3.0 still admits 5.6.1 from any mirror or cache that retained it.
The lockfile already resolves 5.6.2, so the installed tree is unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited), Workspace UI (inherited)

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: edd7245e-2604-46bc-889a-d38396b97551

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@kamal-kaur04

Copy link
Copy Markdown
Collaborator Author

RUN_TESTS

@kamal-kaur04

Copy link
Copy Markdown
Collaborator Author

⚠️ Needs human review

No code defects found in the reviewed changes. The chalk floor moves from ^5.3.0 to ^5.6.2 inside the same major, which excludes the compromised 5.6.1, and the changeset text matches the change.

One region could not be reviewed automatically: the matching range line in package-lock.json (lockfiles are outside automated review scope). A reviewer should confirm the packages/browserstack-service entry reads ^5.6.2 and that node_modules/chalk still resolves to 5.6.2 (the author reports npm ls chalk --all shows only 5.6.2 / 4.1.2).

File Confidence
.changeset/pr-255.md ✅ All Clear
packages/browserstack-service/package.json ✅ All Clear
package-lock.json ⚠️ Needs Human Review

Change map (generated deterministically from the diff)

graph LR
  subgraph nnode_agent["node-agent"]
    n_changeset_pr_255_md["pr-255.md<br/>~5 lines"]
    npackages_browserstack_service_package_json["package.json<br/>~2 lines"]
  end
Loading

↻ This verdict comment is the review anchor — it's updated in place on each run (the gate posts its status separately).

— SDK PR Review Agent

@kamal-kaur04

Copy link
Copy Markdown
Collaborator Author

Lockfile check on head 706da2a (the region the automated review skipped): the only package-lock.json change is the packages/browserstack-service entry's chalk range ^5.3.0 → ^5.6.2. node_modules/chalk still resolves to 5.6.2, and no path resolves 5.6.1. A human reviewer still needs to confirm this to clear the ⚠️.

@kamal-kaur04

Copy link
Copy Markdown
Collaborator Author

⚠️ Sanity needs human review: SDK Wdio Test failed (https://minion-qa.browserstack.com/job/QA/job/SDKWdioTest/620/). The same job is also red on the most recent PRs, whatever their change: #251 (run 612), #252 (run 619), #253 (run 618). That points to a job or environment failure, not this change, which only touches the range and leaves the resolved dependency tree identical (chalk 5.6.2). Local results: build passes, and vitest passes 59 files / 1345 tests. A human needs to confirm the Jenkins failure cause before merge.

@kamal-kaur04
kamal-kaur04 marked this pull request as ready for review September 29, 2026 15:01
@kamal-kaur04
kamal-kaur04 requested a review from a team as a code owner September 29, 2026 15:01
@kamal-kaur04

Copy link
Copy Markdown
Collaborator Author

RUN_TESTS

@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: pending).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: pending).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

@minionhelperappqa

Copy link
Copy Markdown

[SDK Wdio Test] TRA build state: passed | Stability 100% — verdict: success. Passed: 51, Failed: 0, Aggregate: 51. TRA: https://observability.browserstack.com/builds/yqdauqadubc5j16rknzieefndvyfyg47obyzxybo

@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: pending).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: pending).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants