Documentation
On this page
  1. File matching dependency removal
  2. CodSpeed 5.7.1 patch
  3. Verification and scope

Development dependency security

Tracked by pm-r61juc and pm-fnx3np.

Development tools execute during tests, benchmarks and release preparation. Their dependencies have the same admission requirement as production packages: no known advisory may pass the required static gate. Run:

pnpm install --frozen-lockfile
pnpm quality:dependencies

This runs the full pnpm audit, with no production-only or severity filter, then verifies the installed CodSpeed bundle policy. Network/audit errors, missing packages, incomplete policy entries, changed package files, and unreviewed upgrades all fail. quality:static includes this command, so the existing CI, nightly quality and release paths enforce it. The registry-owned local preflight also requires the static gate and permits no skip. Trivy separately includes development dependencies in its required repository scan.

File matching dependency removal

GHSA-vfj7-8cjw-p6xm affects braces 3.0.3, previously reachable through the production fast-glob dependency. A pattern under 10,000 characters can exhaust the recursive brace expansion stack. No fixed version was published when this change was verified. The SDK and repository censuses now use tinyglobby 0.2.17, removing fast-glob, micromatch and braces from the installed graph. Explicit expandDirectories: false retains file-only semantics: a directory argument does not silently become a recursive match. Dot files, brace and extglob patterns, absolute paths and invocation-relative anchoring remain supported. The regression uses a real temporary directory and the same deeply nested input that failed before the replacement. Audit errors remain mandatory failures.

CodSpeed 5.7.1 patch

CodSpeed's declared dependency previously resolved Axios 1.19.0, and both @codspeed/core bundles embedded Axios 1.4.0. Updating the declared dependency alone leaves those embedded implementations and their source-map contents intact. The pnpm override selects Axios 1.20.0 or a newer compatible 1.x release that satisfies the normal dependency cooldown. The exact-version patch in the patch file replaces the embedded dependency section in both CJS and ESM entries with imports of the declared axios and form-data packages. Each entry creates its own Axios client and retains the cancellation constructor, preserving isolation from application request and response interceptors.

The replacement boundary starts at function bind$2(fn, thisArg) and ends immediately before var __defProp$3 = Object.defineProperty. Only axios and FormData$2 from that section are referenced by the retained code. The patch preserves the preceding and following benchmark code, declarations, export surface and native binaries. Each entry removes 19,201 embedded lines. Its map retains 5,375 mappings, removes 39,536 obsolete mappings, and reduces its source inventory from 131 to 21. Remaining generated positions are shifted by the replacement's line delta; their original source, line, column and names are preserved. Removed Axios, redirects, proxy and form-data sources are absent. Both maps end with a newline; the integrity policy records the installed bytes.

The integrity policy pins all twelve package-owned files by SHA-256: both entries, both maps, all three native binaries, the manifest, declarations and declaration map, license and README. Owned artifacts must be regular files; symlinks cannot redirect their module resolution to an unreviewed dependency tree even when their target bytes have the same hash. Admission also checks the exact installed file inventory, so an added executable, map or native payload fails even when the previously approved files are unchanged. Package-local dependency overrides also fail inventory admission: an added node_modules/axios could shadow the audited dependency resolved by the bundle. Only the three node-gyp-build commands and their CMD/PowerShell variants may appear directly in node_modules/.bin. Each must be a regular file whose complete program matches the reviewed shim templates, with targets and module paths derived from the audited installed dependency. Arbitrary names, nested payloads, links, altered programs and forged target markers fail; these shims are outside the twelve package-owned hashes but are independently validated. The shell template records pnpm 11.10.0's installed output; the CMD and PowerShell templates come from @zkochan/cmd-shim 9.0.7. Template changes require renewed real installation evidence on both POSIX and native Windows. The CMD suffix follows the installed PATHEXT spelling, including .CMD; format lookup folds its case while validating the complete program. All three shell launchers are required, together with the CMD and PowerShell sets on Windows. Any additional format must also contain all three commands. Missing or duplicate launchers fail admission. Installation roots and rendered paths containing shell interpolation syntax fail before template comparison; ordinary paths containing spaces remain supported. Templates are comparison data: the checker never rewrites pnpm-generated launchers. The locked dependency graph is checked by the full audit. An upstream upgrade requires a reviewed patch removal or refresh, renewed runtime compatibility evidence, and a matching policy update. Never update hashes merely to admit an unexplained difference.

Verification and scope

The admission suite edits real temporary package copies and proves that each changed package file and additional unreviewed payload is refused. The runtime integration suite uses both public entries in fresh processes, calls a real loopback HTTP server, and verifies setup, benchmark start/stop, HTTP failure conversion, exports, measurement conversions, root-frame wrappers and isolation from real application interceptors. The server observes the audited Axios transport rather than a mocked client. The existing CodSpeed workflow continues to execute the native benchmark integration.

These findings establish vulnerable dependency inventory, not a demonstrated production exploit. CodSpeed is a development dependency. Its Mongo instrumentation transport requires an explicitly configured instrumentation server; ordinary benchmarks do not configure one. Native Scorecard analysis of the merged commit must confirm alert retirement independently of local audits and PR checks.

From docs/DEVELOPMENT_DEPENDENCY_SECURITY.md in pm 2026.10.4. View on GitHub