github mattrobinsonsre/terrapod v1.8.3

latest release: v1.9.1
5 hours ago

A security patch for the 1.8 line, clearing two high-severity frontend
advisories and recording a third as an accepted risk with no upstream fix.

Prompted by the weekly release re-scan, which found both fixes had become
available upstream since v1.8.2 was cut. Drop-in: no configuration changes, no
migrations, no behaviour changes.

Security

Two advisories are fixed, so npm audit against this tag no longer reports
them:

  • GHSA-wq5f-xc86-pv6w — sharp 0.35.4 → 0.35.5 (high). A
    vulnerability in librsvg (CVE-2026-96889), which ships inside the prebuilt
    libvips bundles that sharp carries. The bump moves those bundles 1.3.3 →
    1.3.4, which is where the fix actually lands.
  • GHSA-68fv-2mgg-jv7q — source-map-js 1.2.1 → 1.2.2 (high). An
    event-loop denial of service through indexed source-map section offsets.

Both are production-tree dependencies rather than dev-only, arriving through
next and postcss respectively. Neither bump is forced: both versions satisfy
the range their consumer already declares (postcss asks for ^1.2.1, next
for ^0.35.4), so nothing is pinned outside what the tree already permitted.
Each is an overrides entry, since neither package is declared directly by the
frontend.

One advisory is accepted:

  • GHSA-vfj7-8cjw-p6xm — braces stack-exhaustion denial of service
    (high). There is no fixed version to take. The advisory's range is
    <= 3.0.3 with no first-patched version, and 3.0.3 is the latest braces
    there is, so every version is affected. npm offers a major downgrade of
    eslint-config-next instead, which clears nothing — the older chain depends
    on braces too.

    It is not reachable from anything we ship: the whole chain is dev-only in the
    lockfile, and the production web image contains only the built Next.js output,
    never node_modules. So braces runs during linting and nowhere else, over
    globs we wrote ourselves rather than attacker input. The reasoning and an exit
    condition are recorded in pentest/npm-audit-allow.txt, and npm audit
    against this tag will still report it.

Also in this release, neither of them a vulnerability: one static-analysis
warning is resolved — a deliberately wrapped string in a list now says so with
an explicit + — and a suppression is recorded next to the MD5 call in the
go-terrapod state-version client, where MD5 is the TFE wire field go-tfe sends
rather than a security primitive.

Three remaining static-analysis findings at this tag are untouched and are not
security issues: two py/not-named-self and one py/unused-global-variable,
all informational and all in test files.

Documentation

Two corrections that landed on this branch since v1.8.2 and ship here:

  • The Auth0 and Okta OIDC examples in docs/authentication.md gave the SAML
    ACS path as the callback URL to register. An operator following them would
    have registered a POST-only endpoint as their OIDC redirect target, and OIDC
    login would fail. All three OIDC tables now name /auth/callback (#1960).
  • Three surfaces — the docs/api-reference.md attribute table,
    docs/vcs-integration.md and llms.txt — stated the opposite default
    for allow-fork-pr-plans, the setting that governs
    GHSA-gp5w-76rw-c452. They said off; this line ships it on. Told it
    was already off, an operator would reasonably conclude there was nothing
    to do and leave workspaces planning fork pull requests with their own
    credentials — which is the finding. Worth re-reading if you assessed that
    advisory against the old text (#1946).

Status

Stable — a drop-in patch for anyone on the 1.8 line. 1.8 is the previous minor
and receives security fixes only; the current line is 1.9.

Full Changelog: v1.8.2...v1.8.3

Don't miss a new terrapod release

NewReleases is sending notifications on new releases.