A security patch for the 1.8 line, clearing two high-severity frontend
advisories and recording a third as an accepted risk with no upstream fix.
Prompted by the weekly release re-scan, which found both fixes had become
available upstream since v1.8.2 was cut. Drop-in: no configuration changes, no
migrations, no behaviour changes.
Security
Two advisories are fixed, so npm audit against this tag no longer reports
them:
GHSA-wq5f-xc86-pv6w—sharp0.35.4 → 0.35.5 (high). A
vulnerability in librsvg (CVE-2026-96889), which ships inside the prebuilt
libvips bundles that sharp carries. The bump moves those bundles 1.3.3 →
1.3.4, which is where the fix actually lands.GHSA-68fv-2mgg-jv7q—source-map-js1.2.1 → 1.2.2 (high). An
event-loop denial of service through indexed source-map section offsets.
Both are production-tree dependencies rather than dev-only, arriving through
next and postcss respectively. Neither bump is forced: both versions satisfy
the range their consumer already declares (postcss asks for ^1.2.1, next
for ^0.35.4), so nothing is pinned outside what the tree already permitted.
Each is an overrides entry, since neither package is declared directly by the
frontend.
One advisory is accepted:
-
GHSA-vfj7-8cjw-p6xm—bracesstack-exhaustion denial of service
(high). There is no fixed version to take. The advisory's range is
<= 3.0.3with no first-patched version, and 3.0.3 is the latestbraces
there is, so every version is affected. npm offers a major downgrade of
eslint-config-nextinstead, which clears nothing — the older chain depends
onbracestoo.It is not reachable from anything we ship: the whole chain is dev-only in the
lockfile, and the production web image contains only the built Next.js output,
nevernode_modules. Sobracesruns during linting and nowhere else, over
globs we wrote ourselves rather than attacker input. The reasoning and an exit
condition are recorded inpentest/npm-audit-allow.txt, andnpm audit
against this tag will still report it.
Also in this release, neither of them a vulnerability: one static-analysis
warning is resolved — a deliberately wrapped string in a list now says so with
an explicit + — and a suppression is recorded next to the MD5 call in the
go-terrapod state-version client, where MD5 is the TFE wire field go-tfe sends
rather than a security primitive.
Three remaining static-analysis findings at this tag are untouched and are not
security issues: two py/not-named-self and one py/unused-global-variable,
all informational and all in test files.
Documentation
Two corrections that landed on this branch since v1.8.2 and ship here:
- The Auth0 and Okta OIDC examples in
docs/authentication.mdgave the SAML
ACS path as the callback URL to register. An operator following them would
have registered a POST-only endpoint as their OIDC redirect target, and OIDC
login would fail. All three OIDC tables now name/auth/callback(#1960). - Three surfaces — the
docs/api-reference.mdattribute table,
docs/vcs-integration.mdandllms.txt— stated the opposite default
forallow-fork-pr-plans, the setting that governs
GHSA-gp5w-76rw-c452. They said off; this line ships it on. Told it
was already off, an operator would reasonably conclude there was nothing
to do and leave workspaces planning fork pull requests with their own
credentials — which is the finding. Worth re-reading if you assessed that
advisory against the old text (#1946).
Status
Stable — a drop-in patch for anyone on the 1.8 line. 1.8 is the previous minor
and receives security fixes only; the current line is 1.9.
Full Changelog: v1.8.2...v1.8.3