Skip to content

Ignore the node-forge advisory until a fix is published - #1086

Merged
MBombeck merged 3 commits into
mainfrom
fix/audit-node-forge
Oct 2, 2026
Merged

MBombeck merged 3 commits into
mainfrom
fix/audit-node-forge

Conversation

@MBombeck

@MBombeck MBombeck commented Oct 2, 2026

Copy link
Copy Markdown
Owner

pnpm audit --prod --audit-level=high now reports GHSA-86w9-cpqp-85rv (node-forge <= 1.4.0, RSA PKCS#1 v1.5 signature verification), which would turn the blocking audit on main and the daily schedule red.

  • node-forge arrives only through @parse/node-apn, which uses it in its certificate-based credential path (credentials/certificate/*: p12 / PEM certificate). HealthLog authenticates to APNs with a token (.p8 key via APNS_KEY_ID / APNS_TEAM_ID), so the affected code never runs.
  • The advisory names 1.4.1 as patched, but npm's latest is 1.4.0; there is nothing to raise the floor to.
  • The entry in auditConfig.ignoreGhsas (pnpm-workspace.yaml) carries the reason and the instruction to remove it and raise the floor once 1.4.1 is published.

GHSA-86w9-cpqp-85rv affects RSA PKCS#1 v1.5 signature verification in
node-forge up to 1.4.0, which arrives only through @parse/node-apn for
certificate-based APNs credentials. HealthLog uses token authentication,
so that path never runs, and no patched release exists yet.
Same advisory, same reasoning as the pnpm audit entry: the affected
signature verification sits in node-apn's certificate credential path,
which token-authenticated APNs never reaches, and no fix is published.
@MBombeck
MBombeck merged commit 1a403b7 into main Oct 2, 2026
25 checks passed
@MBombeck
MBombeck deleted the fix/audit-node-forge branch October 2, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant