Skip to content

fix: security sweep (GH-172, GH-205, GH-196) - #12

Merged
dennisofficial merged 2 commits into
mainfrom
dennis/security-sweep
Sep 24, 2026
Merged

dennisofficial merged 2 commits into
mainfrom
dennis/security-sweep

Conversation

@dennisofficial

@dennisofficial dennisofficial commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Security fix sweep for findings filed against this repo.

  • GH-172 (P2) — Removed the 16 commercially licensed TWK Lausanne (Weltkern) woff/woff2 binaries from packages/design-system/src/fonts/TWKLausanne/, dropped the 16 @font-face rules and the ./fonts/* npm export map entry, and swapped the --font-sans family to the already-declared OFL-licensed @fontsource-variable/plus-jakarta-sans dependency. The published package no longer redistributes a retail typeface under an MIT grant. The weight-mapping utilities (350/400/700 ramp) are kept.
  • GH-205 (P2) — ChartStyle in packages/design-system/src/components/organisms/chart.tsx no longer interpolates consumer-supplied values raw into dangerouslySetInnerHTML: the chart id and config keys must match ^[a-zA-Z0-9_-]+$, color values must match a safe CSS-value charset (hex/rgb/hsl, var()/theme(), named colors) and contain no <; anything else is dropped, closing the </style> breakout / HTML injection sink. Added apps/storybook/tests/Chart.test.tsx covering the safe render plus key/color/id injection payloads.
  • GH-196 (P3) — NEEDS-ENV, no code change: https://design-system-storybook-swart.vercel.app is served publicly (verified HTTP 200 with no SSO redirect) while other Comp AI *.vercel.app deployments redirect to SSO. Vercel Deployment Protection is a project setting, not repo code. To fix: Vercel Dashboard → project design-system-storybook → Settings → Deployment Protection → enable Vercel Authentication (or SSO Protection) for Production (and Preview if desired). If public access is the deliberate choice for this open-source showcase, document that decision instead.

Verification

  • pnpm typecheck — 3/3 tasks pass
  • pnpm vitest run --project unit tests/Chart.test.tsx (apps/storybook) — 4/4 pass
  • pnpm lint fails only on pre-existing prettier issues in apps/mcp (also failing on unmodified origin/main; untouched by this PR)
  • GH-196 verified live: curl -sI https://design-system-storybook-swart.vercel.app returns HTTP/2 200 serving the app directly, no 302 to SSO

Summary by cubic

Security sweep across the design system: drops commercially licensed font binaries from the published package and closes an HTML injection sink in chart styles.

Bug Fixes

  • Removed the 16 licensed TWK Lausanne woff/woff2 files, their @font-face rules, and the ./fonts/* export; --font-sans now uses the OFL-licensed @fontsource-variable/plus-jakarta-sans.
  • ChartStyle no longer interpolates unsanitized consumer values into dangerouslySetInnerHTML — chart id and config keys must match ^[a-zA-Z0-9_-]+$, and colors are limited to a safe CSS charset with no <; invalid values are dropped.
  • Added apps/storybook/tests/Chart.test.tsx covering safe rendering and injection payloads for key, color, and id.

Migration

  • GH-196 (public Storybook deployment) requires no code change: enable Vercel Deployment Protection for the design-system-storybook project in the Vercel dashboard, or document the choice to keep it public.

Written for commit 1b8b45f. Summary will update on new commits.

Review in cubic

@vercel

vercel Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
design-system-storybook Ready Ready Preview Sep 24, 2026 8:52pm UTC

Request Review

@dennisofficial
dennisofficial marked this pull request as ready for review September 24, 2026 21:25
@dennisofficial
dennisofficial merged commit e9c16a2 into main Sep 24, 2026
6 of 10 checks passed

This branch was successfully deployed

1 active deployment
Preview — 1b8b45f9 Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant