Skip to content

Release transformabl-core 0.4.1: ReDoS fix + redactPii overlap corruption + PII-scan truncation loudness #40

Description

@davidcrowe

Goal

Cut transformabl-core 0.4.1 as a security release, then bump the transformabl facade so consumers can actually receive it. Production (gatewaystack-connect) runs transformabl-core@0.4.0 on every governed call and cannot upgrade until this ships.

Included fixes

  1. ReDoS in the email PII regex — bound the quantifiers (PR fix(transformabl-core): ReDoS in email PII regex + scan cap (0.4.1) #30, branch fix/transformabl-redos). Security review verdict: the fix is correct, all sibling patterns are already bounded, no remaining super-linear pattern. Merge fix(transformabl-core): ReDoS in email PII regex + scan cap (0.4.1) #30 as the base.
  2. redactPii overlap corruption (H4) — src/redact.ts:30-52 replaces matches by descending original offset; when an inner overlapping match is replaced first, the outer match's stale end slices the wrong point and trailing PII digits survive (reachable in placeholder/remove modes). fix(transformabl-core): ReDoS in email PII regex + scan cap (0.4.1) #30's new recognizers (us_bank_number ⊇ npi/ssn digit runs) make overlaps routine. Fix: merge overlapping spans into maximal intervals before substitution. Ship in the same 0.4.1 — fix(transformabl-core): ReDoS in email PII regex + scan cap (0.4.1) #30 is what makes it exploitable.
  3. Silent PII-scan truncation (M2) — src/detect.ts:149-151 caps scanning at 512KB with no signal (gateway body limit is 2MB), so PII placed past the cap flows through unredacted and unlogged. Violates "fail-open must be loud." Fix: add a scanTruncated flag to TransformResult; fix the now-false comment in normalize.ts.

After publish

  • Bump the transformabl facade's core range from ^0.3.0 (which can NEVER resolve 0.4.x) to ^0.4.1, republish the facade.
  • Coordinate the prod lockfile bump (gatewaystack-connect issue for the stale pins).

Acceptance

  • transformabl-core 0.4.1 on npm; facade range resolves it.
  • Overlapping-match test: redacted output contains no substring of any original match value.
  • 512KB input signals truncation.

Activity

  1. davidcrowe commented on Jul 26, 2026

    @davidcrowe
    CollaboratorAuthor

    Release checklist — everything merged, npm is the last mile (state 2026-07-26)

    All star-push fixes (#50, #51) are on main. npm still serves pre-fix versions of every package below. Two steps:

    1. Merge PR #55 (version bumps for the 7 packages #51 changed)

    2. Publish (needs npm OTP), cores before facades

    cd ~/dev/GatewayStack
    git fetch origin && git checkout main && git reset --hard origin/main && npm i
    
    # cores + shared first
    for p in request-context identifiabl-core limitabl-core validatabl-core transformabl-core proxyabl-core; do
      (cd packages/$p && npm publish --access public)   # prepublishOnly builds; add --otp=XXXXXX
    done
    
    # facades second (their ^ranges resolve the fresh cores)
    for p in identifiabl limitabl validatabl transformabl proxyabl explicabl; do
      (cd packages/$p && npm publish --access public)
    done
    package npm today publishes as why it matters
    transformabl-core 0.4.0 0.4.1 ReDoS + redactPii overlap corruption + scan-cap loudness — prod runs 0.4.0
    proxyabl 0.0.12 0.0.13 fresh npm install is broken today (missing jose dep)
    proxyabl-core 0.1.0 0.1.1 jose + trailing-slash scope bypass
    explicabl 0.0.8 0.0.9 fresh-install break #2 (undeclared node-fetch)
    transformabl 0.2.0 0.3.0 facade range fix — 0.2.0 can never resolve the 0.4.x fixes
    identifiabl-core / identifiabl / limitabl-core / limitabl / validatabl-core / validatabl / request-context current +patch (PR #55) #51 fail-open & policy-widening fixes + per-package LICENSE

    Decision needed: packages/explicabl-core (0.0.1) has never been published — new public package name. Include or hold.

    3. After publish

    • Bump the 3 stale pins in gatewaystack-connect (#431) so prod stops running known-vuln versions of our own OSS.
    • Verify: npm view @gatewaystack/transformabl-core version → 0.4.1, and a clean-room npm i @gatewaystack/proxyabl succeeds.
  2. davidcrowe commented on Jul 26, 2026

    @davidcrowe
    CollaboratorAuthor

    Released 2026-07-26. All 12 packages published (cores + facades), verified from the registry:

    • transformabl-core 0.4.1 live (ReDoS + redactPii overlap + scan-cap loudness)
    • proxyabl 0.0.13 — clean-room npm i @gatewaystack/proxyabl now succeeds (jose fix live; was broken on 0.0.12)
    • explicabl 0.0.9 (node-fetch fix live)
    • all Enforcement-core hardening (#41), stacked on the cleanup bundle #51 hardening bumps live; per-package LICENSE confirmed shipping in tarballs

    Clean-room import test of proxyabl/explicabl/transformabl passes. Held back: explicabl-core (never-published new name — separate decision). Follow-up: bump the 3 stale prod pins in gatewaystack-connect (#431).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions