Repository navigation
chore(deps): update vulnerable dependencies - #13169
LubabaKhalid wants to merge 9 commits into
Conversation
|
The PR is ready for review. A few |
|
Pushed fa55110: the copyable provider example now declares undici ^7.29.1, matching the other three manifests. Verification: its independent build and typecheck pass, its full npm audit reports zero vulnerabilities, and the before/after manifest check confirms all four declarations now use the patched floor. The commit changes one manifest line. The four real PR CI workflows were approved for this commit and are pending verification; earlier production audit and lockfile checks passed. |
There was a problem hiding this comment.
Reviewed 7f5b68a8fefb32761baa9e308c75ed4d4bfdca73. I found no new blocking dependency issues in this diff; merge readiness still depends on the current CI run.
The root production audit passes this PR’s stated high/critical threshold (#13078), but it does not supersede #10985, which targets the remaining findings in #10850. On this exact head, corepack pnpm audit --prod --audit-level high exits 0, with 0 high, 0 critical, 11 moderate and 2 low findings. Re-running at the low threshold confirms:
| Dependency | Still resolved here | Required patched version | Advisory |
|---|---|---|---|
diff (CLI and core) |
7.0.0 |
>=8.0.3 |
GHSA-73rr-hh4g-fpgx |
uuid (core) |
9.0.1 |
>=11.1.1 |
GHSA-w5hq-g745-h8pq |
The original high-severity failure in #10850 was already cleared by #10862; the issue was explicitly left open for the remaining uuid finding. #10985 upgrades these two packages and migrates the diff types. That work still needs to be rebased onto the current pnpm tree and reviewed separately before closing #10850.
The nine changed files are byte-identical to the previously verified fa55110 snapshot, including the provider example's corrected undici floor. All six existing review threads are resolved. Previous lockfile/parity checks, the frozen lockfile validation, and the example build/typecheck/audit therefore remain applicable to those unchanged files.
The previous Java run failed the Flyway uniqueness check because two migrations used V31. At this head, the session-close migration is V32 and the exact CI uniqueness command passes (32 unique migrations). Full Java/database/E2E results still require the latest CI run; this static check alone does not establish that those jobs pass.
Latest CI snapshot: the pnpm worktree installs pass on Linux, macOS and Windows, and several Java jobs pass. The main Qwen Code CI and remaining Java/TUI checks are still queued or running. GitHub still reports CHANGES_REQUESTED; this comment is a scope/verification update, not an approval.
Follow-up review of the same head: two independent static passes found no new correctness or dependency-security issue. All five updated packages in the standalone agent-sdks lockfile have tarball URLs and integrity values matching the official npm registry. A source-level smoke check resolved the actual [email protected] and passed successful download/file-permission and byte-limit/partial-file-cleanup assertions. It used undici MockAgent and reused the other dependencies from the existing checkout; it did not exercise real DNS/TLS/proxy connections or replace the full package build/unit/CI checks. No new inline findings.
chiga0
left a comment
There was a problem hiding this comment.
APPROVE · HEAD 7f5b68a8 · Scan tier
Security dependency update. Checked mechanical consistency across the 9 changed files.
What was verified
| Package | Before | After (resolved) | NOTICES.txt |
|---|---|---|---|
undici |
^7.28.0 (→7.29.0) |
^7.29.1 → 7.30.0 |
7.29.0 → 7.30.0 ✓ |
axios |
^1.19.0 |
^1.20.0 |
— (not in NOTICES) |
@grpc/grpc-js |
1.14.4 (transitive) | override ^1.14.5 → 1.14.5 |
1.14.4 → 1.14.5 ✓ |
brace-expansion@2 |
2.1.4 (transitive) | override ^2.1.7 → 2.1.7 |
2.1.4 → 2.1.7 ✓ |
fast-uri |
3.1.7 |
3.1.8 |
3.1.7 → 3.1.8 ✓ |
Every package.json specifier, pnpm-lock.yaml resolved version, and NOTICES.txt entry are internally consistent at this HEAD. The bot's prior R1-2 finding (NOTICES.txt recording versions inconsistent with the lockfile) is closed — [email protected] in NOTICES.txt matches the 7.30.0 resolution in pnpm-lock.yaml.
pnpm-workspace.yaml overrides for @grpc/grpc-js and brace-expansion@2 are set in both pnpm-workspace.yaml and package.json root overrides. The @a2a-js/sdk peer-dependency reference to @grpc/grpc-js is updated from 1.14.4 to 1.14.5 consistently across the lock file.
The cua-driver/examples/agent-sdks/package-lock.json bump to @hono/[email protected] is an example-subdirectory lockfile update and does not affect the main workspace.
No code changes. corepack pnpm audit --prod --audit-level high reported 0 high, 0 critical per the author's evidence (remaining moderate/low findings are tracked in #10985 and are outside this PR's stated scope).
Reviewed with AI assistance.
Stale head: the round's findings (NOTICES/lock drift, manifest floor) are fixed at 7f5b68a; 0 unresolved threads.
yiliang114
left a comment
There was a problem hiding this comment.
Reviewed at the current head. The bumps are consistent across the four manifests (undici ^7.29.1 floor everywhere), the lockfile resolves undici 7.30.0 / fast-uri 3.1.8 / @grpc/grpc-js 1.14.5 / brace-expansion 2.1.7, and NOTICES.txt now records exactly those — the round-2 ledger drift finding is closed. 0 unresolved threads; the three bot CRs were filed on superseded heads and are dismissed as stale. CI: 25 green, rest skipped/pending, nothing red. Not verified locally: no frozen-lockfile install or unit suites against undici 7.30.0 — registry integrity is enforced at install time by the lock hashes.
What this PR does
Updates vulnerable production dependencies identified by the daily dependency CVE audit and adds targeted overrides for patched dependency versions.
Why it's needed
The production dependency audit reported high-severity vulnerabilities in the dependency tree, including vulnerable
undiciversions. This updates the affected dependency versions and adds targeted security overrides so the production audit no longer reports high or critical vulnerabilities.Reviewer Test Plan
How to verify
Run
corepack pnpm audit --prod --audit-level highand confirm there are no high or critical vulnerabilities.Then run
npm run check:lockfileand confirm both the pnpm lockfile check and Playwright parity check pass.Evidence (Before & After)
N/A — dependency and lockfile changes only.
Tested on
OS | Status -- | -- 🍏 macOS | N/A 🪟 Windows | N/A 🐧 Linux | ✅ testedEnvironment
Ubuntu Linux,pnpm 11.24.0。
Risk & Scope
主要风险或权衡:依赖更新可能改变传递依赖解析,因此重新生成并验证了 lockfile。
未验证 / 不在范围内:未在 macOS 和 Windows 上进行本地验证。
Breaking changes / migration notes:预计无。
Linked Issues
Fixes #13078