Skip to content

chore(deps): update vulnerable dependencies - #13169

Open
LubabaKhalid wants to merge 9 commits into
QwenLM:mainfrom
LubabaKhalid:fix/dependency-cve-audit
Open

LubabaKhalid wants to merge 9 commits into
QwenLM:mainfrom
LubabaKhalid:fix/dependency-cve-audit

Conversation

@LubabaKhalid

@LubabaKhalid LubabaKhalid commented Oct 1, 2026 •

Copy link
Copy Markdown

What this PR does

Updates vulnerable production dependencies identified by the daily dependency CVE audit and adds targeted overrides for patched dependency versions.

Why it's needed

The production dependency audit reported high-severity vulnerabilities in the dependency tree, including vulnerable undici versions. This updates the affected dependency versions and adds targeted security overrides so the production audit no longer reports high or critical vulnerabilities.

Reviewer Test Plan

How to verify

Run corepack pnpm audit --prod --audit-level high and confirm there are no high or critical vulnerabilities.

Then run npm run check:lockfile and confirm both the pnpm lockfile check and Playwright parity check pass.

Evidence (Before & After)

N/A — dependency and lockfile changes only.

Tested on

OS | Status -- | -- 🍏 macOS | N/A 🪟 Windows | N/A 🐧 Linux | ✅ tested

Environment

Ubuntu Linux,pnpm 11.24.0。

Risk & Scope

  • 主要风险或权衡:依赖更新可能改变传递依赖解析,因此重新生成并验证了 lockfile。

  • 未验证 / 不在范围内:未在 macOS 和 Windows 上进行本地验证。

  • Breaking changes / migration notes:预计无。

Linked Issues

Fixes #13078

@LubabaKhalid

Copy link
Copy Markdown
Author

The PR is ready for review. A few pull_request_target workflows are currently awaiting maintainer approval.

@yiliang114

yiliang114 commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Pushed fa55110: the copyable provider example now declares undici ^7.29.1, matching the other three manifests. Verification: its independent build and typecheck pass, its full npm audit reports zero vulnerabilities, and the before/after manifest check confirms all four declarations now use the patched floor. The commit changes one manifest line. The four real PR CI workflows were approved for this commit and are pending verification; earlier production audit and lockfile checks passed.

@yiliang114
yiliang114 enabled auto-merge October 2, 2026 12:28

@yiliang114 yiliang114 left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 7f5b68a8fefb32761baa9e308c75ed4d4bfdca73. I found no new blocking dependency issues in this diff; merge readiness still depends on the current CI run.

The root production audit passes this PR’s stated high/critical threshold (#13078), but it does not supersede #10985, which targets the remaining findings in #10850. On this exact head, corepack pnpm audit --prod --audit-level high exits 0, with 0 high, 0 critical, 11 moderate and 2 low findings. Re-running at the low threshold confirms:

Dependency Still resolved here Required patched version Advisory
diff (CLI and core) 7.0.0 >=8.0.3 GHSA-73rr-hh4g-fpgx
uuid (core) 9.0.1 >=11.1.1 GHSA-w5hq-g745-h8pq

The original high-severity failure in #10850 was already cleared by #10862; the issue was explicitly left open for the remaining uuid finding. #10985 upgrades these two packages and migrates the diff types. That work still needs to be rebased onto the current pnpm tree and reviewed separately before closing #10850.

The nine changed files are byte-identical to the previously verified fa55110 snapshot, including the provider example's corrected undici floor. All six existing review threads are resolved. Previous lockfile/parity checks, the frozen lockfile validation, and the example build/typecheck/audit therefore remain applicable to those unchanged files.

The previous Java run failed the Flyway uniqueness check because two migrations used V31. At this head, the session-close migration is V32 and the exact CI uniqueness command passes (32 unique migrations). Full Java/database/E2E results still require the latest CI run; this static check alone does not establish that those jobs pass.
Latest CI snapshot: the pnpm worktree installs pass on Linux, macOS and Windows, and several Java jobs pass. The main Qwen Code CI and remaining Java/TUI checks are still queued or running. GitHub still reports CHANGES_REQUESTED; this comment is a scope/verification update, not an approval.

Follow-up review of the same head: two independent static passes found no new correctness or dependency-security issue. All five updated packages in the standalone agent-sdks lockfile have tarball URLs and integrity values matching the official npm registry. A source-level smoke check resolved the actual [email protected] and passed successful download/file-permission and byte-limit/partial-file-cleanup assertions. It used undici MockAgent and reused the other dependencies from the existing checkout; it did not exercise real DNS/TLS/proxy connections or replace the full package build/unit/CI checks. No new inline findings.

@chiga0 chiga0 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE · HEAD 7f5b68a8 · Scan tier

Security dependency update. Checked mechanical consistency across the 9 changed files.

What was verified

Package Before After (resolved) NOTICES.txt
undici ^7.28.0 (→7.29.0) ^7.29.1 → 7.30.0 7.29.0 → 7.30.0 ✓
axios ^1.19.0 ^1.20.0 — (not in NOTICES)
@grpc/grpc-js 1.14.4 (transitive) override ^1.14.5 → 1.14.5 1.14.4 → 1.14.5 ✓
brace-expansion@2 2.1.4 (transitive) override ^2.1.7 → 2.1.7 2.1.4 → 2.1.7 ✓
fast-uri 3.1.7 3.1.8 3.1.7 → 3.1.8 ✓

Every package.json specifier, pnpm-lock.yaml resolved version, and NOTICES.txt entry are internally consistent at this HEAD. The bot's prior R1-2 finding (NOTICES.txt recording versions inconsistent with the lockfile) is closed — [email protected] in NOTICES.txt matches the 7.30.0 resolution in pnpm-lock.yaml.

pnpm-workspace.yaml overrides for @grpc/grpc-js and brace-expansion@2 are set in both pnpm-workspace.yaml and package.json root overrides. The @a2a-js/sdk peer-dependency reference to @grpc/grpc-js is updated from 1.14.4 to 1.14.5 consistently across the lock file.

The cua-driver/examples/agent-sdks/package-lock.json bump to @hono/[email protected] is an example-subdirectory lockfile update and does not affect the main workspace.

No code changes. corepack pnpm audit --prod --audit-level high reported 0 high, 0 critical per the author's evidence (remaining moderate/low findings are tracked in #10985 and are outside this PR's stated scope).

Reviewed with AI assistance.

@yiliang114
yiliang114 dismissed stale reviews from ghost October 2, 2026 14:12

Stale head: the round's findings (NOTICES/lock drift, manifest floor) are fixed at 7f5b68a; 0 unresolved threads.

@yiliang114 yiliang114 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at the current head. The bumps are consistent across the four manifests (undici ^7.29.1 floor everywhere), the lockfile resolves undici 7.30.0 / fast-uri 3.1.8 / @grpc/grpc-js 1.14.5 / brace-expansion 2.1.7, and NOTICES.txt now records exactly those — the round-2 ledger drift finding is closed. 0 unresolved threads; the three bot CRs were filed on superseded heads and are dismissed as stale. CI: 25 green, rest skipped/pending, nothing red. Not verified locally: no frozen-lockfile install or unit suites against undici 7.30.0 — registry integrity is enforced at install time by the lock hashes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Daily dependency CVE audit failed

5 participants