Skip to content

Patch transitive fast-uri in docs-site lockfile to close host-confusion advisories - #6502

Merged
lpcox merged 2 commits into
mainfrom
copilot/deps-safe-dependency-updates
Jul 22, 2026
Merged

Patch transitive fast-uri in docs-site lockfile to close host-confusion advisories#6502
lpcox merged 2 commits into
mainfrom
copilot/deps-safe-dependency-updates

Conversation

Copilot AI commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

This addresses the safe dependency update request for fast-uri by applying the security patch version that remediates the two HIGH host-confusion advisories. The root lockfile was already on 3.1.4; this change aligns the remaining vulnerable docs-site resolution.

  • Problem scope

    • fast-uri was expected at 3.1.4 transitively via ajv, but docs-site/package-lock.json still resolved fast-uri@3.1.2.
  • Dependency remediation

    • Updated only docs-site/package-lock.json:
      • node_modules/fast-uri
        • version: 3.1.23.1.4
        • resolved / integrity entries updated accordingly
  • Resulting lockfile state

    • Both lockfile dependency graphs now resolve ajv -> fast-uri@3.1.4.
"node_modules/fast-uri": {
  "version": "3.1.4",
  "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.4.tgz"
}

Copilot AI linked an issue Jul 22, 2026 that may be closed by this pull request
3 tasks
Copilot AI changed the title [WIP] Fix high severity vulnerability in fast-uri dependency Patch transitive fast-uri in docs-site lockfile to close host-confusion advisories Jul 22, 2026
Copilot finished work on behalf of lpcox July 22, 2026 16:41
Copilot AI requested a review from lpcox July 22, 2026 16:41
@lpcox
lpcox marked this pull request as ready for review July 22, 2026 16:45
Copilot AI review requested due to automatic review settings July 22, 2026 16:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

Files not reviewed (1)
  • docs-site/package-lock.json: Generated file

@github-actions

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation build failed for this PR. View logs.

Built from commit 2cec4ce

@github-actions

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 98.99% 99.02% 📈 +0.03%
Statements 98.92% 98.95% 📈 +0.03%
Functions 99.40% 99.40% ➡️ +0.00%
Branches 95.34% 95.34% ➡️ +0.00%
📁 Per-file Coverage Changes (1 files)
File Lines (Before → After) Statements (Before → After)
src/log-directory-setup.ts 96.2% → 100.0% (+3.78%) 96.3% → 100.0% (+3.71%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK AOAI (Entra) completed. Copilot AOAI BYOK (Entra) mode operational. 🔓

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Claude passed

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Gemini completed. All facets verified. 💎

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Contribution Check completed successfully!

Contribution check complete for PR #6502: no guideline issues found. The change is a focused lockfile dependency update with a clear description and issue reference, and it does not introduce new code requiring tests or documentation updates.

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🔑 Smoke Copilot PAT PAT auth validated. All systems operational. ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Build Test Suite completed successfully!

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

@github-actions

Copy link
Copy Markdown
Contributor

🔬 Smoke Test Results

Test Result
GitHub MCP Connectivity ✅ PASS
GitHub.com HTTP ⚠️ N/A (template vars not expanded)
File Write/Read ⚠️ N/A (template vars not expanded)

Overall: PASS (MCP verified; pre-step data unavailable due to unexpanded template variables)

Note: ${{ steps.smoke-data.outputs.* }} were not interpolated — pre-computed test data was not available to the agent.

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

Check Result
API status ✅ PASS
gh check ✅ PASS
File status ✅ PASS

Overall result: ✅ PASS

Generated by Smoke Claude for #6502 · 54.4 AIC · ⊞ 3.2K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🔒 Smoke Test: Copilot Network Isolation — PASS

@lpcox

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed domain (api.github.com): HTTP 200
  • ✅ Blocked domain (example.com): connection denied (403 from proxy)

Overall: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • example.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"

See Network Configuration for more information.

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions github-actions Bot added the smoke-copilot-network-isolation Copilot network-isolation egress smoke test label Jul 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct Mode)

  • ✅ GitHub MCP connectivity
  • ✅ GitHub.com HTTP (200)
  • ✅ File write/read
  • ✅ BYOK inference path

Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com
Status: PASS

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🔬 Smoke Test: Copilot PAT Auth

Test Result
GitHub MCP connectivity ✅ Connected (secrecy policy filtered response — expected for private repo)
GitHub.com HTTP ⚠️ Pre-step data not injected (template vars unexpanded)
File write/read ⚠️ Pre-step data not injected (template vars unexpanded)

Overall: PARTIAL — MCP auth confirmed; pre-computed step outputs were not passed to the agent.

Auth mode: PAT (COPILOT_GITHUB_TOKEN)

🔑 PAT report filed by Smoke Copilot PAT
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Chroot Version Smoke Test Results ✅

Runtime Host Version Chroot Version Match?
Python Python 3.12.13 Python 3.12.13 ✅ YES
Node.js v24.18.0 v24.18.0 ✅ YES
Go go1.22.12 go1.22.12 ✅ YES

All runtime versions match between host and chroot environment.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results: Gemini

  • PR Review: ❌ (Titles filtered by integrity policy)
  • GitHub Connectivity: ❌ (CURL failed with code 7)
  • File Writing: ✅
  • Bash Tool Testing: ✅

Overall Status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

💎 Faceted by Smoke Gemini
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

@lpcox smoke test results:

  • GitHub MCP: ✅
  • GitHub.com connectivity: ✅
  • File write/read: ❌
  • BYOK inference: ✅

Running in direct BYOK mode (AWF_AUTH_TYPE=github-oidc + AWF_AUTH_AZURE_* + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw) authenticated via Microsoft Entra

Overall status: FAIL

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test results:

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • registry.npmjs.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "registry.npmjs.org"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🔬 Smoke Test: API Proxy OpenTelemetry Tracing

Scenario Result Details
S1: Module Loading otel.js loads successfully; exports: startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled + internal helpers
S2: Test Suite 39/39 tests pass in otel.test.js (span creation, status codes, token attrs, ProxyAwareOtlpExporter, FileSpanExporter, fan-out, shutdown)
S3: Env Var Forwarding src/services/api-proxy-env-config.ts forwards GH_AW_OTLP_ENDPOINTS, OTEL_*, GITHUB_AW_OTEL_TRACE_ID, GITHUB_AW_OTEL_PARENT_SPAN_ID to the api-proxy container
S4: Token Tracker Integration token-tracker-http.js exposes onUsage callback (line 285/343) as the OTEL hook point for token usage attributes
S5: OTEL Diagnostics File-fallback exporter writes to /var/log/api-proxy/otel.jsonl when no OTLP endpoint configured; graceful no-op when unconfigured

All 5 scenarios pass. OTEL tracing integration is fully implemented and validated locally.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results — Services Connectivity

Check Result
Redis PING ❌ Name resolution failed (host.docker.internal unreachable)
PostgreSQL pg_isready ❌ No response
PostgreSQL SELECT 1 ❌ Name resolution failed

Overall: FAILhost.docker.internal DNS does not resolve in this environment.

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

@lpcox
Smoke Test: Copilot BYOK (Direct) Mode — Azure OpenAI (Foundry, api-key)

✅ GitHub MCP Testing
✅ GitHub.com Connectivity
✅ File Write/Read Test
✅ BYOK Inference Test

Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw)

Overall: PASS

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia 1/1 passed ✅ PASS
Bun hono 1/1 passed ✅ PASS
C++ fmt N/A ✅ PASS
C++ json N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world N/A ✅ PASS
.NET json-parse N/A ✅ PASS
Go color 1/1 passed ✅ PASS
Go env 1/1 passed ✅ PASS
Go uuid 1/1 passed ✅ PASS
Java gson 1/1 passed ✅ PASS
Java caffeine 1/1 passed ✅ PASS
Node.js clsx all passed ✅ PASS
Node.js execa all passed ✅ PASS
Node.js p-limit all passed ✅ PASS
Rust fd 1/1 passed ✅ PASS
Rust zoxide 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — ✅ PASS

Generated by Build Test Suite for #6502 · 38.7 AIC · ⊞ 8.2K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🔬 Smoke Test: Docker Sbx Validation

Test Result
GitHub MCP connectivity ❌ filtered by secrecy policy
GitHub.com HTTP connectivity ❌ pre-step data unavailable (template not expanded)
File write/read ❌ pre-step data unavailable (template not expanded)

Overall Status: FAIL — workflow template variables were not substituted; pre-computed test data was not available to the agent.

Note: PR data filtered by secrecy policy; author/assignee info unavailable.

📰 BREAKING: Report filed by Smoke Docker Sbx
Add label ready-for-aw to run again

@lpcox
lpcox merged commit 69139b6 into main Jul 22, 2026
140 of 145 checks passed
@lpcox
lpcox deleted the copilot/deps-safe-dependency-updates branch July 22, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Deps] Safe dependency updates (2026-07-22)

3 participants