Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

@radroid radroid commented Aug 8, 2026

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

package needs why not
image-size 1.2.1 No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.5 0.35.0 Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.3 11.1.1 Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

coderabbitai Bot commented Aug 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid radroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfile chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile Aug 8, 2026
@radroid

radroid commented Aug 8, 2026

Copy link
Copy Markdown
Owner Author

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into main Aug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

radroid commented Aug 8, 2026

Copy link
Copy Markdown
Owner Author

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yaml single-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped). 4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened

Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.

Before the sweep the tree had one nanoid@3.3.12, and GHSA pingdotgg#115/pingdotgg#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.

The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.

One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.

Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actions Bot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened

Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.

Before the sweep the tree had one nanoid@3.3.12, and GHSA pingdotgg#115/pingdotgg#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.

The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.

One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.

Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened

Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.

Before the sweep the tree had one nanoid@3.3.12, and GHSA pingdotgg#115/pingdotgg#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.

The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.

One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.

Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant