Skip to content

Commit 2b336c4

Browse files
cristimruvnet
andauthored
sec(deps): bump fast-uri and x/crypto to clear the three failing CI gates (#2068)
* fix(frontend): bump fast-uri to 3.1.7 to clear the npm audit gate fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the Security Scanning job fails on every pull request in the repo. Lockfile only. fast-uri is a dev-only transitive dependency, reached via babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring `^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it. package.json is unchanged and the lockfile change is confined to the one entry. 3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed scheme, host or percent-encoding, the URN regex is anchored, and IPv6 canonicalization was rewritten. Both consumers were exercised locally, webpack config validation through `npm run build` and `serve` through a smoke test on the built bundle, because this repo's e2e job has been seen cancelling at the chromium install step and may not cover serve. Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90 suites, 2890 passed. Refs #1487, audit finding A15-001. Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC * fix(deps): bump golang.org/x/crypto to v0.56.0 to clear both Go scanners GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with a published fix in v0.56.0. They fail two gating CI jobs on every pull request: - Security Scanning runs govulncheck in source mode across all six workspace modules. The root module exits 3, reaching both advisories through internal/database/postgres/testhelpers/postgres.go:145 -> testcontainers -> ssh.NewClientConn. - Build Docker Image scans the shipped image and fails when any advisory has a published fix. Binary-mode govulncheck on the built server lists 6354, 6355 and 5932 before, and only 5932 after. Bumped in the three modules that actually require x/crypto. With GOWORK=off, `go list -m golang.org/x/crypto` reports it is not a known dependency of pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0 requires x/net, x/sys, x/term and x/text versions already present, so nothing else moved, and go.work.sum is byte-identical after `go work sync`. GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing on every scan; scripts/scan-shipped-image.sh tolerates it by design. Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six; docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped binaries clean; go build ./... and go test green in root (33 ok), providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12); go mod tidy -diff and go mod verify clean in all six modules. Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC --------- Co-authored-by: claude-flow <ruv@ruv.net>
1 parent 7cf8e15 commit 2b336c4

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

‎go.mod‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ require (
6464
go.opentelemetry.io/otel v1.44.0 // indirect
6565
go.opentelemetry.io/otel/metric v1.44.0 // indirect
6666
go.opentelemetry.io/otel/trace v1.44.0 // indirect
67-
golang.org/x/crypto v0.55.0
67+
golang.org/x/crypto v0.56.0
6868
golang.org/x/net v0.57.0 // indirect
6969
golang.org/x/oauth2 v0.36.0
7070
golang.org/x/sync v0.22.0

‎go.sum‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -379,8 +379,8 @@ go.opentelemetry.io/otel/sdk/metric v1.43.0 h1:S88dyqXjJkuBNLeMcVPRFXpRw2fuwdvfC
379379
go.opentelemetry.io/otel/sdk/metric v1.43.0/go.mod h1:C/RJtwSEJ5hzTiUz5pXF1kILHStzb9zFlIEe85bhj6A=
380380
go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk=
381381
go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE=
382-
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
383-
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
382+
golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y=
383+
golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I=
384384
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
385385
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
386386
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=

0 commit comments

Comments
 (0)