Repository navigation
Commit 2b336c4
sec(deps): bump fast-uri and x/crypto to clear the three failing CI gates (#2068)
* fix(frontend): bump fast-uri to 3.1.7 to clear the npm audit gate
fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories
(GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf,
GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the
Security Scanning job fails on every pull request in the repo.
Lockfile only. fast-uri is a dev-only transitive dependency, reached via
babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring
`^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it.
package.json is unchanged and the lockfile change is confined to the one
entry.
3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed
scheme, host or percent-encoding, the URN regex is anchored, and IPv6
canonicalization was rewritten. Both consumers were exercised locally,
webpack config validation through `npm run build` and `serve` through a
smoke test on the built bundle, because this repo's e2e job has been seen
cancelling at the chromium install step and may not cover serve.
Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90
suites, 2890 passed.
Refs #1487, audit finding A15-001.
Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
* fix(deps): bump golang.org/x/crypto to v0.56.0 to clear both Go scanners
GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with
a published fix in v0.56.0. They fail two gating CI jobs on every pull
request:
- Security Scanning runs govulncheck in source mode across all six
workspace modules. The root module exits 3, reaching both advisories
through internal/database/postgres/testhelpers/postgres.go:145 ->
testcontainers -> ssh.NewClientConn.
- Build Docker Image scans the shipped image and fails when any advisory
has a published fix. Binary-mode govulncheck on the built server lists
6354, 6355 and 5932 before, and only 5932 after.
Bumped in the three modules that actually require x/crypto. With GOWORK=off,
`go list -m golang.org/x/crypto` reports it is not a known dependency of
pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0
requires x/net, x/sys, x/term and x/text versions already present, so
nothing else moved, and go.work.sum is byte-identical after `go work sync`.
GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing
on every scan; scripts/scan-shipped-image.sh tolerates it by design.
Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six;
docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped
binaries clean; go build ./... and go test green in root (33 ok),
providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12);
go mod tidy -diff and go mod verify clean in all six modules.
Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
---------
Co-authored-by: claude-flow <ruv@ruv.net>1 parent 7cf8e15 commit 2b336c4
2 files changed
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
67 | | - | |
| 67 | + | |
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
379 | 379 | | |
380 | 380 | | |
381 | 381 | | |
382 | | - | |
383 | | - | |
| 382 | + | |
| 383 | + | |
384 | 384 | | |
385 | 385 | | |
386 | 386 | | |
| |||
0 commit comments