Skip to content

sec(deps): bump fast-uri and x/crypto to clear the three failing CI gates - #2068

Merged
cristim merged 2 commits into
mainfrom
fix/ci-unblock-fast-uri-xcrypto
Sep 8, 2026
Merged

cristim merged 2 commits into
mainfrom
fix/ci-unblock-fast-uri-xcrypto

Conversation

@cristim

@cristim cristim commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

What

Two dependency bumps that clear the three CI jobs currently failing on every pull request in this repo:

Job Why it fails today
Security Scanning npm audit --audit-level=high exits 1 on fast-uri 3.1.5, and govulncheck source mode exits 3 on golang.org/x/crypto
Build Docker Image the shipped image carries two x/crypto advisories that have a published fix
CI Success aggregate gate, fails because the two above fail

fast-uri 3.1.5 to 3.1.7 (lockfile only) and golang.org/x/crypto v0.55.0 to v0.56.0 in the three modules that require it. 7 files, 12 insertions, 12 deletions, no source changes.

Both halves are in one PR deliberately: CI Success requires both jobs, and Security Scanning fails on both ecosystems, so a PR fixing either half alone still could not go green.

Verification

Every gate was run locally with a baseline taken from origin/main via git archive, and again with the diff applied. An independent reviewer that did not write the change repeated all of it.

Gate Baseline With this diff
npm audit --audit-level=high exit 1, four high advisories exit 0, found 0 vulnerabilities
govulncheck source mode, root exit 3 exit 0
govulncheck source mode, all six modules root red all exit 0
binary-mode govulncheck on the built server 6354, 6355, 5932 5932 only
docker build plus scripts/scan-shipped-image.sh fails exit 0, both shipped binaries clean
frontend npm run build plus jest n/a compiles; 90 suites, 2890 passed, 1 skipped
go test root / azure / gcp / pkg / aws n/a 33 / 12 / 5 / 12 / 12 packages ok
go mod tidy -diff, go mod verify n/a clean in all six modules

No regression test is added. A test asserting a version string in go.mod or the lockfile would restate the diff and could only fail if someone reverted it. The real guards are the three CI gates, and each was observed failing before and passing after.

Things a maintainer should know

  • GO-2026-5932 (x/crypto/openpgp) has no published fix, will keep printing on every scan, and is tolerated by scripts/scan-shipped-image.sh by design. It is not what was failing the build.
  • fast-uri 3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed scheme, host or percent-encoding, the URN regex is anchored, and IPv6 canonicalization was rewritten. It is dev-only and transitive, reached through babel-loader -> schema-utils -> ajv and serve -> ajv; npm ls fast-uri --omit=dev is empty. Both consumers were exercised locally, webpack config validation via the build and serve via a smoke test on the built bundle. The serve path was checked by hand because this repo's e2e job has been seen cancelling at the chromium install step, so it may not actually cover it.
  • Module coverage is deliberate. With GOWORK=off, go list -m golang.org/x/crypto reports it is not a known dependency of pkg, providers/aws or tests/e2e, so their absence from the diff is correct rather than an oversight. The Dockerfile builds in workspace mode and builds migrate from the root module, so both shipped binaries inherit the bump.
  • Pre-existing drift left alone. go work sync wants x/sync v0.21.0 to v0.22.0 in pkg/go.mod and providers/aws/go.mod. It wants the identical edit at origin/main, so it is prior drift rather than something this PR introduces, and it is out of scope here.
  • Local govulncheck needs GOTOOLCHAIN=go1.26.6 on a Go 1.27 host, or it fails to load packages rather than reporting cleanly.

Related

Refs LeanerCloud/cloud-commitments-platform#79 (the npm half) and audit finding A15-001. Leaving LeanerCloud/cloud-commitments-platform#79 open rather than closing it, because its title also names svgo and this PR does not address that.

🤖 Generated with claude-flow

https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC

Summary by CodeRabbit

  • Chores
    • Updated the indirect cryptography dependency to version 0.56.0 across the application and cloud provider integrations.

cristim and others added 2 commits September 8, 2026 03:25
fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories
(GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf,
GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the
Security Scanning job fails on every pull request in the repo.

Lockfile only. fast-uri is a dev-only transitive dependency, reached via
babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring
`^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it.
package.json is unchanged and the lockfile change is confined to the one
entry.

3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed
scheme, host or percent-encoding, the URN regex is anchored, and IPv6
canonicalization was rewritten. Both consumers were exercised locally,
webpack config validation through `npm run build` and `serve` through a
smoke test on the built bundle, because this repo's e2e job has been seen
cancelling at the chromium install step and may not cover serve.

Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90
suites, 2890 passed.

Refs #1487, audit finding A15-001.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with
a published fix in v0.56.0. They fail two gating CI jobs on every pull
request:

- Security Scanning runs govulncheck in source mode across all six
  workspace modules. The root module exits 3, reaching both advisories
  through internal/database/postgres/testhelpers/postgres.go:145 ->
  testcontainers -> ssh.NewClientConn.
- Build Docker Image scans the shipped image and fails when any advisory
  has a published fix. Binary-mode govulncheck on the built server lists
  6354, 6355 and 5932 before, and only 5932 after.

Bumped in the three modules that actually require x/crypto. With GOWORK=off,
`go list -m golang.org/x/crypto` reports it is not a known dependency of
pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0
requires x/net, x/sys, x/term and x/text versions already present, so
nothing else moved, and go.work.sum is byte-identical after `go work sync`.

GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing
on every scan; scripts/scan-shipped-image.sh tolerates it by design.

Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six;
docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped
binaries clean; go build ./... and go test green in root (33 ok),
providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12);
go mod tidy -diff and go mod verify clean in all six modules.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
@cristim cristim added type/chore Maintenance / non-user-visible priority/p1 Next up; this sprint severity/high Significant harm urgency/now Drop other things impact/internal Team-internal only effort/xs Trivial / one-liner triaged Item has been triaged labels Sep 8, 2026
@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Essentials

Run ID: 7f3ddfd4-4633-4922-9e79-383ec4beb49b

📥 Commits

Reviewing files that changed from the base of the PR and between 3c0f8ac and 739fc54.

⛔ Files ignored due to path filters (4)
  • frontend/package-lock.json is excluded by !**/package-lock.json
  • go.sum is excluded by !**/*.sum
  • providers/azure/go.sum is excluded by !**/*.sum
  • providers/gcp/go.sum is excluded by !**/*.sum
📒 Files selected for processing (3)
  • go.mod
  • providers/azure/go.mod
  • providers/gcp/go.mod

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The pull request updates the indirect golang.org/x/crypto dependency from v0.55.0 to v0.56.0 in the root, Azure, and GCP Go modules.

Changes

Crypto dependency update

Layer / File(s) Summary
Align module requirements
go.mod, providers/azure/go.mod, providers/gcp/go.mod
The indirect golang.org/x/crypto requirement is updated to v0.56.0 in all three Go modules.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to 739fc

This updates dependency versions to address security advisories without source changes. The aligned module updates and reported validation leave no current merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the dependency security updates, including the fast-uri and golang.org/x/crypto bumps, and states their purpose of clearing CI gates.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/ci-unblock-fast-uri-xcrypto

Comment @coderabbitai help to get the list of available commands.

@cristim cristim changed the title fix(deps): bump fast-uri and x/crypto to clear the three failing CI gates sec(deps): bump fast-uri and x/crypto to clear the three failing CI gates Sep 8, 2026
@cristim
cristim merged commit fdf9c29 into main Sep 8, 2026
29 checks passed
@cristim
cristim deleted the fix/ci-unblock-fast-uri-xcrypto branch September 8, 2026 01:42
cristim added a commit that referenced this pull request Sep 27, 2026
…ates (#2068)

* fix(frontend): bump fast-uri to 3.1.7 to clear the npm audit gate

fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories
(GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf,
GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the
Security Scanning job fails on every pull request in the repo.

Lockfile only. fast-uri is a dev-only transitive dependency, reached via
babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring
`^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it.
package.json is unchanged and the lockfile change is confined to the one
entry.

3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed
scheme, host or percent-encoding, the URN regex is anchored, and IPv6
canonicalization was rewritten. Both consumers were exercised locally,
webpack config validation through `npm run build` and `serve` through a
smoke test on the built bundle, because this repo's e2e job has been seen
cancelling at the chromium install step and may not cover serve.

Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90
suites, 2890 passed.

Refs #1487, audit finding A15-001.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC

* fix(deps): bump golang.org/x/crypto to v0.56.0 to clear both Go scanners

GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with
a published fix in v0.56.0. They fail two gating CI jobs on every pull
request:

- Security Scanning runs govulncheck in source mode across all six
  workspace modules. The root module exits 3, reaching both advisories
  through internal/database/postgres/testhelpers/postgres.go:145 ->
  testcontainers -> ssh.NewClientConn.
- Build Docker Image scans the shipped image and fails when any advisory
  has a published fix. Binary-mode govulncheck on the built server lists
  6354, 6355 and 5932 before, and only 5932 after.

Bumped in the three modules that actually require x/crypto. With GOWORK=off,
`go list -m golang.org/x/crypto` reports it is not a known dependency of
pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0
requires x/net, x/sys, x/term and x/text versions already present, so
nothing else moved, and go.work.sum is byte-identical after `go work sync`.

GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing
on every scan; scripts/scan-shipped-image.sh tolerates it by design.

Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six;
docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped
binaries clean; go build ./... and go test green in root (33 ok),
providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12);
go mod tidy -diff and go mod verify clean in all six modules.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC

---------

Co-authored-by: claude-flow <ruv@ruv.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/internal Team-internal only priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/chore Maintenance / non-user-visible urgency/now Drop other things

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant