Repository navigation
sec(deps): bump fast-uri and x/crypto to clear the three failing CI gates - #2068
Conversation
fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the Security Scanning job fails on every pull request in the repo. Lockfile only. fast-uri is a dev-only transitive dependency, reached via babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring `^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it. package.json is unchanged and the lockfile change is confined to the one entry. 3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed scheme, host or percent-encoding, the URN regex is anchored, and IPv6 canonicalization was rewritten. Both consumers were exercised locally, webpack config validation through `npm run build` and `serve` through a smoke test on the built bundle, because this repo's e2e job has been seen cancelling at the chromium install step and may not cover serve. Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90 suites, 2890 passed. Refs #1487, audit finding A15-001. Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with a published fix in v0.56.0. They fail two gating CI jobs on every pull request: - Security Scanning runs govulncheck in source mode across all six workspace modules. The root module exits 3, reaching both advisories through internal/database/postgres/testhelpers/postgres.go:145 -> testcontainers -> ssh.NewClientConn. - Build Docker Image scans the shipped image and fails when any advisory has a published fix. Binary-mode govulncheck on the built server lists 6354, 6355 and 5932 before, and only 5932 after. Bumped in the three modules that actually require x/crypto. With GOWORK=off, `go list -m golang.org/x/crypto` reports it is not a known dependency of pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0 requires x/net, x/sys, x/term and x/text versions already present, so nothing else moved, and go.work.sum is byte-identical after `go work sync`. GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing on every scan; scripts/scan-shipped-image.sh tolerates it by design. Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six; docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped binaries clean; go build ./... and go test green in root (33 ok), providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12); go mod tidy -diff and go mod verify clean in all six modules. Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Essentials Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (3)
Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe pull request updates the indirect ChangesCrypto dependency update
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This updates dependency versions to address security advisories without source changes. The aligned module updates and reported validation leave no current merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
…ates (#2068) * fix(frontend): bump fast-uri to 3.1.7 to clear the npm audit gate fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the Security Scanning job fails on every pull request in the repo. Lockfile only. fast-uri is a dev-only transitive dependency, reached via babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring `^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it. package.json is unchanged and the lockfile change is confined to the one entry. 3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed scheme, host or percent-encoding, the URN regex is anchored, and IPv6 canonicalization was rewritten. Both consumers were exercised locally, webpack config validation through `npm run build` and `serve` through a smoke test on the built bundle, because this repo's e2e job has been seen cancelling at the chromium install step and may not cover serve. Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90 suites, 2890 passed. Refs #1487, audit finding A15-001. Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC * fix(deps): bump golang.org/x/crypto to v0.56.0 to clear both Go scanners GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with a published fix in v0.56.0. They fail two gating CI jobs on every pull request: - Security Scanning runs govulncheck in source mode across all six workspace modules. The root module exits 3, reaching both advisories through internal/database/postgres/testhelpers/postgres.go:145 -> testcontainers -> ssh.NewClientConn. - Build Docker Image scans the shipped image and fails when any advisory has a published fix. Binary-mode govulncheck on the built server lists 6354, 6355 and 5932 before, and only 5932 after. Bumped in the three modules that actually require x/crypto. With GOWORK=off, `go list -m golang.org/x/crypto` reports it is not a known dependency of pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0 requires x/net, x/sys, x/term and x/text versions already present, so nothing else moved, and go.work.sum is byte-identical after `go work sync`. GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing on every scan; scripts/scan-shipped-image.sh tolerates it by design. Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six; docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped binaries clean; go build ./... and go test green in root (33 ok), providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12); go mod tidy -diff and go mod verify clean in all six modules. Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC --------- Co-authored-by: claude-flow <ruv@ruv.net>
What
Two dependency bumps that clear the three CI jobs currently failing on every pull request in this repo:
Security Scanningnpm audit --audit-level=highexits 1 on fast-uri 3.1.5, and govulncheck source mode exits 3 ongolang.org/x/cryptoBuild Docker ImageCI Successfast-uri3.1.5 to 3.1.7 (lockfile only) andgolang.org/x/cryptov0.55.0 to v0.56.0 in the three modules that require it. 7 files, 12 insertions, 12 deletions, no source changes.Both halves are in one PR deliberately:
CI Successrequires both jobs, andSecurity Scanningfails on both ecosystems, so a PR fixing either half alone still could not go green.Verification
Every gate was run locally with a baseline taken from
origin/mainviagit archive, and again with the diff applied. An independent reviewer that did not write the change repeated all of it.npm audit --audit-level=highdocker buildplusscripts/scan-shipped-image.shnpm run buildplus jestgo testroot / azure / gcp / pkg / awsgo mod tidy -diff,go mod verifyNo regression test is added. A test asserting a version string in
go.modor the lockfile would restate the diff and could only fail if someone reverted it. The real guards are the three CI gates, and each was observed failing before and passing after.Things a maintainer should know
x/crypto/openpgp) has no published fix, will keep printing on every scan, and is tolerated byscripts/scan-shipped-image.shby design. It is not what was failing the build.resolvenow throws on a malformed scheme, host or percent-encoding, the URN regex is anchored, and IPv6 canonicalization was rewritten. It is dev-only and transitive, reached throughbabel-loader -> schema-utils -> ajvandserve -> ajv;npm ls fast-uri --omit=devis empty. Both consumers were exercised locally, webpack config validation via the build andservevia a smoke test on the built bundle. Theservepath was checked by hand because this repo's e2e job has been seen cancelling at the chromium install step, so it may not actually cover it.GOWORK=off,go list -m golang.org/x/cryptoreports it is not a known dependency ofpkg,providers/awsortests/e2e, so their absence from the diff is correct rather than an oversight. The Dockerfile builds in workspace mode and buildsmigratefrom the root module, so both shipped binaries inherit the bump.go work syncwantsx/syncv0.21.0 to v0.22.0 inpkg/go.modandproviders/aws/go.mod. It wants the identical edit atorigin/main, so it is prior drift rather than something this PR introduces, and it is out of scope here.GOTOOLCHAIN=go1.26.6on a Go 1.27 host, or it fails to load packages rather than reporting cleanly.Related
Refs LeanerCloud/cloud-commitments-platform#79(the npm half) and audit finding A15-001. Leaving LeanerCloud/cloud-commitments-platform#79 open rather than closing it, because its title also names svgo and this PR does not address that.🤖 Generated with claude-flow
https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC
Summary by CodeRabbit