From d97c837f4c4df1195e2a45cdf6b348120d1a4597 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Tue, 8 Sep 2026 03:25:14 +0200 Subject: [PATCH 1/2] fix(frontend): bump fast-uri to 3.1.7 to clear the npm audit gate fast-uri 3.0.0 through 3.1.5 carry four high-severity advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp), so `npm audit --audit-level=high` exits 1 and the Security Scanning job fails on every pull request in the repo. Lockfile only. fast-uri is a dev-only transitive dependency, reached via babel-loader -> schema-utils -> ajv and via serve -> ajv, both declaring `^3.0.1`; `npm ls fast-uri --omit=dev` is empty, so nothing ships it. package.json is unchanged and the lockfile change is confined to the one entry. 3.1.7 parses more strictly than 3.1.5: resolve now throws on a malformed scheme, host or percent-encoding, the URN regex is anchored, and IPv6 canonicalization was rewritten. Both consumers were exercised locally, webpack config validation through `npm run build` and `serve` through a smoke test on the built bundle, because this repo's e2e job has been seen cancelling at the chromium install step and may not cover serve. Verified: npm audit exit 1 before, exit 0 after; build compiles; jest 90 suites, 2890 passed. Refs #1487, audit finding A15-001. Co-Authored-By: claude-flow Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC --- frontend/package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/frontend/package-lock.json b/frontend/package-lock.json index c71bb9e13..90002bd36 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -5752,9 +5752,9 @@ "license": "MIT" }, "node_modules/fast-uri": { - "version": "3.1.5", - "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.5.tgz", - "integrity": "sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==", + "version": "3.1.7", + "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.7.tgz", + "integrity": "sha512-dOvZVzjdZdz7phd9v6jCbwxrBW3fK6n8Rc0CtdmM4bumzMnxywBYhuph6J819RRw/ku+rLbelwfMunktuzVVHg==", "dev": true, "funding": [ { From 739fc54f40e8b7cbf19d26f86978e0cafc03ae7b Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Tue, 8 Sep 2026 03:25:41 +0200 Subject: [PATCH 2/2] fix(deps): bump golang.org/x/crypto to v0.56.0 to clear both Go scanners GO-2026-6354 and GO-2026-6355 are golang.org/x/crypto/ssh advisories with a published fix in v0.56.0. They fail two gating CI jobs on every pull request: - Security Scanning runs govulncheck in source mode across all six workspace modules. The root module exits 3, reaching both advisories through internal/database/postgres/testhelpers/postgres.go:145 -> testcontainers -> ssh.NewClientConn. - Build Docker Image scans the shipped image and fails when any advisory has a published fix. Binary-mode govulncheck on the built server lists 6354, 6355 and 5932 before, and only 5932 after. Bumped in the three modules that actually require x/crypto. With GOWORK=off, `go list -m golang.org/x/crypto` reports it is not a known dependency of pkg, providers/aws or tests/e2e, so those are correctly untouched. v0.56.0 requires x/net, x/sys, x/term and x/text versions already present, so nothing else moved, and go.work.sum is byte-identical after `go work sync`. GO-2026-5932 (x/crypto/openpgp) has no published fix and will keep printing on every scan; scripts/scan-shipped-image.sh tolerates it by design. Verified: govulncheck exit 3 -> 0 in the root module and 0 in all six; docker build plus scripts/scan-shipped-image.sh exit 0 with both shipped binaries clean; go build ./... and go test green in root (33 ok), providers/azure (12), providers/gcp (5), pkg (12) and providers/aws (12); go mod tidy -diff and go mod verify clean in all six modules. Co-Authored-By: claude-flow Claude-Session: https://claude.ai/code/session_01Fu9uWjxtDFx5HDKeMRt1jC --- go.mod | 2 +- go.sum | 4 ++-- providers/azure/go.mod | 2 +- providers/azure/go.sum | 4 ++-- providers/gcp/go.mod | 2 +- providers/gcp/go.sum | 4 ++-- 6 files changed, 9 insertions(+), 9 deletions(-) diff --git a/go.mod b/go.mod index ef52736bb..7371654f0 100644 --- a/go.mod +++ b/go.mod @@ -64,7 +64,7 @@ require ( go.opentelemetry.io/otel v1.44.0 // indirect go.opentelemetry.io/otel/metric v1.44.0 // indirect go.opentelemetry.io/otel/trace v1.44.0 // indirect - golang.org/x/crypto v0.55.0 + golang.org/x/crypto v0.56.0 golang.org/x/net v0.57.0 // indirect golang.org/x/oauth2 v0.36.0 golang.org/x/sync v0.22.0 diff --git a/go.sum b/go.sum index ce91af555..ddedaf17d 100644 --- a/go.sum +++ b/go.sum @@ -379,8 +379,8 @@ go.opentelemetry.io/otel/sdk/metric v1.43.0 h1:S88dyqXjJkuBNLeMcVPRFXpRw2fuwdvfC go.opentelemetry.io/otel/sdk/metric v1.43.0/go.mod h1:C/RJtwSEJ5hzTiUz5pXF1kILHStzb9zFlIEe85bhj6A= go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs= diff --git a/providers/azure/go.mod b/providers/azure/go.mod index 840ef6ef1..1da63e8c1 100644 --- a/providers/azure/go.mod +++ b/providers/azure/go.mod @@ -32,7 +32,7 @@ require ( github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect github.com/stretchr/objx v0.5.3 // indirect - golang.org/x/crypto v0.55.0 // indirect + golang.org/x/crypto v0.56.0 // indirect golang.org/x/net v0.57.0 // indirect golang.org/x/sys v0.47.0 // indirect golang.org/x/text v0.41.0 // indirect diff --git a/providers/azure/go.sum b/providers/azure/go.sum index 214b5fced..dde7b28d9 100644 --- a/providers/azure/go.sum +++ b/providers/azure/go.sum @@ -66,8 +66,8 @@ github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4= github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0= github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek= diff --git a/providers/gcp/go.mod b/providers/gcp/go.mod index f674d71b2..b25fb872e 100644 --- a/providers/gcp/go.mod +++ b/providers/gcp/go.mod @@ -57,7 +57,7 @@ require ( go.opentelemetry.io/otel/sdk v1.43.0 // indirect go.opentelemetry.io/otel/sdk/metric v1.43.0 // indirect go.opentelemetry.io/otel/trace v1.44.0 // indirect - golang.org/x/crypto v0.55.0 // indirect + golang.org/x/crypto v0.56.0 // indirect golang.org/x/net v0.57.0 // indirect golang.org/x/sys v0.47.0 // indirect golang.org/x/text v0.41.0 // indirect diff --git a/providers/gcp/go.sum b/providers/gcp/go.sum index 11749c874..2b9a7b398 100644 --- a/providers/gcp/go.sum +++ b/providers/gcp/go.sum @@ -111,8 +111,8 @@ go.opentelemetry.io/otel/sdk/metric v1.43.0 h1:S88dyqXjJkuBNLeMcVPRFXpRw2fuwdvfC go.opentelemetry.io/otel/sdk/metric v1.43.0/go.mod h1:C/RJtwSEJ5hzTiUz5pXF1kILHStzb9zFlIEe85bhj6A= go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=