Skip to content

build(deps-dev): bump vscode postcss + brace-expansion; deterministic add --all abort test - #152

Merged
kdr merged 2 commits into
mainfrom
dependabot-lockfile-bumps
Aug 5, 2026
Merged

build(deps-dev): bump vscode postcss + brace-expansion; deterministic add --all abort test#152
kdr merged 2 commits into
mainfrom
dependabot-lockfile-bumps

Conversation

@kdr

@kdr kdr commented Aug 5, 2026

Copy link
Copy Markdown
Owner

Closes out the current Dependabot security sweep (https://github.com/kdr/overcast/security/dependabot).

What

  • vscode/package-lock.json (lockfile-only, within existing semver ranges):
    • postcss 8.5.19 → 8.5.25 — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset (alert Add evidence-only case memory and typed indexes #22; via tsup/vite)
    • brace-expansion 5.0.8 → 5.0.9 — DoS via unbounded intermediate arrays (flagged by npm audit, no open Dependabot PR; via @vscode/vsce → minimatch)
    • vscode npm audit after: 0 vulnerabilities
  • test/unit/face-index.test.ts: deterministic abort point for aborting during add --all backpressure stops before the next wave. The 100 ms wall-clock abort raced wave 0's child processes under suite load: landing mid-spawn surfaces node's generic AbortError (reason demoted to cause) instead of signal.reason, and wave-0 membership may not be written yet — intermittently failing both assertions (this reddened Build(deps): Bump postcss from 8.5.19 to 8.5.25 in /vscode #149's CI and one local full run). The test now aborts only once the wave-0 member is visibly written, i.e. provably inside the 60 s between-wave settle sleep whose abort path rejects with the reason; if the run settles first the poll bails so the real error surfaces through assert.rejects.

Triage context (same sweep, handled outside this PR)

Not addressed — upstream-blocked (alerts #19, #11–13)

Root brace-expansion@5.0.7 (high) and undici@8.5.0 (3 medium) are pinned inside @earendil-works/pi-coding-agent's published npm-shrinkwrap.json. Root overrides and npm audit fix silently no-op on the shrinkwrapped subtree (audit even prints "fix available", then changes nothing), and pi-coding-agent 0.83.0 still declares undici@8.5.0 exactly — the only real fix is an upstream pi release with a refreshed shrinkwrap, then a reviewed exact-pin bump. Interim reachability: pi 0.83.0's undici use has no cache/retry interceptors (the CVE surfaces), and its minimatch patterns are config-driven, not attacker input.

Verification (all on this branch, full unfiltered output)

suite result
npm test 1319/1319 pass, exit 0
npm run test:e2e (offline) 367/367 passed, 0 failed, exit 0
npm run typecheck exit 0
vscode typecheck / build / test / package exit 0 / exit 0 / 56/56 / .vsix packaged (vsce = the brace-expansion consumer)
npm run test:e2e:live (compiled bun binary) 767/778 passed, 11 failed
live re-run of the 5 failing cases (same binary) 187/194 passed, 7 failed — 4 recovered (transient: Apify x no-hits, brain-LLM see empty responses)

The 7 persistent live failures are external-data conditions, not code: Apify lens actor returning no hits today (4 assertions), chain:btc head tx currently unconfirmed so payload.created is null by design (chain.sh maps status.block_time // null), and one borderline CLIP text×image ranking. The bun binary under test is content-identical to main's (this diff is vscode-lockfile + a unit test only; root lockfile byte-identical after rebase), so those reflect main's current live status, not this PR.

Flake-fix determinism: patched test file green 3×3 isolated runs + full suite green (previously failed the full-suite run).

Follow-up suggestions (not in this PR)


Note

Low Risk
Lockfile-only dependency patches plus a unit-test timing fix; no production runtime or application logic changes.

Overview
Dependency updates (vscode lockfile only): bumps postcss to 8.5.25 and brace-expansion to 5.0.9 within existing semver ranges to address Dependabot/npm audit findings (source map path handling and minimatch DoS).

Test stability: the index add --all backpressure abort test no longer fires AbortController after a fixed 100ms. It waits until wave 0 has written at least one index member (or the run settles), so abort happens during the long between-wave sleep where rejection uses signal.reason, avoiding flaky assert.rejects and wrong member counts under full-suite load.

Reviewed by Cursor Bugbot for commit 836b3fb. Bugbot is set up for automated code reviews on this repo. Configure here.

kdr added 2 commits August 4, 2026 22:17
… /vscode

- postcss 8.5.19 -> 8.5.25: attacker-controlled sourceMappingURL reads
  arbitrary .map files when `from` is unset (GHSA follow-up fix)
- brace-expansion 5.0.8 -> 5.0.9: DoS via unbounded intermediate arrays

Lockfile-only, within existing semver ranges (via @vscode/vsce ->
minimatch and tsup/vite -> postcss). vscode npm audit: 0 vulnerabilities.

NOT addressed (upstream-blocked): root brace-expansion 5.0.7 + undici
8.5.0 are pinned inside @earendil-works/pi-coding-agent's
npm-shrinkwrap.json — overrides/audit fix are silently ignored for
shrinkwrapped subtrees, and even pi-coding-agent 0.83.0 still declares
undici 8.5.0 exactly. Needs an upstream pi release + a reviewed pin
bump.
… test

The 100ms wall-clock abort raced wave 0's child processes under suite
load: landing mid-spawn surfaces node's generic AbortError (reason
demoted to cause) instead of signal.reason, and wave-0 membership may
not be written yet — failing both assertions intermittently (bit this
run and PR #149's CI). Abort once the wave-0 member is visibly written,
when the run is provably inside the 60s between-wave settle sleep whose
abort path rejects with the reason. Bail out early if the run settles
first so a real failure surfaces through assert.rejects instead of an
unhandled rejection + poll-to-deadline.
@kdr
kdr merged commit 56514b5 into main Aug 5, 2026
5 checks passed
@kdr
kdr deleted the dependabot-lockfile-bumps branch August 5, 2026 06:31
@kdr kdr mentioned this pull request Aug 5, 2026
kdr added a commit that referenced this pull request Aug 5, 2026
Patch version bump so the Dependabot lockfile fixes
(#147/#150/#151/#152) ship to npm.

`npm version patch --no-git-tag-version` per RELEASING.md —
`sync-version.mjs` propagated 0.0.15 to `src/version.ts`,
`.claude-plugin/plugin.json`, `.claude-plugin/marketplace.json`, and
`vscode/package.json`+lock (7 files, verified with `sync-version.mjs
--check`).

After merge, cut the tag on main to trigger the npm publish + binary
release train:

```bash
git checkout main && git pull && git tag v0.0.15 && git push origin v0.0.15
```

## Verification

| suite | result |
| --- | --- |
| `npm test` | **1319/1319 pass**, exit 0 |
| `npm run test:e2e` (offline) | **367/367 passed, 0 failed**, exit 0 |
| `node scripts/sync-version.mjs --check` | all surfaces match 0.0.15 |
| `node dist/bin/overcast.js --version --json` |
`{"overcast":"0.0.15","pi":"0.82.1","node":"24.17.0"}` |

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Version-metadata-only bump with no runtime or security logic changes.
> 
> **Overview**
> **Patch release** that bumps the published version from **0.0.14** to
**0.0.15** so recent lockfile/dependency fixes can ship on npm and the
release train.
> 
> The change is limited to synchronized version strings: root
`package.json` / `package-lock.json`, `OVERCAST_VERSION` in
`src/version.ts`, Claude plugin metadata (`plugin.json`,
`marketplace.json`), and the VS Code extension `package.json` /
lockfile. No application logic or behavior changes in this diff.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
2501773. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant