Skip to content

fix(security): remediate open npm Dependabot alerts - #1452

Open
Wassim Chegham (manekinekko) wants to merge 2 commits into
mainfrom
manekinekko-fix-security-npm-dependabot-alerts
Open

Wassim Chegham (manekinekko) wants to merge 2 commits into
mainfrom
manekinekko-fix-security-npm-dependabot-alerts

Conversation

@manekinekko

Copy link
Copy Markdown
Member

Summary

This PR fixes all 91 npm Dependabot alerts that were open on main as of 2026-10-01: 58 in the root pnpm-lock.yaml and 33 in website/.

  • Root: I raised the existing pnpm.overrides floors, keeping overrides scoped per major (undici@5, undici@7, brace-expansion@5, js-yaml@3, …). I also raised direct dependency ranges where the package is a direct dependency: multer in apps/api, postcss and react-router-dom in apps/portal, tar in packages/shared, and vitest at the root and in evaluations/static-prompts. I refreshed the remaining transitive packages with pnpm update -r --depth Infinity, which adds no new overrides. NOTICE is regenerated with pnpm notice.
  • Website: Astro moves from 6 to 7. The astro advisories have no patched 6.x release (first fix is 7.2.8). Starlight and starlight-openapi are raised to compatible versions, and the website overrides are updated for the Vite 8 line.

Alerts resolved

Root (pnpm-lock.yaml)

Package Old New Alerts
undici (v7) 7.28.0 7.29.1 #33 #34 #35 #36 #37 #93 #95 #96 #97 #98 #99 #100 #102 #104 #105
undici (v6, via undici@5 override) 6.27.0 6.28.1 #39 #40 #41 #103
brace-expansion (v2) 2.1.1 2.1.7 #5 #31 #56 #113 #115 #117
brace-expansion (v5) 5.0.6 5.0.12 #3 #116
tar 7.5.16 7.5.22 #7 #8 #9 #10 #15
multer 2.2.0 2.4.0 #70 #82 #83 #84 #92
adm-zip 0.6.0 0.6.1 #73 #91 #106 #111
@grpc/grpc-js 1.14.4 1.14.5 #138 #139
qs 6.15.2 6.16.0 #60 #69
js-yaml (v3) 3.15.0 3.15.2 #45 #87
browserslist 4.28.1 4.29.1 #67 #68
fast-xml-parser 5.9.3 5.11.1 #13
postcss 8.5.19 8.5.28 #53
postcss-selector-parser 6.1.2 6.1.4 #62
react-router (+ react-router-dom) 7.18.0 7.18.4 #44
shell-quote 1.8.4 1.10.0 #6
body-parser 1.20.4 1.20.8 #11
vitest 4.1.0 4.1.11 #81
@vitest/mocker 4.1.0 4.1.11 #74
baseline-browser-mapping 2.9.19 2.11.25 #80
nanoid (root) 3.3.15 3.3.19 none open (#51 and #55 were auto-dismissed). The bare "nanoid": "3.3.15" pin is replaced by "nanoid@3": "^3.3.18", because postcss 8.5.28 requires nanoid ^3.3.18. pnpm audit is now clean.

Website (website/pnpm-lock.yaml, website/package.json)

Package Old New Alerts
astro 6.4.8 7.3.5 #18 #19 #20 #22 #23 #24 #75 #76 #77 #78
sharp 0.34.5 0.35.4 #21 #27 #79 #86
fast-uri 3.1.2 3.1.8 #25 #28 #42 #58 #63 #65 #108
svgo 4.0.1 4.1.0 #26 #71 #72
js-yaml 4.3.0 4.3.2 #46 #88
nanoid 3.3.12 3.3.19 #49 #54
postcss 8.5.16 8.5.28 #29 #52
devalue 5.8.1 5.9.4 #90
smol-toml 1.6.1 1.9.0 #85
postcss-selector-parser 6.1.2 6.1.4 #61

Supporting website changes:

  • @astrojs/starlight 0.39 → 0.42.4 and starlight-openapi 0.25 → 0.26.2. These are the versions compatible with Astro 7.
  • Added @astrojs/markdown-remark as a direct dependency. Astro 7 uses the Sätteri Markdown processor by default, and markdown.remarkPlugins (GFM, base-path, HTTP snippets) only run when the remark pipeline is installed. website/AGENTS.md documents this.
  • website/pnpm-workspace.yaml: the vite override changes from >=7.3.5 <8 to >=8.0.16 <9, because Astro 7 requires Vite 8 and 8.0.16 is the first patched 8.x release. The js-yaml override changes from >=4.2.0 <5 to >=4.3.2 <5.

Alerts that could not be fixed

None. I checked every alert's vulnerable range with semver against the regenerated lockfiles: 91/91 are no longer matched.

  • adm-zip Clean up shared package #73 (GHSA-vwc7-r8mq-g2x9) lists no first_patched_version. Its vulnerable range is >= 0.5.9, <= 0.6.0, so 0.6.1 falls outside it.
  • No major upgrades were deferred. Astro 6 → 7 was required, and the site builds with identical output (see Validation).

Supersedes these open Dependabot PRs

Not closed here:

#736 (uuid 14) is not a security alert and is intentionally untouched.

Notes for reviewers

  • Lockfile entries now use the CFS feed. registry.npmjs.org is blocked on the dev network, so both lockfiles were regenerated through the Microsoft CFS proxy (packagefeedproxy.microsoft.io). CFS metadata exposes only the sha1 shasum, not the sha512 integrity.
    • pnpm therefore rewrote the entries it re-resolved: 174 unchanged-version entries in the root lockfile and 320 in the website lockfile now have sha1 integrity and a 1es-public tarball URL.
    • main already contains 172 entries of this form, and the feed is anonymously readable, so CI installs from it today.
    • If you prefer sha512-only entries, regenerate from an environment with public npm access. The manifests don't need to change.
  • New build warning. Starlight 0.42 on Astro 7 logs The collection "i18n" does not exist or is empty. It's harmless (the site is single-locale) and build output is unaffected.

Validation

Root

  • pnpm install --frozen-lockfile ✅
  • pnpm build ✅
  • pnpm test: 251 files / 3177 tests pass with vitest run --maxWorkers=6 ✅
    • At default concurrency on a heavily loaded shared machine, a few shell-script subprocess tests intermittently hit the 5s timeout or spawnSync ETIMEDOUT. These are scripts/register-agent, install-cli, ensure-dev-certs and build-windows-worker.
    • A different subset failed on each run, and all of them pass in isolation.
  • pnpm lint ⚠️ fails the same way on main: eslint isn't installed, and the CI job is continue-on-error with a TODO. Portal lint passes.
  • pnpm notice:check ✅ (NOTICE regenerated with cargo-about 0.9.1)
  • pnpm audit: no known vulnerabilities ✅

Website

  • pnpm install --frozen-lockfile, pnpm test (7/7), and SITE=https://microsoft.github.io BASE_PATH=/scope pnpm run build all pass: 214 pages ✅
  • Output compared with a build of main: same 214 HTML files and the same counts of tables (26), HTTP-snippet tabs (302), <pre> blocks (839) and content links. Only CSS bundle hashes and names differ.
  • astro dev smoke test: HTTP 200, and the HTTP snippet tabs render ✅
  • pnpm audit: no known vulnerabilities ✅

Bump pnpm override floors (scoped per major) and direct dependency
ranges so every vulnerable package in pnpm-lock.yaml resolves to a
patched release:

- undici@5 -> ^6.28.1, undici@7 -> ^7.29.1
- brace-expansion@5 -> ^5.0.12 (2.x line refreshed to 2.1.7)
- tar ^7.5.21 (packages/shared), multer ^2.4.0 (apps/api + override)
- adm-zip ^0.6.1, @grpc/grpc-js ^1.14.5, qs ^6.16.0, js-yaml@3 ^3.15.2
- fast-xml-parser ^5.10.1, postcss ^8.5.23 (apps/portal + override)
- react-router / react-router-dom ^7.18.2, shell-quote ^1.9.0
- vitest / @vitest/coverage-v8 ^4.1.11
- transitive refresh: body-parser 1.20.8, browserslist 4.29.1,
  baseline-browser-mapping 2.11.25, postcss-selector-parser 6.1.4
- nanoid: replace the bare 3.3.15 pin with nanoid@3 ^3.3.18 (postcss
  8.5.28 requires ^3.3.18)

Regenerate NOTICE for the updated production dependency versions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Upgrade the docs site to Astro 7 (required by the astro advisories,
first patched in 7.2.8) and refresh its transitive dependencies:

- astro ^7.3.5, @astrojs/starlight ^0.42.4, starlight-openapi ^0.26.2
- add @astrojs/markdown-remark: Astro 7 defaults to Satteri and only
  runs markdown.remarkPlugins when the remark pipeline is installed
- sharp ^0.35.4
- overrides: vite >=8.0.16 <9 (Astro 7 requires Vite 8),
  js-yaml >=4.3.2 <5
- transitive refresh: fast-uri 3.1.8, svgo 4.1.0, nanoid 3.3.19,
  postcss 8.5.28, devalue 5.9.4, smol-toml 1.9.0,
  postcss-selector-parser 6.1.4

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot added type: documentation Documentation additions, corrections, and improvements. type: dependencies Dependency additions, removals, and version updates. language: javascript Work involving JavaScript code, tooling, or dependencies. area: portal Scope web portal, pages, and user-facing components. labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Test Results (Node.js 22)

test: Run #172

Tests 📝 Passed ✅ Failed ❌ Skipped ⏭️ Pending ⏳ Other ❓ Flaky 🍂 Duration ⏱️
3177 3177 0 0 0 0 0 1m26s

🎉 All tests passed!

Github Test Reporter

@manekinekko Wassim Chegham (manekinekko) added topic: security Security protections, vulnerabilities, and risk reduction. area: api Scope REST API, run orchestration, SSE streaming, and endpoints. area: shared Shared package: types, DB models, and queue/blob/redis clients used by all apps. area: website Scope documentation website (Astro) under website/. labels Oct 1, 2026
@manekinekko
Wassim Chegham (manekinekko) marked this pull request as ready for review October 1, 2026 19:37
@github-actions github-actions Bot removed the topic: security Security protections, vulnerabilities, and risk reduction. label Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: api Scope REST API, run orchestration, SSE streaming, and endpoints. area: portal Scope web portal, pages, and user-facing components. area: shared Shared package: types, DB models, and queue/blob/redis clients used by all apps. area: website Scope documentation website (Astro) under website/. language: javascript Work involving JavaScript code, tooling, or dependencies. type: dependencies Dependency additions, removals, and version updates. type: documentation Documentation additions, corrections, and improvements.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants