Skip to content

chore(workspace): resolve pnpm audit advisories - #1258

Merged
CalinaCristian merged 1 commit into
mainfrom
fix/audit-prod-2026-09-30
Oct 1, 2026
Merged

CalinaCristian merged 1 commit into
mainfrom
fix/audit-prod-2026-09-30

Conversation

@snuziale

@snuziale snuziale commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Clears pnpm audit --prod (was 1 critical, 2 high, 2 moderate, 1 low) and the dev-dependency advisories that were in #1259, which is folded in here.

Production

Package Change Advisory Approach
next 16.3.4 → 16.3.6 GHSA-vcvr-r3jv-pc5j (critical, RCE in next/og ImageResponse) Direct dep bump in apollo-docs and apollo-vertex
brace-expansion 5.0.9 → 5.0.12 GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr (moderate) Surgical lockfile pin (override added, installed, removed); overrides: unchanged
js-yaml 5.2.2 → 5.4.2 GHSA-r3ph-w7gj-g6xm (moderate) Existing override raised to >=5.4.1
dompurify 3.4.13 → 3.4.16 GHSA-p98j-92pf-mc4p (low) Existing override raised to >=3.4.16

next@16.3.6 and dompurify@3.4.16 are under 14 days old, so both have version-scoped minimumReleaseAgeExclude entries. The @next/* comment is bumped to 16.3.6.

Dev

Package Change Advisories Approach
undici 7.x 7.29.0 → 7.29.1 GHSA-w293-vg96-wgc3, GHSA-rfgv-xxqx-mfg5 (high); 3wwx, pmjh, 3xpg, 2jfj, rx4f (moderate); r53p, 2gqq, 8436 (low) Surgical pin. The parent @semantic-release/github uses ^7.0.0
undici 6.x 6.28.0 → 6.28.1 GHSA-rfgv-xxqx-mfg5 (high), GHSA-3wwx-pv8p-q78v (moderate), GHSA-r53p-7pc4-xj5r (low) Surgical pin. The parent @actions/http-client uses ^6.23.0
ip-address 10.3.1 → 10.7.2 GHSA-rpw4-54j3-4h4q, GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw (moderate) Surgical pin. The parent express-rate-limit uses ^10.2.0
fast-uri 3.1.6 → 3.1.8 GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj (moderate) Existing override raised to ^3.1.8

A surgical pin means adding a temporary override, installing, removing the override and installing again ("Already up to date"). The resulting overrides: block differs only in the fast-uri line. All versions are older than 14 days, so no quarantine exemptions are needed.

Supply-chain vetting (2026-09-30)

  • next 16.3.6: OIDC provenance (same as 16.3.4). Release v16.3.6 by eps1lon cites the advisory; the fix commit is 868fad3 "Harden next/og SVG serialization" and the rest are 16.3.x backports. Deps unchanged apart from @next/env.
  • brace-expansion 5.0.12: publisher juliangruber (unchanged). Tags v5.0.10 to v5.0.12 are the 3 GHSA fork merges plus dependabot bumps, touching src/index.ts and tests. Deps unchanged.
  • js-yaml 5.4.2: publisher vitaly (unchanged). The fix is feat(apollo-react): add Optional and Ends case status badges to StageNode header #797 in 5.4.1; 5.4.2 only adds a forceQuotes fix (docs(apollo-vertex): add intro to Adding a New Component #798). Deps unchanged.
  • dompurify 3.4.16: publisher cure53 (unchanged). src/purify.ts +62/-5 adds the _handleHookDetachedNode checks the advisory describes. The build moved from rollup to rolldown, which is why dist/ churns. No new runtime deps.
  • undici 6.28.1 / 7.29.1: OIDC provenance on both old and new versions, and every commit is by mcollina. The v7.29.1 release notes map each GHSA to its fix commit. 6.28.1 carries the 3 backports relevant to 6.x plus 2 perf backports. No dependencies.
  • fast-uri 3.1.8: published by matteo.collina, same as 3.1.6 (the 3.x line has never had provenance). It contains the 3.x backports (feat(apollo-vertex): update status tokens [AGVSOL-1019] #214, feat(apollo-vertex): setup registry theme [AGVSOL-1201] #216, c88b59e) in index.js and lib/utils.js, with tests. No dependencies.
  • ip-address 10.7.2: OIDC provenance, sole maintainer beaugunderson. This is a larger jump because the fixes landed on top of the 10.4 to 10.7 feature minors (isGlobal, offset/nextNetwork, IANA classifiers). All 26 commits are by the maintainer, including the 4 fork-merge GHSA fixes; 10.7.2 only adds a fromArpa fix. No dependencies.
  • The lockfile integrity for each package matches npm view.

Lockfile scope

Outside the eight target packages, the only changes are pnpm dedupes onto versions already in the lockfile: @swc/helpers 0.5.19 → 0.5.23 (rspack peer) and one semver 7.7.4 → 7.8.5 (make-dir). No new packages.

Test plan

  • pnpm audit --prod: no known vulnerabilities
  • pnpm check:dependencies: passes
  • CI: build / docs apps / release tooling (semantic-release, commitlint)

Not in this PR

A new moderate advisory for hono (<4.13.7, hono/jsx unescaped strings) was published after this work started. It still fails the full pnpm audit and will follow separately.

🤖 Generated with Claude Code

Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:59
@snuziale
snuziale requested a review from a team as a code owner September 30, 2026 21:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Apollo Coded App preview deployments are ready.

Project Status Preview Updated (PT)
apollo-design Ready Preview · Logs Oct 01, 2026, 10:36:44 AM
apollo-docs Ready Preview · Logs Oct 01, 2026, 10:36:44 AM
apollo-landing Ready Preview · Logs Oct 01, 2026, 10:36:44 AM
apollo-vertex Ready Preview · Logs Oct 01, 2026, 10:36:44 AM

@github-actions github-actions Bot added app:apollo-vertex size:L 100-499 changed lines. labels Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency License Review

  • ✅ 1937 package(s) scanned
  • ✅ No license issues found
  • ⚠️ 2 package(s) excluded (see details below)
License distribution
License Packages
MIT 1708
ISC 88
Apache-2.0 55
BSD-3-Clause 27
BSD-2-Clause 23
BlueOak-1.0.0 8
MPL-2.0 4
MIT-0 3
CC0-1.0 3
MIT OR Apache-2.0 2
(MIT OR Apache-2.0) 2
Unlicense 2
LGPL-3.0-or-later 1
Python-2.0 1
CC-BY-4.0 1
(MPL-2.0 OR Apache-2.0) 1
Unknown 1
Artistic-2.0 1
(WTFPL OR MIT) 1
(BSD-2-Clause OR MIT OR Apache-2.0) 1
CC-BY-3.0 1
0BSD 1
(MIT OR CC0-1.0) 1
MIT AND ISC 1
Excluded packages
Package Version License Reason
@img/sharp-libvips-linux-x64 1.3.3 LGPL-3.0-or-later LGPL pre-built binary, not linked
khroma 2.1.0 Unknown MIT per GitHub repo, missing license field in package.json

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Storybook visual diff

✅ No stories are affected by this PR's changes; nothing to compare. Logs

Updated (PT): Oct 01, 2026, 10:38:23 AM

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

📊 Coverage + size by package

Per-package bundle size on this PR (no JS/TS source changes detected under packages/* or web-packages/*).

Package Coverage New-line coverage Packed (gzip) Unpacked vs main
@uipath/apollo-core 75.0% — 42.01 MB 50.16 MB —
@uipath/apollo-react 48.3% — 7.78 MB 30.31 MB —
@uipath/apollo-ui-icons — — 2.86 MB 6.96 MB —
@uipath/apollo-wind 70.0% — 552.8 KB 3.36 MB —
@uipath/ap-chat 85.8% — 43.90 MB 56.64 MB —

"Coverage" is each package's own coverage.include scope (e.g. apollo-core instruments only scripts/). "Packed"/"Unpacked" come from npm pack --dry-run and only cover built packages — "—" means not measured this run (package not affected / not built). "vs main" is the packed (gzipped) delta against the last successful main build (the package-sizes artifact from the Release workflow); "—" there means no main baseline was available this run. The baseline is main's latest build, not this PR's exact merge-base, so it includes any drift since the branch diverged. Packages with no vitest config are omitted.

@snuziale
snuziale added this pull request to stack #1260 October 1, 2026 00:25
Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:50
@snuziale
snuziale force-pushed the fix/audit-prod-2026-09-30 branch from 6a72761 to 8bfbd82 Compare October 1, 2026 16:50

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-sensitive dependency updates still require successful CI and registry signature checks before approval.

Review effort: Balanced
Findings: None

Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

Production:
- next 16.3.4 -> 16.3.6 (apollo-docs, apollo-vertex): GHSA-vcvr-r3jv-pc5j
  (critical, RCE in next/og ImageResponse)
- brace-expansion 5.0.9 -> 5.0.12 (surgical lockfile pin, no override):
  GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr (moderate)
- js-yaml override >=5.4.1 (resolves 5.4.2): GHSA-r3ph-w7gj-g6xm (moderate)
- dompurify override >=3.4.16: GHSA-p98j-92pf-mc4p (low)

Dev:
- undici 7.29.0 -> 7.29.1 (via @semantic-release/github, ^7.0.0): GHSA-w293-vg96-wgc3,
  GHSA-rfgv-xxqx-mfg5 (high) + 3wwx/pmjh/3xpg/2jfj/rx4f (moderate) + r53p/2gqq/8436 (low)
- undici 6.28.0 -> 6.28.1 (via @actions/http-client, ^6.23.0): GHSA-rfgv-xxqx-mfg5 (high),
  GHSA-3wwx-pv8p-q78v (moderate), GHSA-r53p-7pc4-xj5r (low)
- ip-address 10.3.1 -> 10.7.2 (via express-rate-limit, ^10.2.0): GHSA-rpw4-54j3-4h4q,
  GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw (moderate)
- fast-uri override ^3.1.6 -> ^3.1.8 (resolves 3.1.8): GHSA-qw65-cvwx-89v3,
  GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj (moderate)

Version-scoped quarantine exemptions for next@16.3.6 and dompurify@3.4.16
(both < 14 days); all other versions > 14 days old. undici, ip-address and
brace-expansion use the surgical pin; parent ranges hold the patched
versions. All vetted 2026-09-30: publisher unchanged, tag + diff match
advisories, no new deps, lockfile integrity matches registry. Lockfile also
dedupes @swc/helpers 0.5.19->0.5.23 and one semver 7.7.4->7.8.5 onto
versions already locked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 17:24
@snuziale
snuziale force-pushed the fix/audit-prod-2026-09-30 branch from 8bfbd82 to 66aafce Compare October 1, 2026 17:24
@snuziale snuziale changed the title chore(workspace): resolve pnpm audit --prod advisories chore(workspace): resolve pnpm audit advisories Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Production and release-tooling dependency updates require successful pending CI and final human supply-chain verification.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

Comment thread pnpm-workspace.yaml
@CalinaCristian
CalinaCristian merged commit 20f4748 into main Oct 1, 2026
55 of 57 checks passed
@CalinaCristian
CalinaCristian deleted the fix/audit-prod-2026-09-30 branch October 1, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app:apollo-vertex size:L 100-499 changed lines.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants