Skip to content

chore(workspace): resolve remaining pnpm audit dev-dependency advisories - #1259

Closed
snuziale wants to merge 2 commits into
fix/audit-prod-2026-09-30from
fix/audit-dev-2026-09-30
Closed

snuziale wants to merge 2 commits into
fix/audit-prod-2026-09-30from
fix/audit-dev-2026-09-30

Conversation

@snuziale

@snuziale snuziale commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #1258. With both PRs merged, the full pnpm audit (dev deps included) exits 0.

Package Change Advisories Approach
undici 7.x 7.29.0 → 7.29.1 GHSA-w293-vg96-wgc3, GHSA-rfgv-xxqx-mfg5 (high); 3wwx, pmjh, 3xpg, 2jfj, rx4f (moderate); r53p, 2gqq, 8436 (low) Surgical pin. The parent @semantic-release/github uses ^7.0.0
undici 6.x 6.28.0 → 6.28.1 GHSA-rfgv-xxqx-mfg5 (high), GHSA-3wwx-pv8p-q78v (moderate), GHSA-r53p-7pc4-xj5r (low) Surgical pin. The parent @actions/http-client uses ^6.23.0
ip-address 10.3.1 → 10.7.2 GHSA-rpw4-54j3-4h4q, GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw (moderate) Surgical pin. The parent express-rate-limit uses ^10.2.0
fast-uri 3.1.6 → 3.1.8 GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj (moderate) Existing override raised to ^3.1.8

A surgical pin means adding a temporary override, installing, removing the override and installing again ("Already up to date"). The resulting overrides: block differs only in the fast-uri line. All versions are older than 14 days, so no quarantine exemptions are needed.

Supply-chain vetting (2026-09-30)

  • undici 6.28.1 / 7.29.1: OIDC provenance on both old and new versions, and every commit is by mcollina. The v7.29.1 release notes map each GHSA to its fix commit. 6.28.1 carries the 3 backports relevant to 6.x plus 2 perf backports. No dependencies.
  • fast-uri 3.1.8: published by matteo.collina, same as 3.1.6 (the 3.x line has never had provenance). It contains the 3.x backports (feat(apollo-vertex): update status tokens [AGVSOL-1019] #214, feat(apollo-vertex): setup registry theme [AGVSOL-1201] #216, c88b59e) in index.js and lib/utils.js, with tests. No dependencies.
  • ip-address 10.7.2: OIDC provenance, sole maintainer beaugunderson. This is a larger jump because the fixes landed on top of the 10.4 to 10.7 feature minors (isGlobal, offset/nextNetwork, IANA classifiers). All 26 commits are by the maintainer, including the 4 fork-merge GHSA fixes; 10.7.2 only adds a fromArpa fix. No dependencies.
  • The lockfile integrity for each package matches npm view.

Lockfile scope

36 lines change, and every one is one of the four target packages. Nothing else moved.

Test plan

  • pnpm audit: no known vulnerabilities
  • pnpm check:dependencies: passes
  • CI green (affects release tooling: semantic-release / commitlint; ip-address reaches apollo-vertex through shadcn's MCP SDK)

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Dependency License Review

  • ✅ 1937 package(s) scanned
  • ✅ No license issues found
  • ⚠️ 2 package(s) excluded (see details below)
License distribution
License Packages
MIT 1708
ISC 88
Apache-2.0 55
BSD-3-Clause 27
BSD-2-Clause 23
BlueOak-1.0.0 8
MPL-2.0 4
MIT-0 3
CC0-1.0 3
MIT OR Apache-2.0 2
(MIT OR Apache-2.0) 2
Unlicense 2
LGPL-3.0-or-later 1
Python-2.0 1
CC-BY-4.0 1
(MPL-2.0 OR Apache-2.0) 1
Unknown 1
Artistic-2.0 1
(WTFPL OR MIT) 1
(BSD-2-Clause OR MIT OR Apache-2.0) 1
CC-BY-3.0 1
0BSD 1
(MIT OR CC0-1.0) 1
MIT AND ISC 1
Excluded packages
Package Version License Reason
@img/sharp-libvips-linux-x64 1.3.3 LGPL-3.0-or-later LGPL pre-built binary, not linked
khroma 2.1.0 Unknown MIT per GitHub repo, missing license field in package.json

@snuziale
snuziale added this pull request to stack #1260 October 1, 2026 00:25
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

📊 Coverage + size by package

Per-package bundle size on this PR (no JS/TS source changes detected under packages/* or web-packages/*).

Package Coverage New-line coverage Packed (gzip) Unpacked vs main
@uipath/apollo-core 75.0% — 42.01 MB 50.16 MB ±0
@uipath/apollo-react 48.3% — 7.78 MB 30.31 MB ±0
@uipath/apollo-ui-icons — — 2.86 MB 6.96 MB ±0
@uipath/apollo-wind 70.0% — 552.8 KB 3.36 MB +25 B
@uipath/ap-chat 85.8% — 43.90 MB 56.64 MB ±0

"Coverage" is each package's own coverage.include scope (e.g. apollo-core instruments only scripts/). "Packed"/"Unpacked" come from npm pack --dry-run and only cover built packages — "—" means not measured this run (package not affected / not built). "vs main" is the packed (gzipped) delta against the last successful main build (the package-sizes artifact from the Release workflow); "—" there means no main baseline was available this run. The baseline is main's latest build, not this PR's exact merge-base, so it includes any drift since the branch diverged. Packages with no vitest config are omitted.

snuziale and others added 2 commits October 1, 2026 09:50
- next 16.3.4 -> 16.3.6 (apollo-docs, apollo-vertex): GHSA-vcvr-r3jv-pc5j
  (critical, RCE in next/og ImageResponse)
- brace-expansion 5.0.9 -> 5.0.12 (surgical lockfile pin, no override):
  GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr (moderate)
- js-yaml override >=5.4.1 (resolves 5.4.2): GHSA-r3ph-w7gj-g6xm (moderate)
- dompurify override >=3.4.16: GHSA-p98j-92pf-mc4p (low)

Version-scoped quarantine exemptions for next@16.3.6 and dompurify@3.4.16
(both < 14 days). All four vetted 2026-09-30: publisher unchanged,
tag + diff match advisory, no new deps, lockfile integrity matches registry.
Lockfile also dedupes @swc/helpers 0.5.19->0.5.23 and one semver
7.7.4->7.8.5 onto versions already locked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- undici 7.29.0 -> 7.29.1 (via @semantic-release/github, ^7.0.0): GHSA-w293-vg96-wgc3,
  GHSA-rfgv-xxqx-mfg5 (high) + 3wwx/pmjh/3xpg/2jfj/rx4f (moderate) + r53p/2gqq/8436 (low)
- undici 6.28.0 -> 6.28.1 (via @actions/http-client, ^6.23.0): GHSA-rfgv-xxqx-mfg5 (high),
  GHSA-3wwx-pv8p-q78v (moderate), GHSA-r53p-7pc4-xj5r (low)
- ip-address 10.3.1 -> 10.7.2 (via express-rate-limit, ^10.2.0): GHSA-rpw4-54j3-4h4q,
  GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw (moderate)
- fast-uri override ^3.1.6 -> ^3.1.8 (resolves 3.1.8): GHSA-qw65-cvwx-89v3,
  GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj (moderate)

undici and ip-address use the surgical pin (override, install, remove,
install); parent caret ranges hold the patched versions and overrides: is
unchanged for them. All versions > 14 days old, no quarantine exemptions.
Vetted 2026-09-30: publisher unchanged, tag + diff match advisories, no new
deps, lockfile integrity matches registry.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:50
@snuziale
snuziale force-pushed the fix/audit-dev-2026-09-30 branch from 3fce792 to dab7fa9 Compare October 1, 2026 16:50
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Apollo Coded App preview deployments are ready.

Project Status Preview Updated (PT)
apollo-design Ready Preview · Logs Oct 01, 2026, 10:00:03 AM
apollo-docs Ready Preview · Logs Oct 01, 2026, 10:00:03 AM
apollo-landing Ready Preview · Logs Oct 01, 2026, 10:00:03 AM
apollo-vertex Ready Preview · Logs Oct 01, 2026, 10:00:03 AM

@github-actions github-actions Bot added the size:M 30-99 changed lines. label Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Supply-chain dependency updates require final human confirmation of package vetting and successful CI.

Review effort: Balanced
Findings: None

What changed in this PR

Updates audited transitive development dependencies, complementing #1258 to clear remaining pnpm audit advisories.

Changes:

  • Raises the fast-uri security override to ^3.1.8.
  • Surgically updates vulnerable fast-uri, ip-address, and undici lockfile resolutions.
File Description
pnpm-workspace.yaml Raises and documents the vetted fast-uri override.
pnpm-lock.yaml Pins the four targeted secure dependency versions.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@snuziale
snuziale requested a review from a team as a code owner October 1, 2026 17:24
@snuziale

snuziale commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Folded into #1258 as a single squashed commit.

@snuziale snuziale closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M 30-99 changed lines.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants