Skip to content

fix(deps): clear shipped-closure advisories (brace-expansion, fast-uri, axios) - #5906

Merged
Astro-Han merged 3 commits into
apache:mainfrom
liugddx:fix/shipped-advisories
Oct 2, 2026
Merged

Astro-Han merged 3 commits into
apache:mainfrom
liugddx:fix/shipped-advisories

Conversation

@liugddx

@liugddx liugddx commented Oct 1, 2026

Copy link
Copy Markdown
Member

Fixes #5905.

The shipped-dependency audit and the CLI tarball audit are failing on every PR. This PR clears every advisory that reaches the shipped closure, and keeps check:release green.

Changes

Verification (local, against registry.npmjs.org)

  • Shipped-closure audit: node scripts/audit-shipped-dependencies.mjs reports advisories reaching it at moderate or above: 0. Before this PR it reported axios.
  • CLI production audit: npm audit --omit=dev --workspace maka-agent, the same command release-cli-package.mjs runs, reports total 0.
  • Notices: check:third-party-notices and check:cli-third-party-notices both pass.
  • Release tests: check:release passes 212/214. The two failures are Windows-only fixture errors (EBUSY on rmdir, Git fixture setup) in tests unrelated to dependencies.
  • Runtime: npm run build passes. The runtime bot tests pass 107/109; the two proxiedFetch streaming failures are identical on main. Lark and WeCom SDKs load with axios 1.20.0.

If this merges, #5881 and #5882 become redundant; Dependabot should close them on its own once main carries these versions. #5883 (the Eval harness toolchain lockfile) is outside the shipped closure and isn't touched here.

AI use

Diagnosed and prepared with Claude Code. The Dependabot commits are unchanged; the axios/notices commit carries a Co-Authored-By trailer.

🤖 Generated with Claude Code

dependabot Bot and others added 3 commits October 1, 2026 19:24
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.9 to 5.0.12.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.7 to 3.1.8.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.7...v3.1.8)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
The shipped-dependency audit fails on main because advisories now reach the
product closure:
- brace-expansion@5.0.9 (high)
- fast-uri@3.1.7 (moderate)
- axios@1.18.1 (high, several advisories fixed in 1.20.0)

The two Dependabot bumps (apache#5881, apache#5882) each fix only one advisory, so
each still fails the audit on the other one. Neither regenerates the
third-party notices, so `check:release` also rejects them.

Take both bumps, move the transitive axios to 1.20.0 within its existing
`^1.x` ranges (used by @larksuiteoapi/node-sdk and @wecom/aibot-node-sdk),
and regenerate the desktop and CLI third-party notices with the pinned npm
(11.19.0).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the effort/XS Under 10 readable lines label Oct 1, 2026

@Astro-Han Astro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 07eaa3aa306de43028f61dec264baf7572232161 (3 files, +16/−16). The purpose is to clear the shipped-closure advisories that have been making audit red on every PR.

No P0–P3 findings.

What the diff does. brace-expansion 5.0.9 → 5.0.12, fast-uri 3.1.7 → 3.1.8, and axios 1.18.1 → 1.20.0 reachable transitively through the Lark and WeCom SDKs. The lockfile change is confined to those packages — version, resolved, integrity, and axios's form-data range ^4.0.5 → ^4.0.6 — and both THIRD_PARTY_NOTICES.txt files are regenerated for exactly the same three packages.

I checked the security claim against the registry rather than against the description. Querying npm's bulk advisory endpoint for both the old and the new versions of each package:

  • axios: twelve advisories (seven rated high, five moderate) whose vulnerable ranges all terminate at <1.20.0. 1.18.1 therefore sits inside every one of them, and 1.20.0 sits outside all twelve.
  • brace-expansion: three advisories with thresholds <5.0.10, <5.0.11 and <5.0.12. 5.0.9 is affected by all three; 5.0.12 is outside all three, i.e. exactly the strictest patched version.
  • fast-uri: one moderate advisory, >=3.0.0 <3.1.8. 3.1.7 is affected; 3.1.8 is not.
  • form-data 4.0.6: no advisory, which is consistent with the lockfile not moving that entry.

So each bump lands exactly on or above the patched threshold for the advisories it is meant to clear, and no bump exceeds what that requires.

The lockfile-only shape is consistent with the claim that both consumers declare ^1.x. No package.json is touched, and the notice files change for precisely the three bumped packages — there is no form-data entry, which is correct because its locked version did not move. Only three files changed in total, so nothing unrelated is mixed into a dependency-version fix.

Gate on this head: audit is green — the check that was failing across the repository — together with test, package, windows_recovery, owner, label and the installed-CLI validations. The merge state is blocked, which I read as review still pending rather than as a verdict. The two Dependabot commits are carried unchanged, so their own provenance is untouched.

What I could not judge

  • I did not run the repository's own audit or test suites, so the body's "the two proxiedFetch streaming failures are identical on main" and the two Windows-only fixture failures are taken as declared rather than reproduced.
  • I did not exercise the Lark or WeCom SDKs against axios 1.20.0.

I did not approve, request changes, or merge.


Automated review notice: This comment was posted by an automated review agent operated by Astro-Han. It is not an independent human review and does not replace one.

@Astro-Han

Copy link
Copy Markdown
Contributor

Thanks @liugddx — bundling the two Dependabot bumps with the axios update and regenerated notices clears the audit for everyone. Merging now.

@Astro-Han Astro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at @Astro-Han's explicit request: a focused dependency fix; the automated review of this head verified each bump against the registry advisories and found no issues, and CI (including audit) is green.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/XS Under 10 readable lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(deps): shipped-dependency audit fails on brace-expansion, fast-uri and axios advisories

2 participants