chore(deps): clear 108 Dependabot alerts across docs, canary, and examples - #476
kylehounslow merged 13 commits into
Conversation
Clears GHSA alerts in docs/package-lock.json by raising direct/override floors so the fresh lockfile no longer resolves vulnerable versions: - astro ^7.1.1 -> ^7.2.8 (GHSA-26w7-cxv4-gfx2 critical, GHSA-376h-93r7-7g6f) - undici override ^7.24.0 -> ^7.29.1 (resolves 7.30.0; clears 10 undici GHSAs) - sharp override ^0.35.0 -> ^0.35.4 (GHSA-rgj7-g3m4-5g8c) - vitest/@vitest/* ^4.0.18 -> ^4.1.11 (GHSA-82fw-gwwq-j7x9) Transitive devalue 5.9.4, js-yaml 4.3.2, svgo 4.1.0 float to patched. Build: 148 pages built. Tests: 557 passed (28 files). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
Fresh lockfile floats transitive and direct deps to patched versions, no package.json change needed (all within existing caret ranges): astro 7.3.5, undici 8.11.2, devalue 5.9.4, js-yaml 4.3.2, sharp 0.35.5, svgo 4.1.0, dompurify 3.4.16. Clears the critical astro GHSA-26w7-cxv4-gfx2 plus undici/devalue/js-yaml/sharp/svgo/dompurify advisories. Build: astro build Complete (clean dist). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
Clears GHSA-ch52-4w7c-c8xp (range <= 4.2.0) in docs/ and docs/starlight-docs/. Transitive via astro (^4.2.0). Lockfile-only. Upstream closed the report as not a vulnerability (RFC 9111 7.3) and 4.3.0 has no max-stale change, so this clears the alert by range only. Build: docs/ and starlight-docs 148 pages each; docs/ npm test 557 passed. Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
Clears GHSA-8988-9cw3-xx77, GHSA-vxq7-64xx-v4gw, GHSA-gh4c-6fx4-qh6g. Lockfile-only. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
aiohttp 3.14.3, anyio 4.14.2, cryptography 50.0.2, pyjwt 2.15.1, soupsieve 2.10, urllib3 2.8.0. Clears 26 Dependabot alerts. Lockfile-only. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
anyio 4.14.2, urllib3 2.8.0. Clears 5 Dependabot alerts. Lockfile-only. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
anyio 4.14.2, urllib3 2.8.0. Clears 5 Dependabot alerts. Lockfile-only. uv sync --locked passes (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
cryptography 50.0.2, pyjwt 2.15.1, urllib3 2.8.0. Clears 17 Dependabot alerts. Lockfile-only. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #476 +/- ##
=======================================
Coverage 55.62% 55.62%
=======================================
Files 4 4
Lines 169 169
Branches 48 47 -1
=======================================
Hits 94 94
Misses 74 74
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
…ultidict strands-agents-tools 0.2.22 -> 0.8.9 (CVE-2026-18394, CVE-2026-15746, CVE-2026-78379, CVE-2026-18733, CVE-2026-19111), multidict 6.7.1 -> 6.9.1 (CVE-2026-104874), click 8.3.1 -> 8.5.0 (CVE-2026-7246). Flagged by the Mend check. Lockfile-only; strands-agents-evals 0.1.15 allows tools <1.0.0. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
langgraph-sdk 0.4.2 -> 0.4.5 (CVE-2026-104873, fixed in 0.4.4). Flagged by the Mend check. Lockfile-only. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
|
Pushed 2 more commits to clear the Mend findings that have a fix available:
Both are lockfile-only. strands-agents-evals 0.1.15 already allows strands-agents-tools <1.0.0, so no direct dep changes. Mend will still fail on the rest. All of these are on main today, and none have a fix this repo can pick up without an override:
The Mend summary reports "Base branch total remaining vulnerabilities: 0", even though main has these same versions, so it labels all of them as new to this PR. Happy to add overrides for katex and postcss-selector-parser if you'd rather have Mend green. Both would force a version outside the range the parent declares, so I'd rather wait for mermaid and expressive-code to bump. |
click 8.3.1 -> 8.5.0 (CVE-2026-7246), transitive via uvicorn. Flagged by the Mend check. Lockfile-only. uv sync --locked passes (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
multidict 6.7.1 -> 6.9.1 (CVE-2026-104874), transitive via aiohttp. Flagged by the Mend check. Lockfile-only. uv sync --locked and import check pass (python 3.12). Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
|
Correction to my last comment: the click and multidict CVEs also showed up in two other examples, so they were still open after that push. 2 more commits fix them:
Both are lockfile-only, and |
katex ^0.18.2 (CVE-2026-103923; resolves 0.18.10, mermaid pins ^0.16.47) and postcss-selector-parser ^7.1.6 (CVE-2026-104844; postcss-nested 6.x pins ^6.1.1). Both are outside the range the parent declares. No page uses mermaid math, so katex is not exercised at build or render time. Build output is unchanged apart from mermaid chunk hashes; CSS is byte-identical. Build: 148 pages. Signed-off-by: Kyle Hounslow <kylehounslow@users.noreply.github.com>
|
Pushed one more commit for the two docs findings: overrides in docs/starlight-docs for katex Both versions are outside what the parent declares. mermaid pins katex
Mend should now flag only brace-expansion (bundled in aws-cdk-lib, aws/aws-cdk#38932) and zod (no release covers it yet; 4.6.5 is the latest). Both are already on main. I can drop the override commit if you'd rather wait for mermaid and expressive-code to move. |
|
Some mend findings still remain but let's get them as follow-up instead: https://github.com/opensearch-project/observability-stack/pull/476/checks?check_run_id=111941813929 |
|
Mend check is still failing should we also add these? |
What
Clears 108 of the 111 open Dependabot alerts on
main. Every change is lockfile-level or a within-major floor bump, so no breaking upgrade. The remaining 3 (aws/cdk brace-expansion) are bundled inside aws-cdk-lib and blocked upstream on aws/aws-cdk#38932.Fix
One commit per manifest.
docs/ (26): raised direct and override floors: astro
^7.1.1->^7.2.8(critical GHSA-26w7-cxv4-gfx2, GHSA-376h-93r7-7g6f), undici override^7.24.0->^7.29.1(10 advisories), sharp override^0.35.0->^0.35.4, vitest / @vitest/*^4.0.18->^4.1.11. Transitives devalue 5.9.4, js-yaml 4.3.2, svgo 4.1.0 float to patched.docs/starlight-docs/ (26): lockfile-only: astro 7.3.5, undici 8.11.2, devalue 5.9.4, js-yaml 4.3.2, sharp 0.35.5, svgo 4.1.0, dompurify 3.4.16.
http-cache-semantics 4.2.0 -> 4.3.0, both docs lockfiles (GHSA-ch52-4w7c-c8xp): this clears the alert by version range only. The maintainer closed the report as not a vulnerability (kornelski/http-cache-semantics#56, citing RFC 9111 section 7.3) and 4.3.0 doesn't change max-stale handling. The starlight-docs entry is a single-package lockfile edit, because a full
npm updatethere prunes the optional peer@astrojs/markdown-remark, which the build needs.docker-compose/agent-eval-canary (3): urllib3 2.8.0.
examples/ (53), lockfile-only:
Validation
vulnerable_version_rangeentries in its GHSA advisory. On this branch the only versions still in range are the 3 aws/cdk brace-expansion ones.npm ciclean,npm run build148 pages,npm test557 passed (28 files)npm ciclean,npm run build148 pages on a clean distuv sync --lockedpasses and every imported module loads (python:3.12-slim). weather-agent importsboto3andhttpxwithout declaring them in pyproject.toml. That's already the case on main and this PR doesn't touch it.The 108 cleared alerts also cover the bumps in these open Dependabot PRs: #406, #446, #447, #449, #451, #452, #454, #455, #458, #459, #460, #461, #462, #468, #469, #472, #473, #475, #386, #389, #392. Two of those stop short of the patched floor: #458 (devalue 5.9.2) and #406 (dompurify 3.4.13). This PR also supersedes #402.
The docs/ lockfile was regenerated with npm 11, because npm 10.9.x crashes with an
edgesOuterror when it hits theoverridesblock. The lockfile is lockfileVersion 3 andnpm ciinstalls it cleanly under npm 10.