fix(deps): clear shipped-closure advisories (brace-expansion, fast-uri, axios) - #5906
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.9 to 5.0.12. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.7 to 3.1.8. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.7...v3.1.8) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
The shipped-dependency audit fails on main because advisories now reach the product closure: - brace-expansion@5.0.9 (high) - fast-uri@3.1.7 (moderate) - axios@1.18.1 (high, several advisories fixed in 1.20.0) The two Dependabot bumps (apache#5881, apache#5882) each fix only one advisory, so each still fails the audit on the other one. Neither regenerates the third-party notices, so `check:release` also rejects them. Take both bumps, move the transitive axios to 1.20.0 within its existing `^1.x` ranges (used by @larksuiteoapi/node-sdk and @wecom/aibot-node-sdk), and regenerate the desktop and CLI third-party notices with the pinned npm (11.19.0). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Astro-Han
left a comment
There was a problem hiding this comment.
Reviewed 07eaa3aa306de43028f61dec264baf7572232161 (3 files, +16/−16). The purpose is to clear the shipped-closure advisories that have been making audit red on every PR.
No P0–P3 findings.
What the diff does. brace-expansion 5.0.9 → 5.0.12, fast-uri 3.1.7 → 3.1.8, and axios 1.18.1 → 1.20.0 reachable transitively through the Lark and WeCom SDKs. The lockfile change is confined to those packages — version, resolved, integrity, and axios's form-data range ^4.0.5 → ^4.0.6 — and both THIRD_PARTY_NOTICES.txt files are regenerated for exactly the same three packages.
I checked the security claim against the registry rather than against the description. Querying npm's bulk advisory endpoint for both the old and the new versions of each package:
axios: twelve advisories (seven rated high, five moderate) whose vulnerable ranges all terminate at<1.20.0. 1.18.1 therefore sits inside every one of them, and 1.20.0 sits outside all twelve.brace-expansion: three advisories with thresholds<5.0.10,<5.0.11and<5.0.12. 5.0.9 is affected by all three; 5.0.12 is outside all three, i.e. exactly the strictest patched version.fast-uri: one moderate advisory,>=3.0.0 <3.1.8. 3.1.7 is affected; 3.1.8 is not.form-data4.0.6: no advisory, which is consistent with the lockfile not moving that entry.
So each bump lands exactly on or above the patched threshold for the advisories it is meant to clear, and no bump exceeds what that requires.
The lockfile-only shape is consistent with the claim that both consumers declare ^1.x. No package.json is touched, and the notice files change for precisely the three bumped packages — there is no form-data entry, which is correct because its locked version did not move. Only three files changed in total, so nothing unrelated is mixed into a dependency-version fix.
Gate on this head: audit is green — the check that was failing across the repository — together with test, package, windows_recovery, owner, label and the installed-CLI validations. The merge state is blocked, which I read as review still pending rather than as a verdict. The two Dependabot commits are carried unchanged, so their own provenance is untouched.
What I could not judge
- I did not run the repository's own audit or test suites, so the body's "the two
proxiedFetchstreaming failures are identical onmain" and the two Windows-only fixture failures are taken as declared rather than reproduced. - I did not exercise the Lark or WeCom SDKs against
axios1.20.0.
I did not approve, request changes, or merge.
Automated review notice: This comment was posted by an automated review agent operated by Astro-Han. It is not an independent human review and does not replace one.
|
Thanks @liugddx — bundling the two Dependabot bumps with the axios update and regenerated notices clears the audit for everyone. Merging now. |
Astro-Han
left a comment
There was a problem hiding this comment.
Approved at @Astro-Han's explicit request: a focused dependency fix; the automated review of this head verified each bump against the registry advisories and found no issues, and CI (including audit) is green.
Fixes #5905.
The shipped-dependency
auditand the CLI tarball audit are failing on every PR. This PR clears every advisory that reaches the shipped closure, and keepscheck:releasegreen.Changes
brace-expansion5.0.9 → 5.0.12 (chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 #5881) andfast-uri3.1.7 → 3.1.8 (chore(deps): bump fast-uri from 3.1.7 to 3.1.8 #5882). Each of those PRs fails on its own (see ci(deps): shipped-dependency audit fails on brace-expansion, fast-uri and axios advisories #5905), so they need to land together.axios1.18.1 → 1.20.0, transitive via@larksuiteoapi/node-sdkand@wecom/aibot-node-sdk. Both declare^1.x, so nopackage.jsonchanges. The lockfile diff is 4 lines: the version, resolved and integrity ofaxios, and itsform-datarange (^4.0.6, already the locked version).THIRD_PARTY_NOTICES.txtfor desktop and CLI. This was the step Dependabot can't do. The lockfile update and the notice generation both used the pinned npm 11.19.0, so the lockfile keeps itslibcfields.Verification (local, against registry.npmjs.org)
node scripts/audit-shipped-dependencies.mjsreportsadvisories reaching it at moderate or above: 0. Before this PR it reportedaxios.npm audit --omit=dev --workspace maka-agent, the same commandrelease-cli-package.mjsruns, reports total 0.check:third-party-noticesandcheck:cli-third-party-noticesboth pass.check:releasepasses 212/214. The two failures are Windows-only fixture errors (EBUSY on rmdir, Git fixture setup) in tests unrelated to dependencies.npm run buildpasses. The runtime bot tests pass 107/109; the twoproxiedFetchstreaming failures are identical onmain. Lark and WeCom SDKs load withaxios1.20.0.If this merges, #5881 and #5882 become redundant; Dependabot should close them on its own once
maincarries these versions. #5883 (the Eval harness toolchain lockfile) is outside the shipped closure and isn't touched here.AI use
Diagnosed and prepared with Claude Code. The Dependabot commits are unchanged; the
axios/notices commit carries aCo-Authored-Bytrailer.🤖 Generated with Claude Code