Skip to content

fix(deps): clear 2026-09-29 advisories and close a CI path-filter blind spot - #284

Merged
freebuff-web[bot] merged 1 commit into
mainfrom
fix/bun-audit-advisories-20261001
Oct 1, 2026
Merged

freebuff-web[bot] merged 1 commit into
mainfrom
fix/bun-audit-advisories-20261001

Conversation

@freebuff-web

@freebuff-web freebuff-web Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Advisories

Two advisories published 2026-09-29 tripped the bun audit --audit-level=high
gate on main. bun audit now reports zero findings at every severity in
both workspaces.

package before after advisory
brace-expansion 5.0.9 5.0.12 GHSA-qhr7-859c-m2p7 — high, DoS via uncontrolled recursion
fast-uri 3.1.5 3.1.8 GHSA-hrr3-gc8f-f4qj — host case normalization
ip-address 10.4.0 10.7.2 4× SSRF / trust-boundary
hono 4.12.x 4.13.12 memory exhaustion, query-parser differentials, JSX escaping
dompurify (gui) 3.4.13 3.4.16 GHSA-p98j-92pf-mc4p — DOM XSS

All are overrides entries, so no direct dependency range moves and the
lockfile diff is limited to those packages.

CI path-filter blind spot

tests/ci-workflows.test.ts pins the action SHAs of container.yml and
deploy-docs.yml. The three Dependabot PRs merged today changed exactly those
SHAs — and the suite went red.

It stayed red on main silently because ci.yml gates on a paths: list that
enumerates workflow files individually. That list had drifted and omitted
container.yml and deploy-docs.yml
, so a PR touching only one of them ran
no tests at all. Every check on all three PRs reported clean.

The trigger is now .github/workflows/**, which cannot drift the same way.

Verification

  • bun audit — clean at every severity, root and gui
  • bun run typecheck — clean
  • bun run privacy:scan — passed
  • tests/ci-workflows.test.ts — 90 pass / 0 fail
  • Full suite via scripts/ci-test-shard.ts — 4 failures, byte-identical to the
    same run on clean main (CLI help ×2, service diagnostics, codex-runtime);
    none introduced here

Note

The 4 remaining failures are pre-existing on main and reproduce on a clean
checkout. They are unrelated to this change.

…nd spot

`bun audit` now reports zero findings at every severity in both workspaces.
Two advisories published 2026-09-29 tripped the `--audit-level=high` gate:
brace-expansion (high, DoS via uncontrolled recursion) and fast-uri. Also
cleared the moderate set that matters most for a proxy -- ip-address
(SSRF/trust-boundary), hono (memory exhaustion, query-parser differentials,
JSX escaping) and dompurify (DOM XSS). All are `overrides` bumps, so no
direct dependency range moves.

Separately, Cross-platform CI now triggers on `.github/workflows/**` instead
of an enumerated file list. That list had drifted and omitted container.yml
and deploy-docs.yml, so a PR touching only one of them ran no tests at all --
which is how the three merged Dependabot pin bumps landed a commit that broke
tests/ci-workflows.test.ts while every check reported clean. The action pins in
that test are updated to the new SHAs, each verified against its upstream
release tag first.

Co-Authored-By: Codex <noreply@openai.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: GroepOnline/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 29bc22f7-17fa-42a8-92a8-f5b8fa419f61

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the bug label Oct 1, 2026
@freebuff-web
freebuff-web Bot merged commit 5770910 into main Oct 1, 2026
23 checks passed
@freebuff-web
freebuff-web Bot deleted the fix/bun-audit-advisories-20261001 branch October 1, 2026 06:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant