Skip to content

fix(deps): clear high dev audit advisories - #1566

Merged
Astro-Han merged 2 commits into
devfrom
fix/dev-dep-audit-high-advisories
Aug 18, 2026
Merged

Astro-Han merged 2 commits into
devfrom
fix/dev-dep-audit-high-advisories

Conversation

@Astro-Han

@Astro-Han Astro-Han commented Aug 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

Clear the high-severity advisories currently reported by the pinned bun audit --audit-level=high job after v2026.8.3. This PR intentionally contains only the dependency versions and lockfile resolutions needed for those findings; there is no related issue.

Why

The audit baseline contained 10 high findings across nine packages. The remediation boundaries are:

  • electron: direct desktop dev dependency; 40.x has no patched release, so move to the first fixed 41.x release, 41.10.3.
  • ip-address: introduced by MCP, Arborist, and desktop builder chains, including an exact 10.1.0 edge; pin the first fixed 10.3.1 release at the root.
  • brace-expansion: introduced through minimatch; move the existing security override to 5.0.9 and carry the existing CommonJS compatibility patch forward.
  • nanoid: introduced by Vite through PostCSS; pin the first fixed 3.x release, 3.3.18, without upgrading Vite or PostCSS.
  • pdfjs-dist: direct OpenCode runtime dependency; move from 5.6.205 to the first fixed release, 6.2.108. The supported Node legacy entry imports successfully in Bun and Node 24.
  • socket.io-parser: introduced by the GitLab provider through socket.io-client; pin the compatible fixed 4.2.7 release.
  • undici: keep the unaffected 6.x chain unchanged, move desktop and Electron's optional 7.x chain to 7.29.0, and resolve Effect's existing ^8.2.0 edge to the first fixed 8.9.0 release.
  • fast-uri: advance the existing root security override to 3.1.5.
  • js-yaml: advance the existing root security override to 4.3.1.

No unrelated dependency refresh was run.

Related Issue

None. This follows the release handoff and STATUS item for advisories that remained after v2026.8.3.

Human Review Status

Pending

Review Focus

Please verify that each manifest or lockfile change maps to one current high advisory, that the three compatible undici major lines remain separate, and that the Electron/PDF.js major boundaries have sufficient runtime evidence.

Risk Notes

  • Electron crosses from 40.x to 41.x because no patched 40.x build exists. Electron 41.10.3 passed typechecking, 652 desktop tests, a production build, and a real macOS development launch through sidecar readiness. Windows runtime packaging remains covered by PR CI.
  • PDF.js crosses a major boundary. Both the previous and new default Node entry require browser globals; the documented legacy entry imports successfully with Bun and Node 24 after the upgrade.
  • The visible UI/copy checklist item is intentionally unticked because this PR has no visible UI or copy change.

How To Verify

bun install --frozen-lockfile: passed with Bun 1.3.14
bun audit --audit-level=high: passed with zero high findings
Focused audit/brace compatibility tests: 3 passed
PDF.js legacy import smoke: passed in Bun 1.3.14 and Node 24
OpenCode typecheck: passed
Desktop Electron typecheck: passed
Desktop Electron unit tests: 652 passed
Electron 41.10.3 production build: passed
bun run dev:desktop: reached sidecar ready and init done on macOS
git diff --check: passed

Screenshots or Recordings

Not applicable; there is no visible UI change.

Checklist

How to use this checklist:

  • Tick a box by replacing [ ] with [x]. Do not edit, add, or remove items.
  • The bot-applied label items can only be honestly ticked AFTER the PR is opened and the labeler / priority-triage bots have run — return to the PR description and tick them then.
  • Most items are required. The few that are conditional are explicitly marked (conditional); for those, leave unticked if they truly do not apply and explain why in Risk Notes. All other items must be ticked before requesting human review.
  • Type label — this PR carries exactly one of bug, enhancement, task, documentation. Type labels are author-added; the labeler bot does NOT assign them. Add the label in the GitHub UI, then tick this.
  • Routing labels — this PR carries at least one of app, ui, platform, harness, ci. The labeler bot assigns these on PR open based on changed paths. Confirm the bot's choice (or override if wrong), then tick this.
  • Priority label — this PR carries exactly one of P0, P1, P2, P3. The priority-triage bot suggests one on PR open. Confirm or override, then tick this.
  • Human Review Status above is set to Pending, Approved by @<reviewer>, or Not required: <reason> (default is Pending; "not required" is restricted to bot-authored low-risk PRs).
  • I linked the related issue, or stated in Summary why there is no issue.
  • I described the review focus and any meaningful risks.
  • I replaced the example block in How To Verify with the real verification steps and the key result for each.
  • I did not introduce unrelated refactors, dependencies, generated files, or file changes beyond the stated scope.
  • (conditional) I manually checked visible UI or copy changes when needed, with screenshots or recordings. Leave unticked only if no visible UI or copy changed.
  • (conditional) I considered macOS and Windows impact for platform, packaging, updater, signing, paths, shell, or permissions changes. Leave unticked only if no platform/packaging surface was touched.
  • (conditional) I called out docs, release notes, dependencies, permissions, credentials, deletion behavior, generated content, or local file changes when relevant. Leave unticked only if none of those surfaces was touched.
  • I reviewed the final diff for unrelated changes and suspicious dependency changes.
  • I am targeting dev, and my PR title and commit messages use Conventional Commits in English.

Summary by CodeRabbit

  • Bug Fixes
    • Improved compatibility for pattern expansion utilities while preserving existing callable behavior.
    • Updated PDF rendering, desktop runtime, networking, and supporting packages for improved stability and compatibility.
    • Added safeguards and compatibility updates for several underlying libraries.

Upgrade only the direct and transitive packages implicated by the current Bun high-severity audit. Keep the brace-expansion CommonJS compatibility patch on the fixed release and preserve separate compatible undici major lines in the lockfile.\n\nElectron moves to the first fixed 41.x release because 40.x has no patched build. PDF.js moves to its first patched release; its Node legacy entry remains importable under Bun and Node 24.
@Astro-Han Astro-Han added bug Something isn't working dependencies Pull requests that update a dependency file P2 Medium priority platform Electron shell, OS integration, packaging, updater, signing, paths, and permissions labels Aug 18, 2026 — with ChatGPT Codex Connector
@github-actions github-actions Bot added ci Continuous integration / GitHub Actions harness Model harness, prompts, tool descriptions, and session mechanics labels Aug 18, 2026
@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@Astro-Han, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 4 minutes

Limit details: You’ve used all 1 included review currently available under your plan.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: a1d4b813-2b9a-4eaa-bec3-a80d8d828988

📥 Commits

Reviewing files that changed from the base of the PR and between ad18f61 and c9eafb5.

📒 Files selected for processing (2)
  • packages/opencode/test/github/brace-expansion-compatibility.test.ts
  • patches/brace-expansion@5.0.9.patch

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 5bed0e00-033a-4045-9877-179c3df00497

📥 Commits

Reviewing files that changed from the base of the PR and between 40fcb60 and ad18f61.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (4)
  • package.json
  • packages/desktop-electron/package.json
  • packages/opencode/package.json
  • patches/brace-expansion@5.0.9.patch

Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The change updates dependency versions and root overrides, retargets the brace-expansion patch, and adds named exports to its CommonJS compatibility patch.

Changes

Dependency updates

Layer / File(s) Summary
Dependency version alignment
package.json, packages/desktop-electron/package.json, packages/opencode/package.json
Root overrides and package dependencies use updated versions. The brace-expansion patch target changes to 5.0.9.
Brace-expansion compatibility patch
patches/brace-expansion@5.0.9.patch
The CommonJS export remains callable and now exposes expand, EXPANSION_MAX, and EXPANSION_MAX_LENGTH as named properties.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: 🔵 Low · up to ad18f

The PR updates dependency versions and lockfile resolutions to clear high advisories, with the listed validation checks passing. It is mergeable with explicit owner awareness to confirm that overrides for packages outside the stated advisory set are required and remove any unrelated entries.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the dependency updates intended to resolve high-severity audit advisories.
Description check ✅ Passed The description includes all required sections, explains the dependency remediation, documents risks, and provides verification results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dev-dep-audit-high-advisories

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested priority: P2 (includes non-doc, non-test paths outside the low-risk bucket).

P1/P0 are reserved for maintainer confirmation. Please relabel manually if this is a release blocker, security issue, data-loss risk, or updater/runtime failure.

@Astro-Han
Astro-Han marked this pull request as ready for review August 18, 2026 12:23
@Astro-Han
Astro-Han merged commit 61fb483 into dev Aug 18, 2026
42 checks passed
@Astro-Han
Astro-Han deleted the fix/dev-dep-audit-high-advisories branch August 18, 2026 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working ci Continuous integration / GitHub Actions dependencies Pull requests that update a dependency file harness Model harness, prompts, tool descriptions, and session mechanics P2 Medium priority platform Electron shell, OS integration, packaging, updater, signing, paths, and permissions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant