Repository navigation
pkg(security): Bump patched releases for security advisories - #4248
Conversation
Refresh in-range lockfile resolutions and pin transitive packages whose parents still depend on a vulnerable version. Co-authored-by: Nathaniel Tucker <me@ntucker.me>
|
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Benchmark Spread
Details
| Benchmark suite | Current: fe598fe | Previous: a403df8 | Ratio |
|---|---|---|---|
setOneEntity in 10k entity store |
168 ops/sec (±0.94%) |
264 ops/sec (±1.76%) |
1.57 |
This comment was automatically generated by workflow using github-action-benchmark.
|
Staff engineer (Cursor agent): CHANGE_THIS_PR (pre-merge evidence, not a code change) at fe598fe. The in-range lockfile bumps and the Blocking: nothing builds the docs site for this PR. Two of the new resolutions only affect the Docusaurus build, and both cross a major:
But this PR only touches Ask: before merge, run the same steps as FOLLOW_UP (not blocking):
|
|
Lead Engineer: Taking Staff's CHANGE_THIS_PR above (#issuecomment-6019456161) on the cloud agent that opened this PR, so Claude Code please hold off to avoid a collision. Why: Plan: on fe598fe, run |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #4248 +/- ##
=======================================
Coverage 98.10% 98.10%
=======================================
Files 166 166
Lines 3166 3166
Branches 626 626
=======================================
Hits 3106 3106
Misses 18 18
Partials 42 42 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Size Change: 0 B Total Size: 103 kB ℹ️ View Unchanged
|
There was a problem hiding this comment.
Benchmark React
Details
| Benchmark suite | Current: fe598fe | Previous: 954b1e9 | Ratio |
|---|---|---|---|
data-client: getlist-100 |
129.87 ops/s (± 4.0%) |
173.93 ops/s (± 4.5%) |
1.34 |
data-client: getlist-500 |
42.28 ops/s (± 4.6%) |
51.95 ops/s (± 5.1%) |
1.23 |
data-client: update-entity |
322.58 ops/s (± 8.4%) |
408.33 ops/s (± 7.2%) |
1.27 |
data-client: update-user |
327.96 ops/s (± 7.4%) |
363.76 ops/s (± 8.4%) |
1.11 |
data-client: getlist-500-sorted |
45.66 ops/s (± 10.4%) |
50.3 ops/s (± 9.6%) |
1.10 |
data-client: update-entity-sorted |
289.92 ops/s (± 6.6%) |
333.33 ops/s (± 7.2%) |
1.15 |
data-client: update-entity-multi-view |
303.03 ops/s (± 4.6%) |
370.37 ops/s (± 5.4%) |
1.22 |
data-client: list-detail-switch-10 |
8.2 ops/s (± 9.7%) |
14 ops/s (± 9.2%) |
1.71 |
data-client: update-user-10000 |
69.69 ops/s (± 11.3%) |
81 ops/s (± 15.6%) |
1.16 |
data-client: invalidate-and-resolve |
36.83 ops/s (± 5.6%) |
43.67 ops/s (± 5.6%) |
1.19 |
data-client: unshift-item |
196.08 ops/s (± 8.4%) |
238.1 ops/s (± 4.1%) |
1.21 |
data-client: delete-item |
277.78 ops/s (± 4.9%) |
322.58 ops/s (± 5.8%) |
1.16 |
data-client: move-item |
162.61 ops/s (± 10.0%) |
200 ops/s (± 10.9%) |
1.23 |
This comment was automatically generated by workflow using github-action-benchmark.
There was a problem hiding this comment.
Benchmark
Details
| Benchmark suite | Current: fe598fe | Previous: 31b1820 | Ratio |
|---|---|---|---|
normalizeLong |
369 ops/sec (±3.87%) |
433 ops/sec (±3.96%) |
1.17 |
normalizeLong Values |
352 ops/sec (±1.31%) |
388 ops/sec (±0.38%) |
1.10 |
normalizeLong Scalar |
347 ops/sec (±4.09%) |
368 ops/sec (±3.41%) |
1.06 |
normalizeLong Scalar update |
861 ops/sec (±1.20%) |
921 ops/sec (±0.17%) |
1.07 |
denormalizeLong |
226 ops/sec (±6.16%) |
241 ops/sec (±6.46%) |
1.07 |
denormalizeLong Values |
201 ops/sec (±5.71%) |
229 ops/sec (±5.09%) |
1.14 |
denormalizeLong donotcache |
996 ops/sec (±0.82%) |
993 ops/sec (±0.75%) |
1.00 |
denormalizeLong Values donotcache |
699 ops/sec (±0.73%) |
748 ops/sec (±0.14%) |
1.07 |
denormalizeLong Scalar donotcache |
1029 ops/sec (±0.31%) |
1066 ops/sec (±0.45%) |
1.04 |
denormalizeShort donotcache 500x |
1394 ops/sec (±0.13%) |
1368 ops/sec (±0.12%) |
0.98 |
denormalizeShort 500x |
609 ops/sec (±7.21%) |
645 ops/sec (±6.81%) |
1.06 |
denormalizeShort 500x withCache |
6678 ops/sec (±0.66%) |
6906 ops/sec (±0.09%) |
1.03 |
queryShort 500x withCache |
3127 ops/sec (±0.92%) |
3179 ops/sec (±0.38%) |
1.02 |
buildQueryKey All |
55679 ops/sec (±0.55%) |
58802 ops/sec (±0.66%) |
1.06 |
query All withCache |
5995 ops/sec (±2.92%) |
5833 ops/sec (±2.85%) |
0.97 |
denormalizeLong with mixin Entity |
176 ops/sec (±8.25%) |
217 ops/sec (±7.87%) |
1.23 |
denormalizeLong withCache |
7040 ops/sec (±0.25%) |
7041 ops/sec (±0.21%) |
1.00 |
denormalizeLong withCache (Scalar churn) |
6983 ops/sec (±1.11%) |
7009 ops/sec (±0.23%) |
1.00 |
denormalizeLong Values withCache |
5099 ops/sec (±1.67%) |
5156 ops/sec (±1.47%) |
1.01 |
denormalizeLong Scalar withCache |
7596 ops/sec (±0.40%) |
7841 ops/sec (±0.16%) |
1.03 |
denormalizeLong Scalar update withCache |
4017 ops/sec (±0.30%) |
4093 ops/sec (±0.47%) |
1.02 |
denormalizeLong All withCache |
6147 ops/sec (±0.42%) |
6448 ops/sec (±0.30%) |
1.05 |
denormalizeLong Query-sorted withCache |
6340 ops/sec (±1.75%) |
6164 ops/sec (±1.19%) |
0.97 |
denormalizeLongAndShort withEntityCacheOnly |
1717 ops/sec (±0.80%) |
1753 ops/sec (±0.13%) |
1.02 |
denormalize bidirectional 50 |
4391 ops/sec (±9.01%) |
4614 ops/sec (±9.90%) |
1.05 |
denormalize bidirectional 50 donotcache |
42842 ops/sec (±0.33%) |
40694 ops/sec (±0.44%) |
0.95 |
getResponse |
4429 ops/sec (±3.25%) |
4365 ops/sec (±4.21%) |
0.99 |
getResponse (null) |
9956068 ops/sec (±0.59%) |
10265167 ops/sec (±0.48%) |
1.03 |
getResponse (clear cache) |
175 ops/sec (±9.84%) |
205 ops/sec (±7.76%) |
1.17 |
getSmallResponse |
3405 ops/sec (±1.26%) |
3558 ops/sec (±1.28%) |
1.04 |
getSmallInferredResponse |
2802 ops/sec (±0.36%) |
2852 ops/sec (±0.23%) |
1.02 |
getResponse Collection |
4266 ops/sec (±3.61%) |
4482 ops/sec (±2.35%) |
1.05 |
get Collection |
2951 ops/sec (±0.56%) |
3260 ops/sec (±0.22%) |
1.10 |
get Query-sorted |
4978 ops/sec (±1.58%) |
4847 ops/sec (±1.35%) |
0.97 |
setLong |
400 ops/sec (±1.04%) |
427 ops/sec (±0.19%) |
1.07 |
setLongWithMerge |
240 ops/sec (±1.45%) |
249 ops/sec (±0.16%) |
1.04 |
setLongWithSimpleMerge |
259 ops/sec (±0.74%) |
265 ops/sec (±0.29%) |
1.02 |
setSmallResponse 500x |
887 ops/sec (±1.46%) |
897 ops/sec (±1.47%) |
1.01 |
setMany 50x one-per-row |
129 ops/sec (±1.10%) |
157 ops/sec (±0.44%) |
1.22 |
setMany 50 batch |
3276 ops/sec (±2.43%) |
3674 ops/sec (±0.46%) |
1.12 |
setMany 500x one-per-row |
13.73 ops/sec (±1.38%) |
16.07 ops/sec (±0.41%) |
1.17 |
setMany 500 batch |
1354 ops/sec (±3.35%) |
1441 ops/sec (±0.19%) |
1.06 |
This comment was automatically generated by workflow using github-action-benchmark.
Fixes # .
Motivation
Clear security advisories in the Yarn workspace and in the standalone example apps without changing library source or published APIs.
Open Renovate PRs were not duplicated: #4208 (React Native 0.87, mermaid, vite) has a failing check and still needs review, and #4209 (major build packages) still needs review. React Native 0.87 also has #4186, which needs code changes (
InteractionManager). This PR only takes security fixes that stay inside existing ranges or a narrow resolution.No changeset: root tooling, the lockfile, and example overrides only.
Advisory counts
Deprecation notices from
yarn npm audit(10 moderate:@types/uuid,acorn-dynamic-import,babel-merge,eslint,glob,inflight,node-domexception,rimraf,sourcemap-codec,whatwg-encoding) are not CVEs and are unchanged. They are omitted below.shell-quote@1.10.0was already in the base lockfile (GHSA-pqg4-j6r4-53mv,>=1.8.4 <1.11.0). The first registry response did not list it; the next audit of that same resolution did. It is included in the workspace Before column.Yarn workspace (
yarn npm audit --all --recursive)Advisory entries, not dependency-tree size:
Standalone examples (
npm auditmetadata)npm counts every package in the vulnerable tree, so one
bracesadvisory shows up as many highs.examples/github-appexamples/todo-appexamples/nextjsexamples/vue-todo-appnextjsandvue-todo-appwere already clean and were not modified. The remaining example highs/lows are thebracesandelliptictrees below.Solution
In-range lockfile updates (
yarn up -R, manifests unchanged):compression1.8.1 → 1.8.2 where parents use^1.8.1proxy-addr2.0.7 → 2.0.8source-map-js1.2.1 → 1.2.2http-cache-semantics4.1.1 → 4.3.0shell-quote1.10.0 → 1.12.0pbkdf23.1.3 → 3.1.7 (GHSA-477h-4r7f-fvrx, patched in 3.1.7; not in the npm audit feed yet, which is why Dependabot #4243 sees it andyarn npm auditdoes not)postcss-modules-local-by-default4.0.5 → 4.2.0,postcss-modules-scope3.2.0 → 3.2.1,postcss-discard-comments7.0.3 → 7.0.8,cssnano7.0.6 → 7.1.9 and its 7.x plugins, so those parents acceptpostcss-selector-parser7.1.6metro0.84.4 → 0.84.6 (and the matchingmetro-*packages). React Native 0.86 depends onmetro@^0.84.3; 0.84.6 drops vulnerableimage-size@1.2.1for an internal helper. This avoids the React Native 0.87 upgrade@react-navigation/native7.3.13 → 7.5.0,@react-navigation/native-stack7.18.5 → 7.20.0,@react-navigation/core7.21.11 → 7.23.0. Core 7.23 no longer depends onquery-string@7, which removes vulnerabledecode-uri-component. Peer ranges in@data-client/reactare unchangedResolutions (parents have no release that allows the patched version):
serve/compression: 1.8.2—serve@14.2.6(latest) depends oncompression@1.8.1exactly. 1.8.2 is the patched patch release.simple-git: >=4.0.2—yeoman-generator8 and 9 (latest) still depend onsimple-git@^3.36.0. 4.0.2 keeps the namedsimpleGitexport yeoman imports, and it depends on@simple-git/argv-parser@2.0.1. 4.0.0 and 4.0.1 still depend onargv-parser@2.0.0, which is itself vulnerable. Used by@anansi/cli's generator, not by library runtime.tinypool: >=2.1.2(resolved to 2.2.0) —@docusaurus/core@3.10.2(latest) depends ontinypool@^1.0.2. 2.2.0 still default-exportsTinypooland still accepts the SSG pool options docusaurus passes (maxMemoryLimitBeforeRecycle,isolateWorkers). Tinypool 2 requires Node^20 || >=22. Website CI is Node 26. The Node 18 test job does not build the site.postcss-selector-parser: ^7.1.6— the only remaining 6.1.4 copy was cssnano 6, via@docusaurus/bundler@3.10.2(latest). Those plugins cap the parser at^6, and 6.1.4 is the last 6.x. The 7.0 break makes removals duringwalk()safe, which is what the cssnano plugins do.cssnano@6minify still produces output with the override.Example apps (npm, not the Yarn workspace):
npm audit fix(no--force) inexamples/github-appandexamples/todo-app:proxy-addr,source-map-js,http-cache-semantics,shell-quote,pbkdf2,postcss-selector-parser, andcompressionwhere the range already allowed 1.8.2 (todo-app).examples/github-appoverrides, same reason as the Yarn resolutions:compression: 1.8.2(servepins 1.8.1) andsimple-git: 4.0.2(yeoman-generatorpins 3.x).Open questions
Left unfixed:
braces@3.0.3(high) viachokidar@3. 3.0.3 is the latest release and it is still inside<=3.0.3. npm's suggested fix is a downgrade ofwebpack-dev-serverto 2.9.7. No patched release.elliptic@6.6.1(low) viabrowserify-sign. 6.6.1 is the latest release and it is still inside<=6.6.1. The suggested fix downgrades@anansi/webpack-configto 4.2.5. No patched release.sprintf-js@1.0.3(moderate) viaargparse@1(js-yaml@3, from@istanbuljs/load-nyc-config). Every published version is inside<=1.1.3. No patched release.katex@0.16.47(low) viamermaid. The fix iskatex >=0.18.2.mermaid@12.1.0(latest) still depends onkatex@^0.16.47and vendors KaTeX 0.16 into its bundle, so resolving thekatexpackage would not patch the copy mermaid renders. Needs a mermaid release. Low severity: an existing prototype pollution gadget can bypass KaTeX trust checks.npm audit fix --forcewas not used. It wants to downgrade@anansi/cli,webpack-dev-server, and@anansi/webpack-configto old majors.Dependabot PRs that overlap the example lockfile bumps can close if this lands: #4243, #4242, #4218, #4217, #4216.
Validation
yarn build,yarn tsc --project tsconfig.test.json --noEmit,yarn check:typeperf,yarn workspace rdc-website typecheck, andyarn lint --quiet packages/*/src(the CI lint command) pass.examples/todo-appbuilds, typechecks, and passestest:pkg.examples/github-appclient and server builds pass. CircleCI on this PR is green, including unit tests, the Node 18/20 matrix, and legacy TypeScript builds.Website build verification
site-preview.ymland Vercel skip this PR because it does not touchwebsite/**ordocs/{core,rest,graphql}/**. The docs site was built locally onfe598fe4f642c9138639239f1d340f07067e1f72(Node 22.14.0) with both major-crossing resolutions active (tinypool@2.2.0under@docusaurus/core@3.10.2,postcss-selector-parser@7.1.6undercssnano@6.1.2):Exit 0. Client compiled in 36.82s, server in 16.98s, static files written to
build. No[WARNING]or[ERROR]lines.