Skip to content

pkg(security): Bump patched releases for security advisories - #4248

Merged
ntucker merged 1 commit into
masterfrom
cursor/security-advisory-bumps-98d2
Oct 6, 2026
Merged

ntucker merged 1 commit into
masterfrom
cursor/security-advisory-bumps-98d2

Conversation

@ntucker

@ntucker ntucker commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Fixes # .

Motivation

Clear security advisories in the Yarn workspace and in the standalone example apps without changing library source or published APIs.

Open Renovate PRs were not duplicated: #4208 (React Native 0.87, mermaid, vite) has a failing check and still needs review, and #4209 (major build packages) still needs review. React Native 0.87 also has #4186, which needs code changes (InteractionManager). This PR only takes security fixes that stay inside existing ranges or a narrow resolution.

No changeset: root tooling, the lockfile, and example overrides only.

Advisory counts

Deprecation notices from yarn npm audit (10 moderate: @types/uuid, acorn-dynamic-import, babel-merge, eslint, glob, inflight, node-domexception, rimraf, sourcemap-codec, whatwg-encoding) are not CVEs and are unchanged. They are omitted below.

shell-quote@1.10.0 was already in the base lockfile (GHSA-pqg4-j6r4-53mv, >=1.8.4 <1.11.0). The first registry response did not list it; the next audit of that same resolution did. It is included in the workspace Before column.

Yarn workspace (yarn npm audit --all --recursive)

Advisory entries, not dependency-tree size:

Severity Before After
critical 6 0
high 8 1
moderate 3 1
low 2 2
total 19 4

Standalone examples (npm audit metadata)

npm counts every package in the vulnerable tree, so one braces advisory shows up as many highs.

Example Before After
examples/github-app critical 6, high 15, moderate 0, low 4 (25) critical 0, high 11, moderate 0, low 4 (15)
examples/todo-app critical 1, high 12, moderate 0, low 4 (17) critical 0, high 10, moderate 0, low 4 (14)
examples/nextjs 0 0
examples/vue-todo-app 0 0

nextjs and vue-todo-app were already clean and were not modified. The remaining example highs/lows are the braces and elliptic trees below.

Solution

In-range lockfile updates (yarn up -R, manifests unchanged):

  • compression 1.8.1 → 1.8.2 where parents use ^1.8.1
  • proxy-addr 2.0.7 → 2.0.8
  • source-map-js 1.2.1 → 1.2.2
  • http-cache-semantics 4.1.1 → 4.3.0
  • shell-quote 1.10.0 → 1.12.0
  • pbkdf2 3.1.3 → 3.1.7 (GHSA-477h-4r7f-fvrx, patched in 3.1.7; not in the npm audit feed yet, which is why Dependabot #4243 sees it and yarn npm audit does not)
  • postcss-modules-local-by-default 4.0.5 → 4.2.0, postcss-modules-scope 3.2.0 → 3.2.1, postcss-discard-comments 7.0.3 → 7.0.8, cssnano 7.0.6 → 7.1.9 and its 7.x plugins, so those parents accept postcss-selector-parser 7.1.6
  • metro 0.84.4 → 0.84.6 (and the matching metro-* packages). React Native 0.86 depends on metro@^0.84.3; 0.84.6 drops vulnerable image-size@1.2.1 for an internal helper. This avoids the React Native 0.87 upgrade
  • @react-navigation/native 7.3.13 → 7.5.0, @react-navigation/native-stack 7.18.5 → 7.20.0, @react-navigation/core 7.21.11 → 7.23.0. Core 7.23 no longer depends on query-string@7, which removes vulnerable decode-uri-component. Peer ranges in @data-client/react are unchanged

Resolutions (parents have no release that allows the patched version):

  • serve/compression: 1.8.2 — serve@14.2.6 (latest) depends on compression@1.8.1 exactly. 1.8.2 is the patched patch release.
  • simple-git: >=4.0.2 — yeoman-generator 8 and 9 (latest) still depend on simple-git@^3.36.0. 4.0.2 keeps the named simpleGit export yeoman imports, and it depends on @simple-git/argv-parser@2.0.1. 4.0.0 and 4.0.1 still depend on argv-parser@2.0.0, which is itself vulnerable. Used by @anansi/cli's generator, not by library runtime.
  • tinypool: >=2.1.2 (resolved to 2.2.0) — @docusaurus/core@3.10.2 (latest) depends on tinypool@^1.0.2. 2.2.0 still default-exports Tinypool and still accepts the SSG pool options docusaurus passes (maxMemoryLimitBeforeRecycle, isolateWorkers). Tinypool 2 requires Node ^20 || >=22. Website CI is Node 26. The Node 18 test job does not build the site.
  • postcss-selector-parser: ^7.1.6 — the only remaining 6.1.4 copy was cssnano 6, via @docusaurus/bundler@3.10.2 (latest). Those plugins cap the parser at ^6, and 6.1.4 is the last 6.x. The 7.0 break makes removals during walk() safe, which is what the cssnano plugins do. cssnano@6 minify still produces output with the override.

Example apps (npm, not the Yarn workspace):

  • npm audit fix (no --force) in examples/github-app and examples/todo-app: proxy-addr, source-map-js, http-cache-semantics, shell-quote, pbkdf2, postcss-selector-parser, and compression where the range already allowed 1.8.2 (todo-app).
  • examples/github-app overrides, same reason as the Yarn resolutions: compression: 1.8.2 (serve pins 1.8.1) and simple-git: 4.0.2 (yeoman-generator pins 3.x).

Open questions

Left unfixed:

  • braces@3.0.3 (high) via chokidar@3. 3.0.3 is the latest release and it is still inside <=3.0.3. npm's suggested fix is a downgrade of webpack-dev-server to 2.9.7. No patched release.
  • elliptic@6.6.1 (low) via browserify-sign. 6.6.1 is the latest release and it is still inside <=6.6.1. The suggested fix downgrades @anansi/webpack-config to 4.2.5. No patched release.
  • sprintf-js@1.0.3 (moderate) via argparse@1 (js-yaml@3, from @istanbuljs/load-nyc-config). Every published version is inside <=1.1.3. No patched release.
  • katex@0.16.47 (low) via mermaid. The fix is katex >=0.18.2. mermaid@12.1.0 (latest) still depends on katex@^0.16.47 and vendors KaTeX 0.16 into its bundle, so resolving the katex package would not patch the copy mermaid renders. Needs a mermaid release. Low severity: an existing prototype pollution gadget can bypass KaTeX trust checks.
  • eslint 9 deprecation is not a CVE. ESLint 10 would be a major config change.
  • npm audit fix --force was not used. It wants to downgrade @anansi/cli, webpack-dev-server, and @anansi/webpack-config to old majors.

Dependabot PRs that overlap the example lockfile bumps can close if this lands: #4243, #4242, #4218, #4217, #4216.

Validation

yarn build, yarn tsc --project tsconfig.test.json --noEmit, yarn check:typeperf, yarn workspace rdc-website typecheck, and yarn lint --quiet packages/*/src (the CI lint command) pass. examples/todo-app builds, typechecks, and passes test:pkg. examples/github-app client and server builds pass. CircleCI on this PR is green, including unit tests, the Node 18/20 matrix, and legacy TypeScript builds.

Website build verification

site-preview.yml and Vercel skip this PR because it does not touch website/** or docs/{core,rest,graphql}/**. The docs site was built locally on fe598fe4f642c9138639239f1d340f07067e1f72 (Node 22.14.0) with both major-crossing resolutions active (tinypool@2.2.0 under @docusaurus/core@3.10.2, postcss-selector-parser@7.1.6 under cssnano@6.1.2):

./scripts/ci-install.sh website
yarn ci:build:website
VERCEL_ENV=preview yarn workspace rdc-website build

Exit 0. Client compiled in 36.82s, server in 16.98s, static files written to build. No [WARNING] or [ERROR] lines.

Open in Web Open in Cursor 

Refresh in-range lockfile resolutions and pin transitive packages
whose parents still depend on a vulnerable version.

Co-authored-by: Nathaniel Tucker <me@ntucker.me>
@changeset-bot

changeset-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: fe598fe

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercel Bot commented Oct 6, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs-site Ignored Ignored Oct 6, 2026 3:18pm UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T15:22:26.190454Z fe598fe PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Benchmark Spread

Details
Benchmark suite Current: fe598fe Previous: a403df8 Ratio
setOneEntity in 10k entity store 168 ops/sec (±0.94%) 264 ops/sec (±1.76%) 1.57

This comment was automatically generated by workflow using github-action-benchmark.

ntucker commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator Author

Staff engineer (Cursor agent): CHANGE_THIS_PR (pre-merge evidence, not a code change) at fe598fe.

The in-range lockfile bumps and the serve/compression / simple-git resolutions look right, and not taking npm audit fix --force or the RN 0.87 jump is the correct call.

Blocking: nothing builds the docs site for this PR. Two of the new resolutions only affect the Docusaurus build, and both cross a major:

  • tinypool: >=2.1.2 moves @docusaurus/core's SSG worker pool from ^1 to 2.x.
  • postcss-selector-parser: ^7.1.6 moves cssnano 6 (via @docusaurus/bundler) from ^6 to 7.x for production CSS minification.

But this PR only touches package.json, yarn.lock, and the example lockfiles. site-preview.yml is path-filtered to website/** and docs/{core,rest,graphql}/**, and website/scripts/vercel-ignore.sh uses the same paths, so the website workflow doesn't run here (Vercel already shows the preview as Ignored). After merge, the master push and the production deploy skip for the same reason. If either override breaks SSG or minification, it would first show up on some later, unrelated docs PR or deploy. The PR body checks the tinypool option names and that cssnano 6 "still produces output", but it doesn't say a full site build ran.

Ask: before merge, run the same steps as site-preview.yml on this SHA (./scripts/ci-install.sh website, yarn ci:build:website, VERCEL_ENV=preview yarn workspace rdc-website build) and confirm it finishes with no [WARNING]/[ERROR] lines. Then add the result to the PR body. If it fails, drop that one resolution and leave the advisory in Open questions with the others. Not asking to add yarn.lock to the path filters here: skipping lockfile-only previews is a deliberate choice in vercel-ignore.sh, and that call doesn't belong in this PR.

FOLLOW_UP (not blocking):

  • simple-git: >=4.0.2 and tinypool: >=2.1.2 have no upper bound, so a future lockfile refresh could pull simple-git 5 or tinypool 3 into yeoman/docusaurus with no review, and per the above, with no site build either. ^4.0.2 / ^2.1.2 would cap that. The repo's other resolutions (sigstore, qs) already use >=, so this belongs in a separate convention pass, not here.
  • Each of the four new resolutions has a clear removal trigger (serve releasing past compression@1.8.1, yeoman-generator on simple-git 4, Docusaurus on tinypool 2 / cssnano 7). It's worth tracking those so the overrides come out once upstream catches up and don't turn into permanent pins.

ntucker commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator Author

Lead Engineer: Taking Staff's CHANGE_THIS_PR above (#issuecomment-6019456161) on the cloud agent that opened this PR, so Claude Code please hold off to avoid a collision.

Why: tinypool >=2.1.2 (Docusaurus SSG worker pool, ^1 to 2.x) and postcss-selector-parser ^7.1.6 (cssnano 6, ^6 to 7.x) cross majors and only affect the docs site build. This PR touches only package.json and lockfiles, so site-preview.yml and website/scripts/vercel-ignore.sh (path-filtered to website/** and the docs dirs) skip it. Vercel shows Ignored, and the master push and prod deploy will skip it too. A break would first show up on an unrelated docs PR.

Plan: on fe598fe, run ./scripts/ci-install.sh website, yarn ci:build:website, and VERCEL_ENV=preview yarn workspace rdc-website build, check for no [WARNING]/[ERROR] lines, and record the result in the PR body. If either resolution breaks the build, drop it and list the advisory under Open questions. No path-filter change (lockfile-only previews are skipped on purpose). Not merging without Nathaniel.

@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.10%. Comparing base (4a75c80) to head (fe598fe).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #4248   +/-   ##
=======================================
  Coverage   98.10%   98.10%           
=======================================
  Files         166      166           
  Lines        3166     3166           
  Branches      626      626           
=======================================
  Hits         3106     3106           
  Misses         18       18           
  Partials       42       42           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Size Change: 0 B

Total Size: 103 kB

ℹ️ View Unchanged
Filename Size
examples/test-bundlesize/dist/App.js 1.46 kB
examples/test-bundlesize/dist/polyfill.js 307 B
examples/test-bundlesize/dist/rdcClient.js 10.9 kB
examples/test-bundlesize/dist/rdcEndpoint.js 8.07 kB
examples/test-bundlesize/dist/rdcNextjs.js 12.4 kB
examples/test-bundlesize/dist/rdcPipeableStream.js 9.7 kB
examples/test-bundlesize/dist/react.js 59.7 kB
examples/test-bundlesize/dist/webpack-runtime.js 784 B

compressed-size-action

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Benchmark React

Details
Benchmark suite Current: fe598fe Previous: 954b1e9 Ratio
data-client: getlist-100 129.87 ops/s (± 4.0%) 173.93 ops/s (± 4.5%) 1.34
data-client: getlist-500 42.28 ops/s (± 4.6%) 51.95 ops/s (± 5.1%) 1.23
data-client: update-entity 322.58 ops/s (± 8.4%) 408.33 ops/s (± 7.2%) 1.27
data-client: update-user 327.96 ops/s (± 7.4%) 363.76 ops/s (± 8.4%) 1.11
data-client: getlist-500-sorted 45.66 ops/s (± 10.4%) 50.3 ops/s (± 9.6%) 1.10
data-client: update-entity-sorted 289.92 ops/s (± 6.6%) 333.33 ops/s (± 7.2%) 1.15
data-client: update-entity-multi-view 303.03 ops/s (± 4.6%) 370.37 ops/s (± 5.4%) 1.22
data-client: list-detail-switch-10 8.2 ops/s (± 9.7%) 14 ops/s (± 9.2%) 1.71
data-client: update-user-10000 69.69 ops/s (± 11.3%) 81 ops/s (± 15.6%) 1.16
data-client: invalidate-and-resolve 36.83 ops/s (± 5.6%) 43.67 ops/s (± 5.6%) 1.19
data-client: unshift-item 196.08 ops/s (± 8.4%) 238.1 ops/s (± 4.1%) 1.21
data-client: delete-item 277.78 ops/s (± 4.9%) 322.58 ops/s (± 5.8%) 1.16
data-client: move-item 162.61 ops/s (± 10.0%) 200 ops/s (± 10.9%) 1.23

This comment was automatically generated by workflow using github-action-benchmark.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Benchmark

Details
Benchmark suite Current: fe598fe Previous: 31b1820 Ratio
normalizeLong 369 ops/sec (±3.87%) 433 ops/sec (±3.96%) 1.17
normalizeLong Values 352 ops/sec (±1.31%) 388 ops/sec (±0.38%) 1.10
normalizeLong Scalar 347 ops/sec (±4.09%) 368 ops/sec (±3.41%) 1.06
normalizeLong Scalar update 861 ops/sec (±1.20%) 921 ops/sec (±0.17%) 1.07
denormalizeLong 226 ops/sec (±6.16%) 241 ops/sec (±6.46%) 1.07
denormalizeLong Values 201 ops/sec (±5.71%) 229 ops/sec (±5.09%) 1.14
denormalizeLong donotcache 996 ops/sec (±0.82%) 993 ops/sec (±0.75%) 1.00
denormalizeLong Values donotcache 699 ops/sec (±0.73%) 748 ops/sec (±0.14%) 1.07
denormalizeLong Scalar donotcache 1029 ops/sec (±0.31%) 1066 ops/sec (±0.45%) 1.04
denormalizeShort donotcache 500x 1394 ops/sec (±0.13%) 1368 ops/sec (±0.12%) 0.98
denormalizeShort 500x 609 ops/sec (±7.21%) 645 ops/sec (±6.81%) 1.06
denormalizeShort 500x withCache 6678 ops/sec (±0.66%) 6906 ops/sec (±0.09%) 1.03
queryShort 500x withCache 3127 ops/sec (±0.92%) 3179 ops/sec (±0.38%) 1.02
buildQueryKey All 55679 ops/sec (±0.55%) 58802 ops/sec (±0.66%) 1.06
query All withCache 5995 ops/sec (±2.92%) 5833 ops/sec (±2.85%) 0.97
denormalizeLong with mixin Entity 176 ops/sec (±8.25%) 217 ops/sec (±7.87%) 1.23
denormalizeLong withCache 7040 ops/sec (±0.25%) 7041 ops/sec (±0.21%) 1.00
denormalizeLong withCache (Scalar churn) 6983 ops/sec (±1.11%) 7009 ops/sec (±0.23%) 1.00
denormalizeLong Values withCache 5099 ops/sec (±1.67%) 5156 ops/sec (±1.47%) 1.01
denormalizeLong Scalar withCache 7596 ops/sec (±0.40%) 7841 ops/sec (±0.16%) 1.03
denormalizeLong Scalar update withCache 4017 ops/sec (±0.30%) 4093 ops/sec (±0.47%) 1.02
denormalizeLong All withCache 6147 ops/sec (±0.42%) 6448 ops/sec (±0.30%) 1.05
denormalizeLong Query-sorted withCache 6340 ops/sec (±1.75%) 6164 ops/sec (±1.19%) 0.97
denormalizeLongAndShort withEntityCacheOnly 1717 ops/sec (±0.80%) 1753 ops/sec (±0.13%) 1.02
denormalize bidirectional 50 4391 ops/sec (±9.01%) 4614 ops/sec (±9.90%) 1.05
denormalize bidirectional 50 donotcache 42842 ops/sec (±0.33%) 40694 ops/sec (±0.44%) 0.95
getResponse 4429 ops/sec (±3.25%) 4365 ops/sec (±4.21%) 0.99
getResponse (null) 9956068 ops/sec (±0.59%) 10265167 ops/sec (±0.48%) 1.03
getResponse (clear cache) 175 ops/sec (±9.84%) 205 ops/sec (±7.76%) 1.17
getSmallResponse 3405 ops/sec (±1.26%) 3558 ops/sec (±1.28%) 1.04
getSmallInferredResponse 2802 ops/sec (±0.36%) 2852 ops/sec (±0.23%) 1.02
getResponse Collection 4266 ops/sec (±3.61%) 4482 ops/sec (±2.35%) 1.05
get Collection 2951 ops/sec (±0.56%) 3260 ops/sec (±0.22%) 1.10
get Query-sorted 4978 ops/sec (±1.58%) 4847 ops/sec (±1.35%) 0.97
setLong 400 ops/sec (±1.04%) 427 ops/sec (±0.19%) 1.07
setLongWithMerge 240 ops/sec (±1.45%) 249 ops/sec (±0.16%) 1.04
setLongWithSimpleMerge 259 ops/sec (±0.74%) 265 ops/sec (±0.29%) 1.02
setSmallResponse 500x 887 ops/sec (±1.46%) 897 ops/sec (±1.47%) 1.01
setMany 50x one-per-row 129 ops/sec (±1.10%) 157 ops/sec (±0.44%) 1.22
setMany 50 batch 3276 ops/sec (±2.43%) 3674 ops/sec (±0.46%) 1.12
setMany 500x one-per-row 13.73 ops/sec (±1.38%) 16.07 ops/sec (±0.41%) 1.17
setMany 500 batch 1354 ops/sec (±3.35%) 1441 ops/sec (±0.19%) 1.06

This comment was automatically generated by workflow using github-action-benchmark.

@ntucker
ntucker merged commit f992c21 into master Oct 6, 2026
32 checks passed
@ntucker
ntucker deleted the cursor/security-advisory-bumps-98d2 branch October 6, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants