Repository navigation
fix(deps): clear bun audit and cargo audit advisories - #472
Merged
Merged
Conversation
Lockfile bumps within semver: rustls 0.23.42 -> 0.23.45 (RUSTSEC-2026-0285), anyhow 1.0.102 -> 1.0.104 (RUSTSEC-2026-0190), event-listener 5.4.1 -> 5.4.2 (RUSTSEC-2026-0221). Document the remaining informational advisories (gtk-rs 0.18 / unic-* via tauri 2) in audit.toml with a review date rather than ignoring them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- astro ^7.3.3 (critical AVIF RCE GHSA-26w7-cxv4-gfx2 + authz bypass) - dompurify ^3.4.15 - bounded overrides raised/added so the lock actually moves to the patched version in the consumers' major: fast-uri, js-yaml, hono, @hono/node-server, browserslist, baseline-browser-mapping, devalue, ip-address, nanoid, qs, sharp, svgo - brace-expansion 1.x/2.x/5.x bumped lock-only (per-major; bun overrides cannot target a major) All five previously ignored ids are fixed by these upgrades and removed. The one remaining suppression, vitest GHSA-82fw-gwwq-j7x9 (fix only in vitest 4, blocked by Storybook 10's bundled @vitest/spy 3 types), carries its reachability evidence and a reviewBy date; audit.ts now fails once any ignore passes its review date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Shironex
added a commit
that referenced
this pull request
Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Both required dependency-audit checks fail on
main:bun audit (Bun workspace)andcargo audit (Rust crate). That blocks every merge. PR #471 didn't cause either failure. This PR fixes them with real upgrades. One advisory is left suppressed, and it carries reachability evidence and a review date.No gate was weakened.
--audit-levelstays atmoderateand no workflow or ruleset changed.scripts/audit.tsis actually stricter now: every ignore needs areviewBydate, and the script fails once that date passes.How versions were moved (and proven)
astro,dompurify).>=patched <nextMajor, whichassertOverridesBoundedenforces.fast-uri >=3.1.4andjs-yaml >=4.3.0floors were still met by the vulnerable versions in the lock, so they never moved anything. They're now raised to the fixed versions.bun install --frozen-lockfileaccepts the lock byte-for-byte. Every resolved version below was read frombun.lock.@anthropic-ai/sdk0.105→0.127, so I didn't do that.Per advisory
cargo audit
The informational ones are documented in
.cargo/audit.tomlwith a review date.bun audit
^1.19.9)reviewBy: 2026-10-21moderategate; not touchedAll five previously ignored IDs are fixed by real upgrades and removed from the list.
Why vitest GHSA-82fw is suppressed, not fixed
The fix exists only in vitest ≥4.1.11. I tried that upgrade and reverted it:
@vitest/browser-playwright, andvitest/browserin place of@vitest/browser/context.@vitest/spy@3.2.4forstorybook/testfn(). That includes 10.6.0 and 11.0.0-alpha.1.vi.fn()passed to a composed story fails to type-check under vitest 4: 159 errors across 69 test files. That's a test-suite migration of its own.Exposure here: effectively unreachable.
mockerPlugin/interceptorPlugin, which is the unauthenticated path the advisory scores.allowedHosts, so DNS rebinding doesn't work. It also rejects browser-origin connections without the per-serverwebSocketToken.Runtime changes worth a look
apps/docsbuilds all 23 pages.Test plan
bun install --frozen-lockfile: lock unchangedbun run lint: lint-meta no violationsbun run typecheckand theapps/webtypecheckbun run audit: passes (1 dated suppression)cargo auditinapps/desktop/src-tauri: 0 vulnerabilitiesbun run test:all: node 2057 pass, web 2953 pass, plugin 15 pass, rust 1588 passterminal::session::tests::unconfined_command_sets_no_shell_state_redirect) fails when the parent shell exportsHISTFILE, as the Orca terminal does. It passes withHISTFILEunset. That's a pre-existing test-hermeticity issue, not caused by this PR.bun run check:rust(fmt, clippy, tests, ts-rs drift)bun run test:web:coverage: 78.3% statements / 80.8% lines, above the floorsbun run test:node:coverage: floor metapps/docsbuild🤖 Generated with Claude Code