Skip to content

fix(deps): clear bun audit and cargo audit advisories - #472

Merged
Shironex merged 2 commits into
mainfrom
Shironex/harvest-w6-l6-audit
Sep 21, 2026
Merged

Shironex merged 2 commits into
mainfrom
Shironex/harvest-w6-l6-audit

Conversation

@Shironex

Copy link
Copy Markdown
Collaborator

Summary

Both required dependency-audit checks fail on main: bun audit (Bun workspace) and cargo audit (Rust crate). That blocks every merge. PR #471 didn't cause either failure. This PR fixes them with real upgrades. One advisory is left suppressed, and it carries reachability evidence and a review date.

No gate was weakened. --audit-level stays at moderate and no workflow or ruleset changed. scripts/audit.ts is actually stricter now: every ignore needs a reviewBy date, and the script fails once that date passes.

How versions were moved (and proven)

  • Direct deps: raised the manifest floor (astro, dompurify).
  • Single-major transitive deps: added or raised a bounded override, >=patched <nextMajor, which assertOverridesBounded enforces.
    • The old fast-uri >=3.1.4 and js-yaml >=4.3.0 floors were still met by the vulnerable versions in the lock, so they never moved anything. They're now raised to the fixed versions.
  • brace-expansion (at 1.x, 2.x and 5.x): I updated the three lock entries to the patched version in each major. Their dependency sets are identical. Bun overrides can't target a single major, and forcing one major breaks the 1.x consumers (fix(deps+ci): clear the critical + 3 highs, tolerate the 5 unfixable by id #411).
  • Proof: bun install --frozen-lockfile accepts the lock byte-for-byte. Every resolved version below was read from bun.lock.
  • The lock diff covers only the target packages plus the new deps they require. Deleting lock entries would have re-resolved the whole tree, including @anthropic-ai/sdk 0.105→0.127, so I didn't do that.

Per advisory

cargo audit

Advisory Crate Outcome
RUSTSEC-2026-0285 rustls upgraded 0.23.42 → 0.23.45
RUSTSEC-2026-0190 anyhow upgraded 1.0.102 → 1.0.104
RUSTSEC-2026-0221 event-listener upgraded 5.4.1 → 5.4.2
RUSTSEC-2024-0370 (unmaintained), RUSTSEC-2024-0429 (unsound) proc-macro-error, glib 0.18 warning, not ignored. gtk-rs 0.18 via muda/wry ← tauri 2; Linux build only (absent from macOS/Windows trees)
RUSTSEC-2025-0075/0080/0081/0098/0100 (unmaintained) unic-* warning, not ignored. urlpattern 0.3 ← tauri-utils 2.9.3 (latest 2.x); parses only our bundled capability config

The informational ones are documented in .cargo/audit.toml with a review date.

bun audit

Advisory Package Outcome
GHSA-26w7-cxv4-gfx2 (critical RCE), GHSA-376h-93r7-7g6f astro upgraded 7.1.6 → 7.3.3
GHSA-5jgf, -f65p, -fph4, -jqff, -7p8r fast-uri upgraded 3.1.4 → 3.1.8
GHSA-mwp4, -4xrf, -22jq ip-address upgraded 10.2.0 → 10.7.2
GHSA-mh99 (was ignored), GHSA-rgw5 brace-expansion upgraded 1.1.16/2.1.2/5.0.8 → 1.1.21/2.1.7/5.0.12
GHSA-c83g, -73wf browserslist upgraded 4.28.2 → 4.29.0
GHSA-5p4m, -2883 js-yaml upgraded 4.3.0 → 4.3.2
GHSA-2v37 nanoid upgraded 3.3.16 → 3.3.19
GHSA-rgj7 (libheif) sharp upgraded 0.35.3 → 0.35.4
GHSA-w27v, -4vpr svgo upgraded 4.0.2 → 4.1.0
GHSA-55q2, -c2j3 dompurify upgraded 3.4.11 → 3.4.15
GHSA-frvp (was ignored) @hono/node-server upgraded 1.19.14 → 1.19.17 (stays 1.x; the MCP SDK declares ^1.19.9)
GHSA-xgm2/-hvrm/-w62v (were ignored), -8j4g, -f23p, -54fx, -gqvv, -g6gw, -crvj, -79qm hono upgraded 4.12.26 → 4.13.8
GHSA-w5vr baseline-browser-mapping upgraded 2.10.38 → 2.11.25
GHSA-9rgm devalue upgraded 5.8.2 → 5.9.4
GHSA-x5fp, -4mjr qs upgraded 6.15.2 → 6.16.0
GHSA-82fw-gwwq-j7x9 (moderate) vitest / @vitest/mocker 3.2.7 suppressed with reason (see below), reviewBy: 2026-10-21
GHSA-g7r4 (low) esbuild 0.27.7 below the moderate gate; not touched

All five previously ignored IDs are fixed by real upgrades and removed from the list.

Why vitest GHSA-82fw is suppressed, not fixed

The fix exists only in vitest ≥4.1.11. I tried that upgrade and reverted it:

  • The provider and entry-point changes are easy: @vitest/browser-playwright, and vitest/browser in place of @vitest/browser/context.
  • The blocker: Storybook 10 bundles @vitest/spy@3.2.4 for storybook/test fn(). That includes 10.6.0 and 11.0.0-alpha.1.
  • So every vi.fn() passed to a composed story fails to type-check under vitest 4: 159 errors across 69 test files. That's a test-suite migration of its own.

Exposure here: effectively unreachable.

  • vitest is test tooling only and never ships.
  • Nothing imports the public mockerPlugin/interceptorPlugin, which is the unauthenticated path the advisory scores.
  • The only listener sits on Vite 7.3.5's HMR socket. That socket binds to localhost and enforces allowedHosts, so DNS rebinding doesn't work. It also rejects browser-origin connections without the per-server webSocketToken.
  • What's left is a same-user local process during a test run, which could read those files anyway, or an ephemeral CI runner.

Runtime changes worth a look

  • astro 7.3.3 (docs site only): compiler-rs 0.4 and markdown-satteri 0.4. apps/docs builds all 23 pages.
  • dompurify 3.4.15 is in the web sanitizer path (patch release).
  • hono 4.13 and @hono/node-server 1.19.17 sit under the agent SDK's MCP transport.
  • rustls 0.23.45 is a patch release.

Test plan

  • bun install --frozen-lockfile: lock unchanged
  • bun run lint: lint-meta no violations
  • bun run typecheck and the apps/web typecheck
  • bun run audit: passes (1 dated suppression)
  • cargo audit in apps/desktop/src-tauri: 0 vulnerabilities
  • bun run test:all: node 2057 pass, web 2953 pass, plugin 15 pass, rust 1588 pass
    • Locally, one Rust test (terminal::session::tests::unconfined_command_sets_no_shell_state_redirect) fails when the parent shell exports HISTFILE, as the Orca terminal does. It passes with HISTFILE unset. That's a pre-existing test-hermeticity issue, not caused by this PR.
  • bun run check:rust (fmt, clippy, tests, ts-rs drift)
  • bun run test:web:coverage: 78.3% statements / 80.8% lines, above the floors
  • bun run test:node:coverage: floor met
  • apps/docs build
  • CI: all 6 required checks

🤖 Generated with Claude Code

Shironex and others added 2 commits September 21, 2026 12:43
Lockfile bumps within semver: rustls 0.23.42 -> 0.23.45 (RUSTSEC-2026-0285),
anyhow 1.0.102 -> 1.0.104 (RUSTSEC-2026-0190), event-listener 5.4.1 -> 5.4.2
(RUSTSEC-2026-0221). Document the remaining informational advisories
(gtk-rs 0.18 / unic-* via tauri 2) in audit.toml with a review date rather
than ignoring them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- astro ^7.3.3 (critical AVIF RCE GHSA-26w7-cxv4-gfx2 + authz bypass)
- dompurify ^3.4.15
- bounded overrides raised/added so the lock actually moves to the patched
  version in the consumers' major: fast-uri, js-yaml, hono,
  @hono/node-server, browserslist, baseline-browser-mapping, devalue,
  ip-address, nanoid, qs, sharp, svgo
- brace-expansion 1.x/2.x/5.x bumped lock-only (per-major; bun overrides
  cannot target a major)

All five previously ignored ids are fixed by these upgrades and removed.
The one remaining suppression, vitest GHSA-82fw-gwwq-j7x9 (fix only in
vitest 4, blocked by Storybook 10's bundled @vitest/spy 3 types), carries
its reachability evidence and a reviewBy date; audit.ts now fails once
any ignore passes its review date.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Shironex Shironex added dependencies Pull requests that update a dependency file rust Pull requests that update rust code javascript Pull requests that update javascript code security Sandbox, confinement, injection defense, permissions labels Sep 21, 2026
@Shironex
Shironex merged commit 92132a6 into main Sep 21, 2026
15 checks passed
@Shironex
Shironex deleted the Shironex/harvest-w6-l6-audit branch September 21, 2026 11:12
@github-project-automation github-project-automation Bot moved this from Todo to Done in Nightcore Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code rust Pull requests that update rust code security Sandbox, confinement, injection defense, permissions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant