Skip to content

fix(deps): remediate Undici advisories - #12513

Closed
rsliter wants to merge 4 commits into
mainfrom
codex/security-undici-advisories
Closed

rsliter wants to merge 4 commits into
mainfrom
codex/security-undici-advisories

Conversation

@rsliter

@rsliter rsliter commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Outcome

NemoClaw now remediates the reviewed Undici advisories in the root OpenClaw 2026.9.1 archive and its Discord and Slack plugin bundles. Managed image builds cache the reviewed replacement archives for offline installation.

Reason

Updating the root dependency alone leaves vulnerable Undici copies inside signed OpenClaw plugin archives. The build and installed-plugin paths must replace those copies without weakening package provenance checks.

Changes

  • Update the root runtime dependency and lock data to Undici 8.10.2.
  • Replace the reviewed OpenClaw, Discord, and Slack archive copies with Undici 8.10.2 or 7.29.1 as their dependency lines require.
  • Patch installed official Discord and Slack packages after provenance verification. Direct dependency updates cannot change bundled files inside those packages.
  • Reject package identity, dependency graph, engine, symlink, or tree-integrity drift before replacement.
  • Add the reviewed replacement archives to the managed image offline cache.
  • Protect the remediation with archive, installed-package, offline-cache, messaging-build, audit, and package-contract tests.

Verification

  • npx vitest run --project integration test/agents/openclaw/openclaw-2026-9-undici-remediation.test.ts test/runtime/messaging/messaging-build-applier.test.ts - 41 tests passed.
  • npx vitest run --project integration test/runtime/messaging/messaging-build-applier-integrity.test.ts - 6 tests passed.
  • npx vitest run --project integration test/agents/openclaw/openclaw-managed-messaging-offline-build.test.ts - 4 tests passed.
  • npx vitest run --project integration test/automation/pull-requests/growth-guardrails.test.ts test/agents/openclaw/openclaw-2026-9-undici-remediation.test.ts - 15 tests passed.
  • npx vitest run --project package-contract test/package-contract/managed-image-registry-transport.test.ts - passed.
  • npm run source-shape:check - passed with no new source-shape cases.
  • npm run build:cli - passed.
  • npm --prefix nemoclaw run build - passed.
  • NODE_OPTIONS=--max-old-space-size=8192 npm run typecheck:cli - passed.
  • git diff --check origin/main...HEAD - passed.
  • The diff contains no secrets, API keys, or credentials.

Review notes

This draft is the approved Pi qualification seed. The changed image inputs require Linux AMD64 and ARM64 candidate receipts from this PR commit and one workflow run. The PR must remain draft until those receipts are committed and the normal publication gate passes without the seed exception.

The local seed publication skipped the Pi receipt refresh check and inherited Hadolint findings. All other selected repository checks passed. CI will provide the candidate image evidence needed to remove the Pi exception.


Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com

Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
@rsliter rsliter self-assigned this Sep 30, 2026
@copy-pr-bot

copy-pr-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

@github-code-quality

github-code-quality Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 1dc162e in the codex/security-undic... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd codex/security-undic... 1dc162e +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 1dc162e in the codex/security-undic... branch is 85%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd codex/security-undic... 1dc162e +/-
src/lib/actions.../status-text.ts 84% 46% -38%
src/lib/onboard...al-inference.ts 84% 90% +6%
src/lib/inferen...file/cleanup.ts 73% 80% +7%
src/lib/state/p...l-retirement.ts 79% 89% +10%
src/lib/readine...y-production.ts 76% 90% +14%
src/lib/onboard.../application.ts 55% 72% +17%
src/lib/onboard...mage/catalog.ts 69% 90% +21%
src/lib/securit...zer-boundary.ts 0% 85% +85%
src/lib/onboard...ternal-image.ts 0% 94% +94%
src/lib/securit...ig-structure.ts 0% 94% +94%

Updated September 30, 2026 16:30 UTC

Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
@rsliter

rsliter commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Maintainer context:

This remains a valid focused Undici remediation. It updates the root OpenClaw runtime and the bundled Slack and Discord plugin paths, including offline and installed-plugin remediation.

It is not a complete repository-wide dependency or CI unblocker. It does not repair the separate brace-expansion advisories, the Debian OpenSSL image-pin drift, or unrelated E2E artifact failures. PR #12507 is a competing, broader implementation that includes those additional repairs. PR #12517 is the independent trusted-audit prerequisite currently written around #12507's reviewed inputs.

Maintainer intent is to preserve and merge this focused fix if exact-head evidence shows that it does not regress unrelated behavior and the required independent trust and CI gates are satisfied. Do not bypass red required checks. If #12507 lands first, re-evaluate this PR against main before merging to avoid duplicating or conflicting with the broader repair.

@rsliter

rsliter commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Closing in favor of continuing the broader repair in #12507.

#12513 remains a valid focused Undici remediation. Its candidate-owned tests, all twelve CLI shards, type checks, installer tests, plugin tests, CodeQL, and CodeRabbit passed on 1dc162e5. It updates the root OpenClaw runtime and bundled Slack and Discord paths while retaining OpenClaw 2026.9.1.

#12507 is the more complete candidate because it also addresses brace-expansion, OpenSSL image pins, interrupted and overlapping patch recovery, and related E2E artifact failures. It is not ready to merge yet. Before selection, it must restore the independent trusted-base audit boundary removed by 73a4b590, resolve the OpenClaw 2026.9.2 scope decision, refresh Pi qualification receipts, and obtain clean exact-head CI, Advisor, and human review.

Reopen #12513 if #12507 stalls, cannot restore the trusted audit boundary, or the broader OpenClaw upgrade is declined and the focused 2026.9.1 remediation is needed as the fallback.

@rsliter rsliter closed this Sep 30, 2026
@wscurran wscurran added area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior platform: container Affects Docker, containerd, Podman, or images labels Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior platform: container Affects Docker, containerd, Podman, or images

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants