Skip to content

chore(deps): clear root workspace security alerts - #3363

Merged
thymikee merged 2 commits into
mainfrom
security/2026-10-10-root-deps
Oct 10, 2026
Merged

thymikee merged 2 commits into
mainfrom
security/2026-10-10-root-deps

Conversation

@thymikee

@thymikee thymikee commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

Clears every open root-workspace Dependabot alert. 6 files; no source changes.

Validation

At e61a2759a: pnpm install --frozen-lockfile clean; pnpm check:affected --run → all runnable checks passed. Limrun suites run directly: 33 files, 212 tests passed. Device lanes are GitHub-authoritative.

pnpm why -r <pkg>:

undici@7.29.1  (single copy, no override)
fast-uri@3.1.7
brace-expansion@5.0.12
tinypool@2.1.2   (└─┬ oxfmt@0.67.0 └── agent-device (devDependencies))
source-map-js@1.2.2

Size +4.7 kB unpacked (>3 kB threshold): bundled undici.js +4.26 kB is the 7.29.1 security patch itself; limrun log-stream.js/ios-client.js +0.4 kB from 0.60.0. Dropping either would reintroduce the vulnerability or the override.

examples/test-app alerts are out of scope.

🤖 Generated with Claude Code

View guided diff Turn on auto-fix

Bump undici 7.29.0 -> 7.29.1 (direct pins and override), fast-uri
override 3.1.6 -> 3.1.7, brace-expansion@5 override to ^5.0.12,
oxfmt ^0.64.0 -> ^0.67.0 (pulls tinypool 2.1.2), and refresh
source-map-js to 1.2.2.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-10-10 13:33 UTC

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

View guided diff | Turn on auto-fix | Re-trigger cubic

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Size Report

Metric Base Current Diff
Installed (including dependencies) 5.15 MB 5.15 MB +4.7 kB
Package (unpacked) 5.15 MB 5.15 MB +4.7 kB
Package (download) 1.55 MB 1.55 MB +1.4 kB

Startup median (7 runs, lower is better):

Scenario Base Current Diff
CLI --version 26.7 ms 26.6 ms -0.0 ms
CLI --help 82.1 ms 82.7 ms +0.6 ms

@limrun/api 0.60.0 pins undici 7.29.1, matching the direct pins, so the
transitive override is no longer needed. 0.61.0 is held back by pnpm's
default minimumReleaseAge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@thymikee

Copy link
Copy Markdown
Member Author

This PR is ready at e61a275. Checks are green (22 of 22), and the diff only touches manifests, the lockfile and workspace overrides. The limrun provider unit tests, the type-check and the bundled-undici size report all cover the changed packages. I read the lockfile text and diffed the @limrun/api tarball. I did not re-run pnpm install --frozen-lockfile or the test suites. I also did not diff the bundled undici output, so the +4.26 kB figure rests on the size-report comment and the version bump. I checked that the resolved versions are the patched ones the body names, but not the Dependabot alert numbers against GitHub's alert state. I did not confirm that oxfmt 0.67 leaves formatting unchanged, and I only have the green format check in CI for that. There are no conflicts, and nothing else needs to happen before merge once maintainers accept it. Not blocking, take or leave: the note on why undici is pinned exactly (tsdown bundles it, so a caret would let lockFileMaintenance move shipped bytes) went away with the override, so the policy for the exact pins in package.json, maestro and provision-kit is now written nowhere, and a one-line note could keep it. Also, with the undici@7 override gone, the transitive copy under @limrun/api and @ai-sdk/provider-utils stays at 7.29.1 only because those packages pin it, so re-add the override if a later @limrun/api release regresses.

@thymikee thymikee added the ready-for-human Valid work that needs human implementation, judgment, or maintainer merge label Oct 10, 2026
@thymikee
thymikee merged commit e6a774a into main Oct 10, 2026
22 checks passed
@thymikee
thymikee deleted the security/2026-10-10-root-deps branch October 10, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-human Valid work that needs human implementation, judgment, or maintainer merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant