Skip to content

fix(deps): security batch — nanoid, tmp, vitest - #84

Merged
haydenshively merged 1 commit into
mainfrom
deps/batch/security-2026-10-01
Oct 1, 2026
Merged

haydenshively merged 1 commit into
mainfrom
deps/batch/security-2026-10-01

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Opened by fix-vulnerable-deps

Fixes: nanoid — GHSA-2v37-7h3g-55p8 (HIGH)
Fixes: tmp — GHSA-ph9p-34f9-6g65 (HIGH), GHSA-52f5-9888-hmc6 (LOW)
Fixes: vitest, @vitest/mocker — GHSA-82fw-gwwq-j7x9 (MODERATE)

Linear: APPS-1643

Summary

  • vitest / @vitest/* 4.1.10 → 4.1.11: exact devDependency pin raised (lowest fix, same major).
  • nanoid 3.3.16 → 3.3.18 (root, via postcss → vite): lockfile-only. With resolutionMode: time-based, the vitest bump moves the cutoff past 3.3.18's release, so no override is needed.
  • tmp 0.0.33 → 0.2.7 (playground, via solc): solc 0.8.36 → 0.8.37 lockfile-only, plus a new playground override tmp: ^0.2.7. solc 0.8.37 pins tmp to exactly 0.2.6, which has its own HIGH advisory (GHSA-7c78-jf6q-g5cm, 0.2.6 only, fixed 0.2.7), hence the override. solc only uses tmp in smtsolver.js (fileSync / removeCallback, same API in 0.2.x); the playground uses soljson.js. Side effect: the playground's in-browser compiler moves to solc 0.8.37.

All dev / CI / playground-build only; nothing here reaches the published dist.

Not in this PR: undici 6.28.0 (GHSA-rfgv-xxqx-mfg5 HIGH +2) — 6.28.1 can't be resolved under time-based resolution without an unrelated direct-dependency move; tracked in APPS-1644.

vet: pass (integrity, release age ≥ 7 days, no install scripts, publishers and provenance unchanged; solc's generated soljson.js bundle not read in full).

Checks run locally: pnpm install, pnpm exec biome check ., pnpm typecheck, pnpm -C playground install --frozen-lockfile, pnpm -C playground typecheck, pnpm -C playground build, pnpm test (Node 24: 685 passed, 1 skipped). Fix check: OSV rescan of both lockfiles — no advisory for nanoid, tmp or vitest remains; only undici@6.28.0 (out of scope above).

Details
  • Not run locally: pnpm test:forge and gas snapshot (forge couldn't download solc in the worker sandbox); no JS dependency involved — CI runs them.
  • Resolved changes: root @vitest/{expect,mocker,pretty-format,runner,snapshot,spy,utils} and vitest 4.1.10 → 4.1.11, nanoid 3.3.16 → 3.3.18; playground solc 0.8.36 → 0.8.37, tmp 0.0.33 → 0.2.7, os-tmpdir removed.
  • Override rung: new override, because the parent's newest release (solc 0.8.37) still pins an affected tmp.

Link to Devin session: https://app.devin.ai/sessions/c03e309c251c4ec79482e12352bd61fd
Open in Devin Desktop: https://app.devin.ai/desktop/session/c03e309c251c4ec79482e12352bd61fd?variant=devin

@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@haydenshively
haydenshively added this pull request to stack #86 October 1, 2026 19:25
- vitest 4.1.10 -> 4.1.11 (GHSA-82fw-gwwq-j7x9)
- nanoid 3.3.16 -> 3.3.18, lockfile-only (GHSA-2v37-7h3g-55p8)
- playground: solc 0.8.36 -> 0.8.37 (lockfile-only) and tmp override ^0.2.7
  (GHSA-ph9p-34f9-6g65, GHSA-52f5-9888-hmc6; 0.2.7 also fixes GHSA-7c78-jf6q-g5cm)

Refs APPS-1643

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration
devin-ai-integration Bot force-pushed the deps/batch/security-2026-10-01 branch from 9a99429 to eaa40e6 Compare October 1, 2026 20:00
@haydenshively
haydenshively merged commit 53f54ae into main Oct 1, 2026
3 checks passed
@haydenshively
haydenshively deleted the deps/batch/security-2026-10-01 branch October 1, 2026 20:07
haydenshively pushed a commit that referenced this pull request Oct 1, 2026
Opened by fix-vulnerable-deps

Stacked on #84

Fixes: ws — AIKIDO-2026-138234 (HIGH)

Linear: APPS-1649

## Summary
- `ws` 8.21.0 → 8.21.1 in both `pnpm-lock.yaml` and
`playground/pnpm-lock.yaml`, via a new override `ws: 8.21.1` in both
`pnpm-workspace.yaml` files (the playground duplicates the root's
settings).
- Override rung: every viem release up to 2.57.2 pins `ws` to exactly
8.21.0 (through `viem` and `isows`), so moving the parent doesn't help.
8.21.1 is the lowest fixed version on the 8.x line (released 2026-07-14,
past the 7-day gate). Remove the override once viem ships a fixed `ws`.
- Pulled in by `viem` (dev/peer dependency) for tests and the playground
build; nothing here reaches the published `dist`.

vet: pass (integrity, release age ≥ 7 days, no install scripts, same
publisher and repo; upstream diff is the fragment-count fix in
`lib/receiver.js` plus lower default
`maxFragments`/`maxBufferedChunks`).

Checks run locally: `pnpm install`, `pnpm exec biome check .`, `pnpm
typecheck`, `pnpm -C playground install --frozen-lockfile`, `pnpm -C
playground typecheck`, `pnpm -C playground build`, `pnpm test` (Node 24:
685 passed, 1 skipped). Fix check: no `ws` < 8.21.1 resolves in either
lockfile (OSV has no record of this Aikido advisory); OSV rescan of both
lockfiles finds only undici 6.28.0 (tracked in APPS-1644).

<details><summary>Details</summary>

- Not run locally: `pnpm test:forge` and gas snapshot (forge couldn't
download solc in the worker sandbox); no JS dependency involved, CI runs
them.
- Lockfile changes: `ws` 8.21.0 → 8.21.1 and the `isows`/`viem` snapshot
references to it; `isows`'s peer `ws` entry becomes `8.21.1`. No
packages added or removed.
- Aikido lists fixed versions 5.2.6, 6.2.5, 7.5.12 and 8.21.1 without
affected ranges, so every resolved `ws` below 8.21.1 was treated as
affected.
</details>


Link to Devin session:
https://app.devin.ai/sessions/55aa92b588e74674b9f2a00333d2813f
Open in Devin Desktop:
https://app.devin.ai/desktop/session/55aa92b588e74674b9f2a00333d2813f?variant=devin

---------

Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant