Skip to content

fix(deps): security batch — ws - #85

Merged
haydenshively merged 2 commits into
deps/batch/security-2026-10-01from
deps/batch/security-2026-10-01-2
Oct 1, 2026
Merged

haydenshively merged 2 commits into
deps/batch/security-2026-10-01from
deps/batch/security-2026-10-01-2

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Opened by fix-vulnerable-deps

Stacked on #84

Fixes: ws — AIKIDO-2026-138234 (HIGH)

Linear: APPS-1649

Summary

  • ws 8.21.0 → 8.21.1 in both pnpm-lock.yaml and playground/pnpm-lock.yaml, via a new override ws: 8.21.1 in both pnpm-workspace.yaml files (the playground duplicates the root's settings).
  • Override rung: every viem release up to 2.57.2 pins ws to exactly 8.21.0 (through viem and isows), so moving the parent doesn't help. 8.21.1 is the lowest fixed version on the 8.x line (released 2026-07-14, past the 7-day gate). Remove the override once viem ships a fixed ws.
  • Pulled in by viem (dev/peer dependency) for tests and the playground build; nothing here reaches the published dist.

vet: pass (integrity, release age ≥ 7 days, no install scripts, same publisher and repo; upstream diff is the fragment-count fix in lib/receiver.js plus lower default maxFragments/maxBufferedChunks).

Checks run locally: pnpm install, pnpm exec biome check ., pnpm typecheck, pnpm -C playground install --frozen-lockfile, pnpm -C playground typecheck, pnpm -C playground build, pnpm test (Node 24: 685 passed, 1 skipped). Fix check: no ws < 8.21.1 resolves in either lockfile (OSV has no record of this Aikido advisory); OSV rescan of both lockfiles finds only undici 6.28.0 (tracked in APPS-1644).

Details
  • Not run locally: pnpm test:forge and gas snapshot (forge couldn't download solc in the worker sandbox); no JS dependency involved, CI runs them.
  • Lockfile changes: ws 8.21.0 → 8.21.1 and the isows/viem snapshot references to it; isows's peer ws entry becomes 8.21.1. No packages added or removed.
  • Aikido lists fixed versions 5.2.6, 6.2.5, 7.5.12 and 8.21.1 without affected ranges, so every resolved ws below 8.21.1 was treated as affected.

Link to Devin session: https://app.devin.ai/sessions/55aa92b588e74674b9f2a00333d2813f
Open in Devin Desktop: https://app.devin.ai/desktop/session/55aa92b588e74674b9f2a00333d2813f?variant=devin

@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@linear-code

linear-code Bot commented Oct 1, 2026

Copy link
Copy Markdown

APPS-1649

@haydenshively
haydenshively added this pull request to stack #86 October 1, 2026 19:25
@haydenshively

Copy link
Copy Markdown
Collaborator

Devin can you make sure your commits are signed across this stack?

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration
devin-ai-integration Bot force-pushed the deps/batch/security-2026-10-01-2 branch from e2eb55e to 69294bf Compare October 1, 2026 20:00
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

@haydenshively Done. Two commits in the stack were signed with a key GitHub didn't recognise (9a99429 on #84, e2eb55e here). I recreated all three stack commits through the GitHub API, keeping the same trees and messages, and force-pushed both branches with a lease. GitHub now shows every commit as Verified: #84 eaa40e6; #85 6acc4d6 and 69294bf. The file contents are byte-identical, and CI passes on both PRs.

@haydenshively
haydenshively merged commit 2193e38 into main Oct 1, 2026
4 of 5 checks passed
@haydenshively
haydenshively deleted the deps/batch/security-2026-10-01-2 branch October 1, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant