Skip to content

Raise transitive dependency security floors - #1203

Merged
zxxma merged 1 commit into
mainfrom
chore/security-dependency-floors-20260915
Sep 15, 2026
Merged

zxxma merged 1 commit into
mainfrom
chore/security-dependency-floors-20260915

Conversation

@zxxma

@zxxma zxxma commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Raise the pnpm Hono floor to >=4.13.5 (locked at 4.13.8) and the Vitest floor to >=4.1.11 <5; align both workspace Vitest declarations and its internal packages at 4.1.11. The upper bound prevents an unrelated major test-runner migration.
  • Update indirect gRPC-Go to 1.83.2 and its required x/net, x/crypto and x/text versions; canonicalize Go checksums.
  • Addresses affected versions in Dependabot alerts v2.20.0: CI chain fix, gnolove filter extraction, docs sweep #159–feat: REST proxy endpoints for ABCI queries #164 (five distinct upstream advisories). No exploitable application entrypoint was established; this is dependency hardening.
  • Based on merged Complete the professional frontend design rollout #1200. Seven files only, including the changelog. No application source, frontend npm lockfile, workflow, Gno pin, wallet-policy or deployment-setting changes.

Test plan

  • Frozen pnpm install, all workspace builds, and 42 workspace tests on Node 22 and Node 20.
  • Audit gate self-tests: 24 pass. Full pnpm audit: zero vulnerabilities at every severity; CI audit gate passes.
  • Bounded dependency-level before/after regressions and valid-input controls for the updated libraries; no production services or personal browser profiles used.
  • Go build, full uncached race/coverage suite (47.2%), and golangci-lint 2.12.2 (zero issues).
  • govulncheck 1.3.0: zero reachable symbol/package vulnerabilities; the targeted gRPC advisory is absent. Nine other module-only advisories remain outside the imported vulnerable packages/call paths.
  • Frontend Node 22 full coverage suite: 5,185 pass, one skipped; 76.82% statement coverage, with pinned Gno checks enabled.
  • Frontend Node 20 full compatibility suite: 5,185 pass, one skipped.
  • Frontend Node 20/22 builds, lint, bundle isolation and unchanged verify-worker regeneration; production/build audit gates pass.
  • Full Chromium E2E: 230 pass, seven skipped. Desktop/iPhone/Pixel guardrails: 59 pass.
  • Hosted CI on 421b2b41: backend, Node 20/22 frontend, full Chromium E2E, guardrails, Docker, Proto, workspace build/tests/audit, dependency review, changelog, CodeQL and Go security scan all pass.
  • Final approving review (normal branch protection requires one approval).

Real Adena acceptance remains skipped by owner decision. No mainnet realms are deployed by this PR. Alerts should close after default-branch merge and refreshed dependency scanning; none were dismissed.

Netlify explicitly canceled this head's preview; its success status is not evidence of a deployed preview. No preview smoke pass is claimed. Final-tree local browser tests and hosted E2E passed.

@netlify

netlify Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for memba-multisig canceled.

Name Link
🔨 Latest commit 421b2b4
🔍 Latest deploy log https://app.netlify.com/projects/memba-multisig/deploys/6aa9258142dc8300082fe2df

@github-actions

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow CI / proto (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedSep 15, 2026, 11:01 AM

@zxxma
zxxma merged commit 6f3142a into main Sep 15, 2026
23 checks passed
@zxxma
zxxma deleted the chore/security-dependency-floors-20260915 branch September 15, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant