fix(security): force @fastify/busboy >=3.2.2 and mute advisories with no patch - #368
Merged
Merged
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
elkaix
enabled auto-merge (squash)
October 3, 2026 16:08
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requirement or Bug
The
Securityworkflow'spnpm auditjob fails onmain: 4 high advisories landed against the lockfile on 2026-10-02 (run 37114513875).Bug Reproduction Steps
N/A — CI/dependency maintenance. On
main:pnpm audit --jsonexits 1 withhigh: 4.Root Cause
Two distinct situations:
@fastify/busboy(transitive via@fastify/multipart@10.0.0, pulled byfastify@5.12.5in agent-gateway): two DoS advisories for<3.2.1, patched upstream in 3.2.1+. Fixable by a version floor.http-cache-semantics@4.2.0andbraces@3.0.3: advisories published 2026-10-02 with no patched release existing (patched_versions: <0.0.0on both; latest published versions are the vulnerable ones). A version floor cannot fix these.This is a state fix, not a workaround for the busboy pair; the mutes below are a deliberate, documented workaround until upstream ships patches.
Code Changes
package.json→pnpm.overrides: add"@fastify/busboy": ">=3.2.1"following the existing security-floor pattern (undici,esbuild,fastify, …). Lockfile resolves 3.2.0 → 3.2.2.package.json→ newpnpm.auditConfig.ignoreGhsas:GHSA-ch52-4w7c-c8xp(http-cache-semantics) andGHSA-vfj7-8cjw-p6xm(braces) — the two advisories with no patched release. Drop both entries when upstream publishes fixed versions.pnpm-lock.yaml: re-resolution from the new override.flake.nix:pnpmDeps.hashrefreshed for the new lockfile (empty-hash →got:procedure;nix build .#pythinker-codegreen locally).apps/pythinker-code/dist-web/.web-bundle-manifest.json: restaged —pnpm-lock.yamlis an explicit input of the web-bundle fingerprint (apps/pythinker-code/scripts/web-bundle-manifest.mjs:39), sopnpm run build:webwas rerun; bundle output itself is unchanged (497 files, identical bytes; only the manifest's source hash moved).Note: the effective override set in this repo is root
package.jsonpnpm.overrides; theoverrides:block inpnpm-workspace.yamlis not applied by pnpm 10.34.3 (verified empirically — a workspace override did not trigger re-resolution), so the change goes where the live set is.Behavior Changes and Affected Users
pnpm auditexit codeauditConfig.ignoreGhsas@fastify/busboyversion@fastify/multipart's^3.2.0rangeNo runtime behavior changes: the bump is a semver-compatible patch of a transitive multipart parser; no CLI, gateway, or web surface changes. Affected modules: dependency resolution only. Test coverage:
pnpm auditexit code is the gate itself;node --test scripts/security/*.test.mjspasses (3/3);check-web-assetspasses after restaging.Checklist
pnpm audit --jsonexits 0 locally.nix build .#pythinker-codegreen with refreshed hash.node --test scripts/security/*.test.mjsgreen.check-web-assetsgreen; web bundle restaged in the same change.Summary by CodeRabbit