Skip to content

fix(security): force @fastify/busboy >=3.2.2 and mute advisories with no patch - #368

Merged
elkaix merged 1 commit into
mainfrom
fix/security-audit-advisories
Oct 3, 2026
Merged

elkaix merged 1 commit into
mainfrom
fix/security-audit-advisories

Conversation

@elkaix

@elkaix elkaix commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Requirement or Bug

The Security workflow's pnpm audit job fails on main: 4 high advisories landed against the lockfile on 2026-10-02 (run 37114513875).

Bug Reproduction Steps

N/A — CI/dependency maintenance. On main: pnpm audit --json exits 1 with high: 4.

Root Cause

Two distinct situations:

  • @fastify/busboy (transitive via @fastify/multipart@10.0.0, pulled by fastify@5.12.5 in agent-gateway): two DoS advisories for <3.2.1, patched upstream in 3.2.1+. Fixable by a version floor.
  • http-cache-semantics@4.2.0 and braces@3.0.3: advisories published 2026-10-02 with no patched release existing (patched_versions: <0.0.0 on both; latest published versions are the vulnerable ones). A version floor cannot fix these.

This is a state fix, not a workaround for the busboy pair; the mutes below are a deliberate, documented workaround until upstream ships patches.

Code Changes

  • package.json → pnpm.overrides: add "@fastify/busboy": ">=3.2.1" following the existing security-floor pattern (undici, esbuild, fastify, …). Lockfile resolves 3.2.0 → 3.2.2.
  • package.json → new pnpm.auditConfig.ignoreGhsas: GHSA-ch52-4w7c-c8xp (http-cache-semantics) and GHSA-vfj7-8cjw-p6xm (braces) — the two advisories with no patched release. Drop both entries when upstream publishes fixed versions.
  • pnpm-lock.yaml: re-resolution from the new override.
  • flake.nix: pnpmDeps.hash refreshed for the new lockfile (empty-hash → got: procedure; nix build .#pythinker-code green locally).
  • apps/pythinker-code/dist-web/.web-bundle-manifest.json: restaged — pnpm-lock.yaml is an explicit input of the web-bundle fingerprint (apps/pythinker-code/scripts/web-bundle-manifest.mjs:39), so pnpm run build:web was rerun; bundle output itself is unchanged (497 files, identical bytes; only the manifest's source hash moved).

Note: the effective override set in this repo is root package.json pnpm.overrides; the overrides: block in pnpm-workspace.yaml is not applied by pnpm 10.34.3 (verified empirically — a workspace override did not trigger re-resolution), so the change goes where the live set is.

Behavior Changes and Affected Users

Behavior Before After Who relies on the old behavior Escape hatch
pnpm audit exit code 1 (4 high) 0 (0 actionable) CI Security job on every push/PR remove auditConfig.ignoreGhsas
@fastify/busboy version 3.2.0 3.2.2 none — patch bump inside @fastify/multipart's ^3.2.0 range none needed

No runtime behavior changes: the bump is a semver-compatible patch of a transitive multipart parser; no CLI, gateway, or web surface changes. Affected modules: dependency resolution only. Test coverage: pnpm audit exit code is the gate itself; node --test scripts/security/*.test.mjs passes (3/3); check-web-assets passes after restaging.

Checklist

  • Changeset evaluated — none written: a transitive dependency bump is not user-perceivable (gen-changesets §1).
  • pnpm audit --json exits 0 locally.
  • nix build .#pythinker-code green with refreshed hash.
  • node --test scripts/security/*.test.mjs green.
  • check-web-assets green; web bundle restaged in the same change.
  • Six required checks green on this PR.

Summary by CodeRabbit

  • Security
    • Updated an underlying request-handling component to require a newer version. No user-facing feature changes are included in this update.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Repository: PyModel/pythinker-code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3434c9f9-ca13-45e1-b41f-b6bd6d801ea2
📥 Commits

Reviewing files that changed from the base of the PR and between 8a76d79 and 866ef0e.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml, !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • apps/pythinker-code/dist-web/.web-bundle-manifest.json
  • flake.nix
  • package.json
 _______________________________________
< Nullus Bugus Maximus. No bug too big. >
 ---------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@elkaix
elkaix enabled auto-merge (squash) October 3, 2026 16:08
@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026

Copy link
Copy Markdown
pnpm dlx https://pkg.pr.new/@pymodel/pythinker-code@866ef0e
npx https://pkg.pr.new/@pymodel/pythinker-code@866ef0e

commit: 866ef0e

@elkaix
elkaix merged commit 6305545 into main Oct 3, 2026
26 of 27 checks passed
@elkaix
elkaix deleted the fix/security-audit-advisories branch October 3, 2026 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant