Skip to content

deps: clear the open Oneleet dependency-scanning findings (undici, provider-utils, x/sys and friends) - #5823

Open
olartgabo wants to merge 7 commits into
mainfrom
olartgabo/dep-bumps-oneleet
Open

olartgabo wants to merge 7 commits into
mainfrom
olartgabo/dep-bumps-oneleet

Conversation

@olartgabo

@olartgabo olartgabo commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

What

The Oneleet monitor "Dependency scanning findings are resolved" feeds the failing Vulnerabilities remediated control; this repo carries 36 of the 49 open findings. #5684 already cleared qs/body-parser/@babel/core/@hono/node-server and pinned claude-code-action. This PR clears everything left that has a non-breaking fix:

  • undici 6.28.0 → 6.29.0, 7.29.0 → 7.29.1/7.30.0. miniflare pins undici exactly, so it moves via miniflare 5.20261001.0-alpha / wrangler 4.147.0.
  • @ai-sdk/provider-utils: every copy now 3.0.30 or ≥4.0.33 (the CVE-2026-8769 fix floors). Trap: the 3.x line grew an undici ^5.29.0 dependency at 3.0.35, and undici 5 has no fixed release — naively updating would have added 13 undici-5 findings (that is exactly the backend's current state). 3.0.30 is the newest 3.x that is patched and undici-free. The v2-line providers pin provider-utils exactly and npm overrides don't rewrite exact pins, so sdk/package.json pins each provider to its newest clean release; a root override (@ai-sdk/provider-utils@^3.0.0 → 3.0.30) covers range consumers (ollama-ai-provider-v2).
  • ai pinned at 6.0.214 (its own fix floor). Bisected: ai ≥ 6.0.259 breaks the sdk's HostRunner stopWhen/timeout integration tests (tool calls stop executing, timeout abort not surfaced) and the eval-git provenance test. Lifting the pin needs a HostRunner-vs-ai investigation — follow-up, not this PR.
  • brace-expansion 2.1.7 / 5.0.12, ip-address 10.7.3, fast-uri 3.1.8.
  • Go launcher: golang.org/x/sys v0.44.0 (CVE-2026-39824 fix floor). x/sys ≥0.44 forces go >= 1.25, which flips the winsymlink GODEBUG default and broke the launcher's junction-resolution tests; godebug winsymlink=0 pins the behavior the shipped launcher has always had (old directive was go 1.22; CI pins Go 1.27.1 so the directive bump is safe).

Deliberately not fixed here: @opentelemetry/core 1.30.1 (CVE-2026-54285) — the fix only ships in the @sentry/node 11 major; needs its own PR.

Verification (Windows, NODE_OPTIONS=--max-old-space-size=8192, --script-shell=bash)

  • npm run docs:check-tokens, npm run typecheck, npm run typecheck:client -w @mcpjam/inspector, npm run test:checks, npm run build:inspector — all exit 0.
  • npm run test -w @mcpjam/sdk: Tests 2 failed | 9434 passed | 8 skipped (9444) — the 2 are Windows-local (symlink EPERM, temp-dir EBUSY) and fail identically on main's deps on this machine.
  • npm run test -w @mcpjam/inspector: failing-file set is byte-identical to a baseline run on main's deps on this machine (Windows-inherited harness/browserd failures); same for @mcpjam/cli (6 file-permission tests).
  • @mcpjam/chat-ui 135/135, @mcpjam/evaluators, @mcpjam/vitest, @mcpjam/mcp test:fast — exit 0.
  • Go: go build ./... && go test ./... in the launcher module — ok.
  • Lockfile: npm ls undici @ai-sdk/provider-utils exit 0; remaining versions: undici {6.29.0, 7.29.1, 7.30.0}, provider-utils {3.0.30, 4.0.33, 4.0.57, 5.0.34}.

Companion backend PR applies the same provider pins via overrides until @mcpjam/sdk ships this change.

Update: GitHub Dependabot alerts (8d61afa)

The Oneleet monitor "GitHub Dependabot alerts are addressed" counts 45 open alerts, all measured against main. Checked against this branch's lockfiles, 25 are already fixed by the commits above (undici ×13, brace-expansion ×7, ip-address ×2, @ai-sdk/provider-utils ×2, fast-uri). The new commit fixes 4 more with in-range updates:

14 stay open because each needs a major bump, and each gets its own PR:

  • vitest / @vitest/mocker ×13 (root, brightdata, conformance/basic lockfiles, plus the vitest range in 7 workspace package.json files: chat-ui, evaluators, mcp, mcpjam-inspector, sdk, vitest, widget-react). The fix is vitest 4.1.11; the repo is on 3.2.7. @mcpjam/vitest declares a >=3.2.0 <4 peer range that has to widen too.
  • @opentelemetry/core (npm #508). 1.30.1 is pinned by @sentry/node 8 and by @sentry/electron 5 (which bundles @sentry/node 8.55.0). @sentry/node ≥10 uses OTel 2.x.

Verification for this commit (Windows, NODE_OPTIONS=--max-old-space-size=8192, --script-shell=bash)

  • npm run docs:check-tokens, npm run typecheck, npm run typecheck:client -w @mcpjam/inspector, npm run test:checks, npm run build:inspector: all exit 0.
  • npm run test -w @mcpjam/sdk: 3 failed | 9433 passed | 8 skipped. Two are the Windows-local failures listed above (symlink EPERM, stdio cwd EBUSY). The third, eval-enterprise-reporting, hit a 5s timeout under full-suite load and passes 8/8 when run alone.
  • check-local-harness-inputs.mjs: fingerprint verified, no change. bundle-browserd.mjs --check: up to date.
  • examples/evals/asana: npm ci and tsc --noEmit exit 0.

Update, 2026-10-03

Oneleet's 'Dependency scanning findings are resolved' monitor (feeding the
failing 'Vulnerabilities remediated' control) flags vulnerable copies of
undici, @ai-sdk/provider-utils, qs, brace-expansion, ip-address, body-parser,
fast-uri, @opentelemetry/core, golang.org/x/sys and claude-code-action in this
repo. #5684 already fixed qs/body-parser/@babel/core/@hono/node-server and
pinned claude-code-action; this clears the rest that has a non-breaking fix:

- undici: 6.28.0 -> 6.29.0 and 7.29.0 -> 7.29.1/7.30.0 (miniflare's exact
  7.29.0 pin moves via miniflare 5.20261001.0-alpha, wrangler 4.147.0).
- @ai-sdk/provider-utils: every copy now 3.0.30 / >=4.0.33. The 3.x line
  grew an undici ^5.29.0 dependency at 3.0.35, and undici 5.x has NO fixed
  release (5.29.0 is the ceiling), so following latest would have ADDED 13
  undici-5 findings. 3.0.30 is the newest 3.x that is both past its own CVE
  fix (>=3.0.28) and free of undici 5. The v2-line @ai-sdk providers pin
  provider-utils exactly, npm overrides do not rewrite exact pins, so
  sdk/package.json pins each provider to its newest release that pins
  3.0.28-3.0.30; a root override covers range consumers
  (ollama-ai-provider-v2).
- ai: pinned 6.0.214 (= its provider-utils fix floor 4.0.33). ai >=6.0.259
  breaks the sdk's HostRunner stopWhen/timeout integration tests (tool calls
  stop executing) and eval-git provenance tests; 6.0.214 is the newest
  verified-green version. Lifting the pin needs a HostRunner investigation.
- brace-expansion 2.1.7/5.0.12, ip-address 10.7.3, fast-uri 3.1.8.
- go launcher: golang.org/x/sys v0.44.0 (CVE-2026-39824 fix floor). That
  forces go>=1.25, which flips the winsymlink GODEBUG default and broke the
  launcher's junction resolution tests; godebug winsymlink=0 keeps the
  behavior the shipped launcher has always had. CI pins Go 1.27.1.

Not fixed here: @opentelemetry/core 1.30.1 (fix only ships with the
@sentry/node 11 major) and the backend's undici 5.29.0 findings (separate
repo; fixed there by the same provider pins via overrides until @mcpjam/sdk
ships these pins).
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@chelojimenez

chelojimenez commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Internal preview

Preview URL: https://mcp-inspector-pr-5823.up.railway.app
Deployed commit: 664bc96
PR head commit: dd990b5
Backend target: staging fallback.
Health: ✅ Convex reachable
Access is employee-only in non-production environments.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 852e9422-e639-4494-bd3a-041d778d20d1
📥 Commits

Reviewing files that changed from the base of the PR and between 89a590b and dd990b5.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


Walkthrough

The change pins AI SDK dependencies to exact versions in the SDK, chat UI, and inspector packages. It adds a root override for @ai-sdk/provider-utils and updates the tmp override for external-editor. The job launcher Go module updates its Go directive and golang.org/x/sys requirement, and adds a winsymlink=0 GODEBUG setting.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to dd990

The dependency pins and job-launcher settings show no established user-facing regression, so this change appears mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to dd990

The updates do not show expanded access or weakened execution controls. Risk remains low because Windows execution and third-party dependency behavior were not verified end to end.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly evidenced exposure is dependency behavior in the affected workspaces and Windows child-process containment. The changed declarations do not add credentials, IAM permissions, secret sources, or tool-policy authority; downstream dependency behavior remains only partially assessed.

Trust Boundaries and Controls

  • observed — The launcher canonicalizes its own path and the requested child path, then requires the absolute child to remain inside the resolved pack root. Test assertions cover both a junction-backed launcher and rejection of an in-pack junction targeting an external executable. These assertions were inspected, not executed.

Resilience and Maintainability Implications

  • observed — The existing child-start ordering remains create suspended, assign to an unnamed kill-on-close Job Object, then resume. Assignment or resume failure terminates the child, preserving the inspected failure-containment control rather than permitting it to run outside the job.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

The dep bump changes two pack inputs: the launcher's go.mod/go.sum (x/sys
v0.44.0 + godebug pin) and the @ai-sdk/harness-claude-code dependency
closure (re-resolved in the lockfile). The pack-inputs guard fails until the
reviewed snapshot matches; a new local-harness pack must be published after
merge, before its digests are recorded.
olartgabo added a commit that referenced this pull request Oct 2, 2026
#5797 and #5823 both appended an entry to the root overrides block and both
rewrote pack-inputs.generated.json, so whichever merged second conflicted.
This branch now stacks on #5823: package.json keeps both overrides, the
lockfile is regenerated from the combined manifests, and the pack fingerprint
is #5823's unchanged, because #5823 already moves the top-level undici to
7.30.0 and cross-env is outside the pack closure.
…babel/core

Four Dependabot alerts were still vulnerable on this branch after the
undici/provider-utils/brace-expansion work, all with in-range fixes:

- @humanfs/node 0.16.7 -> 0.16.8 (alert 807; via eslint, dev only).
  Pulls @humanfs/core 0.19.2 and the new @humanfs/types 0.15.0.
- @tootallnate/once 2.0.0 -> 2.0.1 (alert 413; via electron-forge's
  node-gyp -> make-fetch-happen -> http-proxy-agent 5, dev only).
- examples/evals/asana: picomatch 2.3.1 -> 2.3.2 (alert 138) and
  @babel/core 7.28.6 -> 7.29.7 (alert 475), both under jest. npm update
  also refreshed the lockfile's record of the linked ../../../sdk to its
  current version and dependency pins.

Left for their own PRs because the only fix is a major: vitest (fixed in
4.1.11, repo is on 3.2.7), tmp 0.0.33 (pinned by external-editor under
@electron-forge/cli 7), and @opentelemetry/core 1.30.1 (pinned by
@sentry/node 8 and @sentry/electron 5).
Conflicts:
- mcpjam-inspector/package.json: keep this branch's exact `ai` 6.0.214
  pin, take main's @xyflow/react ^12.12.0.
- package-lock.json: three-way merged per package entry (base = merge
  base, ours = this branch, theirs = main). Only the three workspace
  entries changed on both sides; their dependency maps were merged key by
  key. `npm install --package-lock-only` then reports up to date. Every
  entry this branch changed survives except one orphan
  (@posthog/cli/node_modules/prettier, which nothing depends on), and
  every entry #5840 changed survives (ws 8.22.0, @modelcontextprotocol/sdk
  1.31.0, posthog-node 5.54.1, ...). undici is 6.29.0 / 7.29.1 / 7.30.0
  with no 5.x copy; provider-utils is 3.0.30 or >= 4.0.33.
- pack-inputs.generated.json: re-recorded with
  check-local-harness-inputs.mjs --write for the merged lockfile.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-03T21:10:57.078517Z 493bffd New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

chelojimenez added a commit that referenced this pull request Oct 3, 2026
Each of these failed typecheck in #5772 or needs a decision that is not a
dependency bump, so each one held the whole group:

- ai 7 with the @ai-sdk/* provider majors, @openrouter/ai-sdk-provider 3
  and ollama-ai-provider-v2 4: `TimeoutConfiguration` is now generic
  (TS2314 in sdk/src/HostExecutor.ts fails the SDK declaration build and
  every job behind it), plus about 15 more errors. ai is also pinned
  exactly inside 6.x by #5823.
- react-resizable-panels 4: about 30 type errors in 7 inspector files.
- recharts 3: ui/chart.tsx and 3 more inspector files.
- @mcp-ui/client 7: removes UIResourceRenderer.
- @sentry/node, @sentry/react, @sentry/electron: electron 7 ships its own
  @sentry/node 10.x, node 11 fails in sdk/src/sentry.ts, and the SDK peer
  range would jump ^8 -> ^11.
- commander 15: needs Node >= 22.12; @mcpjam/cli declares >= 20.
- @modelcontextprotocol/ext-apps 2: built on the v2 MCP SDK; fails in
  mcp/ and widget-react/.

Put each back to main's range in every manifest that bumped it, regenerate
the lockfile from main's, and give each family its own version-updates and
security-updates group, excluded from every other workspace group (groups,
not `ignore`, so security updates still arrive). Each group's PR is where
its migration lands. The local-harness pack fingerprint moves with the
lockfile.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
main took a 15-package Dependabot group bump (#5840), including
@modelcontextprotocol/sdk 1.31.0, which conflicted with this branch's
lockfile and the inspector's ai pin. The lockfile was rebuilt from main's
and then `npm update` was run on only the packages this branch upgrades,
so main's single MCP SDK 1.31.0 is kept and none of the patched versions
regress. The pack-input fingerprint is regenerated for the new lockfile.
…o olartgabo/dep-bumps-oneleet

# Conflicts:
#	package-lock.json
tmp 0.0.33 (GHSA HIGH, < 0.2.6; and LOW, <= 0.2.3) reaches the tree only
through external-editor 3.1.0, a dev dependency of electron-forge's
prompts. external-editor calls only tmp.tmpNameSync, which 0.2.x keeps,
so the override is scoped to that one parent. The tree now has a single
tmp 0.2.7 (tmp-promise already used it) and drops os-tmpdir.

This branch was successfully deployed

1 active deployment
preview-pr-5823 — dd990b56 Deployed Oct 4, 2026 by olartgabo via upsert-preview #25934
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants