Skip to content

ci: bump axios to 1.20.0 and audit production dependencies - #47

Merged
sumitake merged 2 commits into
mainfrom
dev/grok/npm-audit-runtime-scope
Oct 6, 2026
Merged

sumitake merged 2 commits into
mainfrom
dev/grok/npm-audit-runtime-scope

Conversation

@sumitake

@sumitake sumitake commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Pull Request

Summary

The full-tree audit still fails on GHSA-vfj7-8cjw-p6xm (braces <= 3.0.3, high, CVE-2026-93687). first_patched_version is null, and braces 3.0.3 is the latest release on npm, so no bump or override can fix it. braces is dev-only, reached through markdownlint-cli2 0.23.3 (latest) via micromatch 4.0.8, and via globby 16.2.4 -> fast-glob 3.3.3 -> micromatch. The step name matches the command. The audit level stays at moderate and nothing is ignored, so a future runtime advisory still fails CI.

Lockfile version delta

Package Before After
axios (node_modules/axios) 1.18.1 1.20.0

No other locked package version changed. npm update axios also rewrote the form-data specifier inside the axios entry from ^4.0.5 to ^4.0.6 (axios 1.20.0's own manifest). The locked form-data package stays 4.0.6. package.json is unchanged.

Verification

Local commands on this tip (Node v22.14.0, npm 10.9.7), after npm update axios:

  • npm ci --ignore-scripts — exit 0. Added 151 packages. npm ci printed the full-tree summary (9 vulnerabilities: 3 low, 1 moderate, 5 high) and exited 0.
  • npm run check — exit 0. 20 tests, 20 pass, 0 fail.
  • npm run lint:markdown — exit 0. markdownlint-cli2 v0.23.3 (markdownlint v0.41.1), 9 files, 0 issues.
  • npm audit --omit=dev --audit-level=moderate — exit 0. found 0 vulnerabilities.
  • npm audit --audit-level=moderate — exit 1 (dev-only; not the CI step). Output:
# npm audit report

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install markdownlint-cli2@0.21.0, which is a breaking change
node_modules/braces
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/fast-glob
      globby  >=8.0.0
      Depends on vulnerable versions of fast-glob
      Depends on vulnerable versions of micromatch
      node_modules/globby
        markdownlint-cli2  >=0.0.5
        Depends on vulnerable versions of globby
        Depends on vulnerable versions of markdownlint
        Depends on vulnerable versions of micromatch
        Depends on vulnerable versions of smol-toml
        node_modules/markdownlint-cli2

katex  0.11.0 - 0.18.1
KaTeX: Existing prototype pollution can bypass trust restrictions - https://github.com/advisories/GHSA-238p-pmpm-9mq7
fix available via `npm audit fix --force`
Will install markdownlint-cli2@0.21.0, which is a breaking change
node_modules/katex
  micromark-extension-math  *
  Depends on vulnerable versions of katex
  node_modules/micromark-extension-math
    markdownlint  >=0.37.0
    Depends on vulnerable versions of micromark-extension-math
    node_modules/markdownlint

smol-toml  <=1.8.0
Severity: moderate
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line - https://github.com/advisories/GHSA-r4xh-jqrq-34v2
fix available via `npm audit fix --force`
Will install markdownlint-cli2@0.21.0, which is a breaking change
node_modules/smol-toml

9 vulnerabilities (3 low, 1 moderate, 5 high)

To address all issues (including breaking changes), run:
  npm audit fix --force
  • Node tests and executable smoke check pass
  • Python tests, Ruff lint, and Ruff format checks pass (not run locally; this diff does not touch Python)
  • Dependency audit and repository validator pass (runtime npm audit --omit=dev --audit-level=moderate exits 0; repository validator runs in CI)
  • No real credentials, tunnel metadata, hostnames, usernames, or private paths are present
  • Microsoft-derived assets remain isolated and attributed
  • User-visible changes are documented in CHANGELOG.md (no user-visible change)

Security impact

Production axios moves from 1.18.1 to 1.20.0, clearing the high runtime advisories that failed CI on 1.18.1. The runtime audit omits dev dependencies and still uses --audit-level=moderate with nothing ignored. Dev-only advisories (braces, katex, smol-toml) remain in a full npm audit and do not fail the runtime step. Authentication, port exposure, command execution, protocol parsing, output handling, services, and licensing are unchanged.

Open in Web Open in Cursor 

The step is named for runtime dependencies but was auditing the full
tree. Pass --omit=dev and keep --audit-level=moderate so dev-only
advisories drop out and production advisories still fail the build.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 025e99ab-1291-4d04-bde0-f25a8999dc1c
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T10:40:04.351918Z 935bfcf PR opened
🔒 Security Review ✅ Completed 2026-10-06T10:41:18.244601Z 935bfcf PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 935bfcf16e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
run: npm run lint:markdown
- name: Audit runtime dependencies
run: npm audit --audit-level=moderate
run: npm audit --omit=dev --audit-level=moderate

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the documented audit command with the workflow

When a moderate-or-higher advisory affects only a development dependency, this workflow can now pass while the command in CONTRIBUTING.md:13-18, explicitly described as one of the “same checks required by CI,” still fails because it lacks --omit=dev (npm audit --help documents dev as an accepted --omit dependency type). Update that command alongside the workflow so contributors can reproduce the required CI audit locally.

Useful? React with 👍 / 👎.

Regenerate the lockfile with npm update axios so the production tree
matches Dependabot #46. No other locked versions change.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@cursor cursor Bot changed the title ci: audit production dependencies only ci: bump axios to 1.20.0 and audit production dependencies Oct 6, 2026
@sumitake
sumitake merged commit 474003f into main Oct 6, 2026
14 checks passed
@sumitake
sumitake deleted the dev/grok/npm-audit-runtime-scope branch October 6, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants