Skip to content

fix(FFESUPPORT-993): remediate September 2026 vulnerabilities - #439

Open
aarsilv wants to merge 4 commits into
mainfrom
aarsilv/ffesupport-993/fix-vulnerabilities
Open

aarsilv wants to merge 4 commits into
mainfrom
aarsilv/ffesupport-993/fix-vulnerabilities

Conversation

@aarsilv

@aarsilv aarsilv commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated from Claude

Remediates the September 2026 advisories in eppo-multiplatform. Jira: FFESUPPORT-993.

What and why

This PR closes the 13 open Dependabot alerts. It also closes RustSec advisories that an OSV scan finds in the SDK Cargo lockfiles but Dependabot does not report. All fixes are version updates. There are no overrides, no source changes, and no Cargo.toml changes.

Package Advisory Lockfile Before → After In a shipped artifact?
brace-expansion GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 package-lock.json 1.1.16 → 1.1.21 No (repo tooling)
js-yaml GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh package-lock.json 4.3.0 → 4.3.2, 3.15.0 → 3.15.2 No
qs GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g package-lock.json 6.15.2 → 6.16.0 No
joi GHSA-6w3j-5fw6-r9vr, GHSA-gg4h-3hg2-grpc package-lock.json 17.13.4 → 17.13.8 No
json (gem) GHSA-x2f5-4prf-w687 ruby-sdk/Gemfile.lock 2.19.5 → 3.0.2 No (development group)
quinn-proto GHSA-4w2j-m93h-cj5j ruby-sdk + elixir-sdk Cargo.lock 0.11.14 → 0.11.15 No (not compiled)
rustls RUSTSEC-2026-0285 (OSV only) ruby-sdk + elixir-sdk Cargo.lock 0.23.40 → 0.23.45 Yes: Ruby gems (see "Changeset")
rkyv RUSTSEC-2026-0233, -0234, -0235 (OSV only) ruby-sdk + elixir-sdk Cargo.lock 0.8.16 → 0.8.17 No (not compiled)
anyhow RUSTSEC-2026-0190 (OSV only) ruby-sdk/Cargo.lock 1.0.102 → 1.0.103 No (not compiled)

npm (root tooling)

The fixed brace-expansion, js-yaml, qs, and joi versions all fit the existing ranges, so a lockfile-only change would clear the advisories. This PR also raises the tooling floors in package.json, so that the manifest records the upgrade:

  • @changesets/cli ^2.27.11 → ^2.31.1 and @changesets/changelog-github ^0.5.0 → ^0.7.0 (the latest releases on changesets 2). One behavior change: changelog-github 0.7.0 turns a bare #123 in a changeset summary into a link. The current changesets have no bare references.
  • start-server-and-test ^2.0.4 → ^2.1.1 (wait-on 7.2.0 → 8.0.4). 2.1.1 is the last release on joi 17. For the reason, see "Deferred". ^2.1.1 still allows 2.1.5 (joi 18) on a future npm update. The Node 12 jobs in python.yml would catch that.
  • npm-run-all 4.1.5 and http-server 14.1.1 are already the latest releases.

Other lockfile changes come with these updates: axios 1.18.1 → 1.20.0, debug 4.3.5 → 4.4.3, and patch/minor updates of changesets internals.

Cargo (ruby-sdk/Cargo.lock, elixir-sdk/Cargo.lock)

cargo update --precise to the smallest fixed version. rustls-webpki moves 0.103.13 → 0.103.15: rustls 0.23.45 requires ^0.103.14, and cargo resolves 0.103.15. quinn-proto, rkyv, and anyhow are in no normal or build dependency graph (cargo tree -i --target all --all-features). They are in the lockfiles only through optional-dependency features, for example reqwest's quinn?/ring.

The root /Cargo.lock is gitignored and not tracked, so this PR does not change it. The root workspace (Python wheels, Rust SDK) has no committed lockfile. A fresh resolve on 2026-09-26 picks rustls 0.23.45, and OSV reports 0 advisories for the resulting 321 crates.

Ruby

rubocop ~> 1.82 → ~> 1.91 in the development group. rubocop 1.91 allows json >= 2.3, so json resolves 3.0.2. The Gemfile change is the same as the open Dependabot PR #437. The lockfile also matches #437, except for three rubocop dependencies one release newer (regexp_parser, unicode-display_width, unicode-emoji). This PR supersedes #437. BUNDLED WITH stays 2.4.4.

Changeset

.changeset/september-2026-security-deps.md queues a patch release for ruby-sdk and elixir-sdk.

  • ruby-sdk: the source gem ships ruby-sdk/Cargo.lock (the gemspec includes Cargo.*), and ruby-release.yml builds the precompiled gems from it.
  • elixir-sdk: the hex package does not include elixir-sdk/Cargo.lock, so hex users resolve rustls when they compile the NIF. This entry does not change what hex users get. It records the lockfile update, the same as july-2026-security-deps.md does for serde_with.
  • python-sdk: no entry. Its wheels build without a committed lockfile.

How the tests and CI protect this change

Executed locally:

  • npm audit: 0 vulnerabilities. An OSV scan of all tracked lockfiles (package-lock.json, both SDK Cargo.lock files, Gemfile.lock, mix.lock): 0 advisories.
  • cargo build --release --locked passes in ruby-sdk and elixir-sdk, and compiles rustls 0.23.45. cargo test --release --locked passes in ruby-sdk.
  • Ruby: npm run with-server test:ruby (rake build + rspec): 503 examples, 0 failures.
  • Node 12 smoke test: the python.yml arch jobs install Node 12.22.9 / npm 8.5.1 from Ubuntu 22.04 apt. In an ubuntu:22.04 container with those versions, npm ci passes, and start-server-and-test starts the mock server and gets HTTP 200. The arch jobs in CI run the real pytest suite. Note: start-server-and-test 2.0.4 and 2.1.1 both declare Node >= 16, so CI already runs it outside its declared range. This PR does not change that.
  • Changesets: changeset version with the old tooling (2.29.8 / 0.5.0) and the new tooling (2.31.1 / 0.7.0) gives the same CHANGELOG.md and version output for all 5 packages. This matters because version.yml runs only on main, so PR CI does not run it. This PR does not change the workspace postversion scripts.

CI: python.yml (including the Node 12 arch jobs), ruby.yml, elixir.yml, and ci.yml all run on this PR, because their pull_request path filters include package-lock.json.

Not validated before merge:

  • The full npm run version (changesets plus the workspace postversion scripts). The comparison above covers changeset version only. This PR does not change the postversion scripts.
  • The Ruby cross-platform gem builds in ruby-release.yml. They do not run on PRs.
  • Elixir mix test locally (no Elixir toolchain here). elixir.yml runs it in CI.

Deferred

  • @changesets/cli 3.x and @changesets/changelog-github 1.x. Both declare Node ^22.11 || ^24 || >=26 (cli@3.0.3, changelog-github@1.0.1). version.yml, publish.yml, and ruby-release.yml pin Node 20, and PR CI does not run version.yml. No open advisory needs the upgrade.
  • start-server-and-test 2.1.2+ and 3.x. They pull wait-on 8.0.5+/9 with joi 18. joi 18 declares Node >= 20 and uses syntax that Node 12 cannot parse. The python.yml run-on-arch jobs run start-server-and-test on Node 12. The follow-up is to install a newer Node in those jobs first.
  • Dependabot alert closure. The alerts close after merge, when Dependabot scans main.

🤖 Generated with Claude Code

aarsilv and others added 4 commits September 26, 2026 15:35
Raise the root tooling floors and re-resolve package-lock.json:
- @changesets/cli ^2.27.11 -> ^2.31.1, @changesets/changelog-github
  ^0.5.0 -> ^0.7.0. js-yaml 4.3.0 -> 4.3.2 and 3.15.0 -> 3.15.2
  (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh).
- start-server-and-test ^2.0.4 -> ^2.1.1 (wait-on 7.2.0 -> 8.0.4).
  joi 17.13.4 -> 17.13.8 (GHSA-6w3j-5fw6-r9vr, GHSA-gg4h-3hg2-grpc).
  2.1.1 is the last release on joi 17. Later releases pull joi 18,
  which needs Node 20. The python.yml arch jobs run Node 12.
- brace-expansion 1.1.16 -> 1.1.21 (GHSA-mh99-v99m-4gvg,
  GHSA-rgw5-rvv9-x895), via npm-run-all -> minimatch@3.
- qs 6.15.2 -> 6.16.0 (GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g),
  via mock-server -> http-server -> union.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ruby-sdk/Cargo.lock and elixir-sdk/Cargo.lock:
- rustls 0.23.40 -> 0.23.45 (RUSTSEC-2026-0285), with rustls-webpki
  0.103.13 -> 0.103.15. The native builds compile rustls.
- quinn-proto 0.11.14 -> 0.11.15 (GHSA-4w2j-m93h-cj5j).
- rkyv 0.8.16 -> 0.8.17 (RUSTSEC-2026-0233, -0234, -0235).
- anyhow 1.0.102 -> 1.0.103 (RUSTSEC-2026-0190), ruby-sdk only.

quinn-proto, rkyv, and anyhow are in the lockfiles, but the builds do
not compile them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
rubocop ~> 1.82 -> ~> 1.91 (development group). rubocop 1.91 allows
json >= 2.3, so json resolves 2.19.5 -> 3.0.2 (GHSA-x2f5-4prf-w687).
BUNDLED WITH stays 2.4.4.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The Ruby and Elixir native builds use the updated lockfiles, so this
queues a patch release for ruby-sdk and elixir-sdk.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 26, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 3f42fe6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
elixir-sdk Patch
ruby-sdk Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

start-server-and-test 2.1.1 requires Node 16+, but Python architecture jobs run it on Node 12.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Remediates September 2026 vulnerabilities across npm, Ruby, and Rust dependencies, with patch releases queued for Ruby and Elixir SDKs.

Changes:

  • Updates npm tooling and vulnerable transitive dependencies.
  • Refreshes Ruby and Rust lockfiles.
  • Adds a Ruby and Elixir security changeset.
File Description
ruby-sdk/​Gemfile.lock Locks updated Ruby dependencies.
ruby-sdk/​Gemfile Updates RuboCop.
ruby-sdk/​Cargo.lock Updates Rust dependencies, including rustls.
package.json Updates npm tooling dependencies.
package-lock.json Resolves patched npm dependencies.
elixir-sdk/​Cargo.lock Updates Rust dependencies, including rustls.
.changeset/​september-2026-security-deps.md Queues Ruby and Elixir patch releases.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
"@changesets/cli": "^2.31.1",
"npm-run-all": "^4.1.5",
"start-server-and-test": "^2.0.4"
"start-server-and-test": "^2.1.1"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Response from Claude:

The premise is correct: start-server-and-test 2.1.1 declares engines.node >=16, and the python.yml run-on-arch jobs run it on Node 12.22.9. This PR does not create that condition:

  • origin/main locks 2.0.4, which also declares node >=16. The July main run of the s390x job printed EBADENGINE package: 'start-server-and-test@2.0.4', required: { node: '>=16' }, current: { node: 'v12.22.9' } and passed.
  • Every release from 2.0.1 onward declares node >=16, so there is no release that fixes joi and declares Node 12 support, short of a downgrade below main.
  • The joi fix does not depend on the start-server-and-test version: joi 17.13.8 fits the ranges of wait-on 7.2.0 (^17.11.0) and 8.0.4 (^17.13.3).
  • In an ubuntu:22.04 container with apt Node 12.22.9 / npm 8.5.1, npm ci passes and 2.1.1 serves the mock server (HTTP 200). The arch jobs in this PR's CI run the real pytest suite.

Moving those jobs to a newer Node is the right long-term fix. It is listed under "Deferred" in the description, because start-server-and-test 2.1.2+ needs it too (joi 18). No change in this PR. codex adjudicated this independently and returned REPLY (no change).

@aarsilv

aarsilv commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 Response from codex:

Fact-check of this PR description against the diff, with the author's executed evidence (npm audit, OSV scans, cargo builds, Ruby rspec, the Node 12 container run, and the changesets old-vs-new comparison).

Round 1 — FIX FIRST. Every version and file reference that could be checked against the diff was CONFIRMED. Findings:

  • WRONG: "python.yml runs on every PR". It has pull_request path filters. It runs here because package-lock.json changed.
  • MISLEADING: the Node 12 smoke test did not say that start-server-and-test declares Node >=16 in both the old and new versions. "They bring js-yaml" implied that the changesets bumps were necessary. The elixir changeset precedent implied that hex users get the fix.
  • MISSING: other lockfile churn (axios, debug, changesets internals, rubocop dependencies), that ^2.1.1 allows newer 2.x releases, the validation boundaries (full npm run version, Ruby cross-platform gem builds, Elixir mix test), and evidence that a fresh root-workspace resolve is clean.

Round 2 (revised description) — all eight objections FIXED. One new factual defect: rustls 0.23.45 requires rustls-webpki ^0.103.14, and 0.103.15 is only the resolved version. It also asked for evidence of changelog-github 1.x's Node engines. Both are now fixed in the description: the rustls-webpki wording is corrected, and the engines of changelog-github@1.0.1 are cited.

Round 3 (after the round-2 fixes) — POST AS IS. The rustls-webpki requirement and the changelog-github 1.x engines are both FIXED. No new inaccuracies.

Advisory status (read from the lockfiles): CLOSED for brace-expansion 1.1.21, joi 17.13.8, js-yaml 3.15.2 and 4.3.2, qs 6.16.0, json 3.0.2, quinn-proto 0.11.15, rustls 0.23.45, rkyv 0.8.17, and anyhow 1.0.103.

Tiebreak on the Copilot start-server-and-test / Node 12 comment: REPLY (no change). The runtime mismatch predates this PR (main locks 2.0.4, which also declares Node >=16). joi 17.13.8 fixes the dependency, and no qualifying release declares Node 12 support.

Pre-push review of the branch diff: no blocking issues found.

@aarsilv
aarsilv requested a review from rasendubi September 27, 2026 00:25
@aarsilv
aarsilv marked this pull request as ready for review September 27, 2026 00:26

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants