Conversation
Raise the root tooling floors and re-resolve package-lock.json: - @changesets/cli ^2.27.11 -> ^2.31.1, @changesets/changelog-github ^0.5.0 -> ^0.7.0. js-yaml 4.3.0 -> 4.3.2 and 3.15.0 -> 3.15.2 (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh). - start-server-and-test ^2.0.4 -> ^2.1.1 (wait-on 7.2.0 -> 8.0.4). joi 17.13.4 -> 17.13.8 (GHSA-6w3j-5fw6-r9vr, GHSA-gg4h-3hg2-grpc). 2.1.1 is the last release on joi 17. Later releases pull joi 18, which needs Node 20. The python.yml arch jobs run Node 12. - brace-expansion 1.1.16 -> 1.1.21 (GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895), via npm-run-all -> minimatch@3. - qs 6.15.2 -> 6.16.0 (GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g), via mock-server -> http-server -> union. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ruby-sdk/Cargo.lock and elixir-sdk/Cargo.lock: - rustls 0.23.40 -> 0.23.45 (RUSTSEC-2026-0285), with rustls-webpki 0.103.13 -> 0.103.15. The native builds compile rustls. - quinn-proto 0.11.14 -> 0.11.15 (GHSA-4w2j-m93h-cj5j). - rkyv 0.8.16 -> 0.8.17 (RUSTSEC-2026-0233, -0234, -0235). - anyhow 1.0.102 -> 1.0.103 (RUSTSEC-2026-0190), ruby-sdk only. quinn-proto, rkyv, and anyhow are in the lockfiles, but the builds do not compile them. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
rubocop ~> 1.82 -> ~> 1.91 (development group). rubocop 1.91 allows json >= 2.3, so json resolves 2.19.5 -> 3.0.2 (GHSA-x2f5-4prf-w687). BUNDLED WITH stays 2.4.4. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The Ruby and Elixir native builds use the updated lockfiles, so this queues a patch release for ruby-sdk and elixir-sdk. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
🦋 Changeset detectedLatest commit: 3f42fe6 The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
start-server-and-test 2.1.1 requires Node 16+, but Python architecture jobs run it on Node 12.
Review effort: Lite
Findings: 1
What changed in this PR
Remediates September 2026 vulnerabilities across npm, Ruby, and Rust dependencies, with patch releases queued for Ruby and Elixir SDKs.
Changes:
- Updates npm tooling and vulnerable transitive dependencies.
- Refreshes Ruby and Rust lockfiles.
- Adds a Ruby and Elixir security changeset.
| File | Description |
|---|---|
ruby-sdk/Gemfile.lock |
Locks updated Ruby dependencies. |
ruby-sdk/Gemfile |
Updates RuboCop. |
ruby-sdk/Cargo.lock |
Updates Rust dependencies, including rustls. |
package.json |
Updates npm tooling dependencies. |
package-lock.json |
Resolves patched npm dependencies. |
elixir-sdk/Cargo.lock |
Updates Rust dependencies, including rustls. |
.changeset/september-2026-security-deps.md |
Queues Ruby and Elixir patch releases. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "@changesets/cli": "^2.31.1", | ||
| "npm-run-all": "^4.1.5", | ||
| "start-server-and-test": "^2.0.4" | ||
| "start-server-and-test": "^2.1.1" |
There was a problem hiding this comment.
🤖 Response from Claude:
The premise is correct: start-server-and-test 2.1.1 declares engines.node >=16, and the python.yml run-on-arch jobs run it on Node 12.22.9. This PR does not create that condition:
origin/mainlocks 2.0.4, which also declaresnode >=16. The Julymainrun of the s390x job printedEBADENGINE package: 'start-server-and-test@2.0.4', required: { node: '>=16' }, current: { node: 'v12.22.9' }and passed.- Every release from 2.0.1 onward declares
node >=16, so there is no release that fixes joi and declares Node 12 support, short of a downgrade belowmain. - The joi fix does not depend on the
start-server-and-testversion: joi 17.13.8 fits the ranges of wait-on 7.2.0 (^17.11.0) and 8.0.4 (^17.13.3). - In an
ubuntu:22.04container with apt Node 12.22.9 / npm 8.5.1,npm cipasses and 2.1.1 serves the mock server (HTTP 200). The arch jobs in this PR's CI run the real pytest suite.
Moving those jobs to a newer Node is the right long-term fix. It is listed under "Deferred" in the description, because start-server-and-test 2.1.2+ needs it too (joi 18). No change in this PR. codex adjudicated this independently and returned REPLY (no change).
|
🤖 Response from codex: Fact-check of this PR description against the diff, with the author's executed evidence (npm audit, OSV scans, cargo builds, Ruby rspec, the Node 12 container run, and the changesets old-vs-new comparison). Round 1 — FIX FIRST. Every version and file reference that could be checked against the diff was CONFIRMED. Findings:
Round 2 (revised description) — all eight objections FIXED. One new factual defect: rustls 0.23.45 requires rustls-webpki Round 3 (after the round-2 fixes) — POST AS IS. The rustls-webpki requirement and the changelog-github 1.x engines are both FIXED. No new inaccuracies. Advisory status (read from the lockfiles): CLOSED for brace-expansion 1.1.21, joi 17.13.8, js-yaml 3.15.2 and 4.3.2, qs 6.16.0, json 3.0.2, quinn-proto 0.11.15, rustls 0.23.45, rkyv 0.8.17, and anyhow 1.0.103. Tiebreak on the Copilot Pre-push review of the branch diff: no blocking issues found. |

🤖 Generated from Claude
Remediates the September 2026 advisories in eppo-multiplatform. Jira: FFESUPPORT-993.
What and why
This PR closes the 13 open Dependabot alerts. It also closes RustSec advisories that an OSV scan finds in the SDK Cargo lockfiles but Dependabot does not report. All fixes are version updates. There are no
overrides, no source changes, and noCargo.tomlchanges.package-lock.jsonpackage-lock.jsonpackage-lock.jsonpackage-lock.jsonruby-sdk/Gemfile.lockCargo.lockCargo.lockCargo.lockruby-sdk/Cargo.locknpm (root tooling)
The fixed brace-expansion, js-yaml, qs, and joi versions all fit the existing ranges, so a lockfile-only change would clear the advisories. This PR also raises the tooling floors in
package.json, so that the manifest records the upgrade:@changesets/cli^2.27.11 → ^2.31.1 and@changesets/changelog-github^0.5.0 → ^0.7.0 (the latest releases on changesets 2). One behavior change: changelog-github 0.7.0 turns a bare#123in a changeset summary into a link. The current changesets have no bare references.start-server-and-test^2.0.4 → ^2.1.1 (wait-on 7.2.0 → 8.0.4). 2.1.1 is the last release on joi 17. For the reason, see "Deferred".^2.1.1still allows 2.1.5 (joi 18) on a futurenpm update. The Node 12 jobs inpython.ymlwould catch that.npm-run-all4.1.5 andhttp-server14.1.1 are already the latest releases.Other lockfile changes come with these updates: axios 1.18.1 → 1.20.0, debug 4.3.5 → 4.4.3, and patch/minor updates of changesets internals.
Cargo (
ruby-sdk/Cargo.lock,elixir-sdk/Cargo.lock)cargo update --preciseto the smallest fixed version. rustls-webpki moves 0.103.13 → 0.103.15: rustls 0.23.45 requires^0.103.14, and cargo resolves 0.103.15. quinn-proto, rkyv, and anyhow are in no normal or build dependency graph (cargo tree -i --target all --all-features). They are in the lockfiles only through optional-dependency features, for example reqwest'squinn?/ring.The root
/Cargo.lockis gitignored and not tracked, so this PR does not change it. The root workspace (Python wheels, Rust SDK) has no committed lockfile. A fresh resolve on 2026-09-26 picks rustls 0.23.45, and OSV reports 0 advisories for the resulting 321 crates.Ruby
rubocop~> 1.82 → ~> 1.91 in the development group. rubocop 1.91 allowsjson >= 2.3, so json resolves 3.0.2. The Gemfile change is the same as the open Dependabot PR #437. The lockfile also matches #437, except for three rubocop dependencies one release newer (regexp_parser, unicode-display_width, unicode-emoji). This PR supersedes #437.BUNDLED WITHstays 2.4.4.Changeset
.changeset/september-2026-security-deps.mdqueues a patch release forruby-sdkandelixir-sdk.ruby-sdk: the source gem shipsruby-sdk/Cargo.lock(the gemspec includesCargo.*), andruby-release.ymlbuilds the precompiled gems from it.elixir-sdk: the hex package does not includeelixir-sdk/Cargo.lock, so hex users resolve rustls when they compile the NIF. This entry does not change what hex users get. It records the lockfile update, the same asjuly-2026-security-deps.mddoes forserde_with.python-sdk: no entry. Its wheels build without a committed lockfile.How the tests and CI protect this change
Executed locally:
npm audit: 0 vulnerabilities. An OSV scan of all tracked lockfiles (package-lock.json, both SDKCargo.lockfiles,Gemfile.lock,mix.lock): 0 advisories.cargo build --release --lockedpasses inruby-sdkandelixir-sdk, and compiles rustls 0.23.45.cargo test --release --lockedpasses inruby-sdk.npm run with-server test:ruby(rake build+ rspec): 503 examples, 0 failures.python.ymlarch jobs install Node 12.22.9 / npm 8.5.1 from Ubuntu 22.04 apt. In anubuntu:22.04container with those versions,npm cipasses, andstart-server-and-teststarts the mock server and gets HTTP 200. The arch jobs in CI run the real pytest suite. Note:start-server-and-test2.0.4 and 2.1.1 both declare Node >= 16, so CI already runs it outside its declared range. This PR does not change that.changeset versionwith the old tooling (2.29.8 / 0.5.0) and the new tooling (2.31.1 / 0.7.0) gives the sameCHANGELOG.mdand version output for all 5 packages. This matters becauseversion.ymlruns only onmain, so PR CI does not run it. This PR does not change the workspacepostversionscripts.CI:
python.yml(including the Node 12 arch jobs),ruby.yml,elixir.yml, andci.ymlall run on this PR, because theirpull_requestpath filters includepackage-lock.json.Not validated before merge:
npm run version(changesets plus the workspacepostversionscripts). The comparison above coverschangeset versiononly. This PR does not change thepostversionscripts.ruby-release.yml. They do not run on PRs.mix testlocally (no Elixir toolchain here).elixir.ymlruns it in CI.Deferred
@changesets/cli3.x and@changesets/changelog-github1.x. Both declare Node^22.11 || ^24 || >=26(cli@3.0.3,changelog-github@1.0.1).version.yml,publish.yml, andruby-release.ymlpin Node 20, and PR CI does not runversion.yml. No open advisory needs the upgrade.start-server-and-test2.1.2+ and 3.x. They pull wait-on 8.0.5+/9 with joi 18. joi 18 declares Node >= 20 and uses syntax that Node 12 cannot parse. Thepython.ymlrun-on-arch jobs runstart-server-and-teston Node 12. The follow-up is to install a newer Node in those jobs first.main.🤖 Generated with Claude Code