Skip to content

fix(FFESUPPORT-996): remediate September 2026 vulnerabilities - #127

Merged
aarsilv merged 3 commits into
mainfrom
aarsilv/ffesupport-996/fix-vulnerabilities
Oct 2, 2026
Merged

aarsilv merged 3 commits into
mainfrom
aarsilv/ffesupport-996/fix-vulnerabilities

Conversation

@aarsilv

@aarsilv aarsilv commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated from Claude

This PR closes the 15 open Dependabot alerts on node-server-sdk (@eppo/node-server-sdk). It also closes 7 related alerts that Dependabot auto-dismissed but yarn audit still reports. All vulnerable packages are dev-only transitive dependencies. The PR also raises the devDependency floors in package.json and bumps the package version to 4.0.3.

Jira: https://datadoghq.atlassian.net/browse/FFESUPPORT-996

Commits

  1. Remediate vulnerabilities. Re-resolve the vulnerable packages in yarn.lock. Raise the floor of the existing js-yaml resolution.
  2. Raise devDependency floors. package.json floors and the lockfile. Drop stale lock entries so the new jest and eslint trees dedupe.
  3. Bump version to 4.0.3.

Advisories closed

Package Severity Before → After First patched Advisories Pulled via
fast-uri high 3.1.2 → 3.1.8 3.1.6 GHSA-4c8g-83qw-93j6, GHSA-v2hh-gcrm-f6hx, GHSA-7p8r-x3mc-p8w7, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc, GHSA-jqff-g426-hqxp api-extractor, api-documenter → tsdoc-config, node-core-library → ajv@8
js-yaml 3.x high 3.15.0 → 3.15.2 3.15.2 GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh jest → @istanbuljs/load-nyc-config
js-yaml 4.x high 4.3.0 → 4.3.2 4.3.2 GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh eslint@8, @eslint/eslintrc, api-documenter
brace-expansion 1.x high 1.1.15 → 1.1.21 1.1.18 GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg¹, GHSA-rgw5-rvv9-x895¹ minimatch@3
brace-expansion 2.x high 2.1.1 → 2.1.7 2.1.4 same as 1.x glob@10 → minimatch@9
brace-expansion 5.x high 5.0.6 → 5.0.12 5.0.9 same as 1.x api-extractor, typescript-estree → minimatch@10
browserslist high 4.28.2 → 4.29.1 4.28.7 GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx¹ jest → @babel/helper-compilation-targets
baseline-browser-mapping medium 2.10.27 → 2.11.26 2.11.0 GHSA-w5vr-8v7q-w6rv browserslist

¹ Dependabot auto-dismissed this alert. yarn audit still reported it, so this PR closes it too.

All rows are in yarn.lock. None ships: the lockfile does not publish, and none of these packages is in the runtime dependency tree.

The js-yaml resolution stays

@microsoft/api-documenter 7.30.16 (latest) still pins js-yaml ~4.1.0. This PR keeps the existing scoped resolution "@microsoft/api-documenter/js-yaml" and raises it from ^4.2.0 to ^4.3.2. resolutionRationales records the reason. The @types/node resolution does not change. The PR adds no resolution.

devDependency floors raised (commit 2)

@microsoft/api-documenter ^7.30.16, @microsoft/api-extractor ^7.59.2, @typescript-eslint/eslint-plugin and @typescript-eslint/parser ^8.70.1, eslint-import-resolver-typescript ^4.4.5, eslint-plugin-prettier ^5.5.6, jest ^30.5.2, prettier ^3.9.9, testdouble ^3.21.0, ts-jest ^29.4.14.

The other devDependencies already resolve their latest in-range release. Their bare major floors (for example ^8) become explicit (for example ^8.57.1). All changes are in-range. Major upgrades are deferred; see below.

yarn.lock changes by 919 insertions and 808 deletions. Commit 1 changes 47 insertions and 47 deletions. Commit 2 changes 871 insertions and 760 deletions. In commit 2, 131 package names change: 65 in the jest tree, 26 in unrs-resolver and related packages, 10 @typescript-eslint/* packages, 8 @microsoft/* and @rushstack/* packages, and 22 others. The lockfile has 621 packages (main: 604).

jest-haste-map 30.5.1 (from jest 30.5) adds @parcel/watcher, a native addon with prebuilt binaries per platform. Its install script does nothing unless npm_config_build_from_source=true.

Runtime impact

  • No runtime dependency changes. dependencies is still @eppo/js-client-sdk-common: ^5. Its transitive tree in yarn.lock has the same 36 packages at the same versions as main.
  • A local dist/ build is identical to a main build, except one string. The tsc output and the API Extractor rollup dist/node-server-sdk.d.ts are identical. dist/tsdoc-metadata.json records the API Extractor version (7.58.7 → 7.59.2).
  • node-server-sdk.api.md and docs/ do not change.
  • The version bump changes sdkVersion, which src/sdk-data.ts reads from package.json.

How the tests and CI protect this change

Local runs on Node 20.20.2 and 24.15.0 (host) and Node 22.23.3 (docker node:22):

  • yarn install --frozen-lockfile passes on all three. The lockfile agrees with package.json. No engine error on Node 20. The install runs prepare: tsc and API Extractor 7.59.2.
  • eslint '**/*.{ts,tsx}' passes with 0 problems.
  • yarn typecheck passes.
  • The unit tests pass: 115 tests / 2 suites, the same as main.
  • yarn docs (api-documenter 7.30.16) passes on Node 20 and 24.
  • yarn test, the command that publish.yml runs, passes on Node 20.
  • yarn audit reports 0 advisories (main: 121 high, 10 moderate).
  • An OSV scan of yarn.lock (621 packages) reports 0 advisories. The OSV data includes the OpenSSF malicious-package feed. It finds only known entries.
  • PR CI passes: lint-test-sdk and typecheck on Node 20, 22, and 24.

Dependabot closes the alerts when it scans main after the merge.

Not validated before merge

  • publish.yml runs only on a release. Its publish job runs yarn install and yarn test on Node 20. The local Node 20 run covers these commands. Its test-packaged-node-sdk job (the sdk-test-data relay) and the npm publish step did not run.
  • The release job installs and runs the new devDependencies. Several new versions are less than 7 days old: the ts-jest 29.4.14 floor (2026-09-25), the prettier 3.9.9 floor (2026-09-23), and the transitive browserslist 4.29.1 (2026-09-24). yarn audit and OSV report only known advisories and known malicious packages.

Deferred

Advisories: none. This PR closes all open alerts. No alert stays dismissed or auto-dismissed without a fix.

Major devDependency upgrades:

  • eslint 8 → 10. It needs flat config. eslint-plugin-import 2.32.0 accepts eslint up to ^9 only. This is a tooling migration for a separate PR.
  • TypeScript 5.9 → 6/7. TypeScript 7 is outside the peer ranges of ts-jest 29.4.14 (<7) and typescript-eslint 8.70.1 (<6.1.0). TypeScript 6 is a compiler major, and the compiler emits the published dist/. It needs its own PR with a dist/ review.
  • lint-staged 16 → 17. lint-staged 17 needs Node >= 22.22.1. Yarn 1 enforces engines at install, and CI installs on Node 20.

Runtime: @eppo/js-client-sdk-common 5.0.2 is not released yet (Eppo-exp/js-sdk-common#332). A later PR can raise the floor.

Notes

  • Version: main is at 4.0.2. It has no tag, and npm does not have it. The newest tag is v4.0.1. Its publish run failed at "Publish Latest" (the job logs now return HTTP 410), so npm does not have 4.0.1 either; the newest npm version is 4.0.0. Commit 3 is separate, so a reviewer can drop it and release as 4.0.2 instead.
  • PR chore: release v4.0.1 #123 ("chore: release v4.0.1") is stale. It sets 4.0.1 and pins @eppo/js-client-sdk-common 4.15.5. This PR does not touch it.
  • No Dependabot PR is open for these alerts.
  • Follow-up: CONTRIBUTING.md still describes a manual npm publish and a CHANGELOG.md update. The repo has no CHANGELOG.md (deleted in Assignment logging callback #16), and publish.yml publishes on a GitHub release.

🤖 Generated with Claude Code

aarsilv and others added 3 commits September 26, 2026 16:57
Re-resolve dev-only transitive dependencies to the latest patched
version in their existing ranges:
- fast-uri 3.1.2 -> 3.1.8 (6 GHSAs, via ajv@8 in api-extractor/documenter)
- js-yaml 3.15.0 -> 3.15.2 and 4.3.0 -> 4.3.2
  (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh)
- brace-expansion 1.1.15 -> 1.1.21, 2.1.1 -> 2.1.7, 5.0.6 -> 5.0.12
  (GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895)
- browserslist 4.28.2 -> 4.29.1 (GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx)
- baseline-browser-mapping 2.10.27 -> 2.11.26 (GHSA-w5vr-8v7q-w6rv)

@microsoft/api-documenter 7.30.16 still pins js-yaml ~4.1.0, so keep
the scoped resolution and raise its floor to ^4.3.2.

No runtime dependency changes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e releases

Raise every devDependency floor to its latest release that installs on
Node 20, 22, and 24:
- @microsoft/api-documenter ^7.30.16, @microsoft/api-extractor ^7.59.2
- @typescript-eslint/eslint-plugin and parser ^8.70.1
- eslint-import-resolver-typescript ^4.4.5, eslint-plugin-prettier ^5.5.6
- jest ^30.5.2, ts-jest ^29.4.14, testdouble ^3.21.0, prettier ^3.9.9
- Explicit floors for packages already at their latest in-range release.

Drop stale lock entries for expect, pretty-format, unrs-resolver, and
synckit so each range dedupes onto the new version.

Majors stay deferred: eslint 10 (flat config), TypeScript 6/7, and
lint-staged 17 (needs Node >= 22.22.1).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The release version bump lacks the required changelog entry and warrants human approval.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Remediates vulnerable dev-only dependencies and bumps the SDK version to 4.0.3.

Changes:

  • Updates patched transitive dependencies in the lockfile.
  • Raises development dependency floors.
  • Preserves the js-yaml resolution override.
  • Updates the package version.
File Description
yarn.lock Re-resolves vulnerable and transitive dependency trees.
package.json Updates devDependencies, resolutions, and version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
{
"name": "@eppo/node-server-sdk",
"version": "4.0.2",
"version": "4.0.3",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Response from Claude:

I keep the bump without a changelog entry. The repo has no CHANGELOG.md: commit b46936c (#16) deleted it. CONTRIBUTING.md:9 still mentions the file, but that text is out of date. The recent version bumps (#119, #120, #124, #125) added no changelog. A version bump does not publish the package. publish.yml runs only when someone publishes a GitHub release, and the release notes go there.

codex checked this claim independently and returned INVALID, with the same evidence.

The bump is in its own commit (b7fd946), so a maintainer can drop it. The PR description has a follow-up for the out-of-date release steps in CONTRIBUTING.md.

@aarsilv

aarsilv commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Response from codex:

Fact-check of the PR description against the branch diff, yarn.lock, and Claude's executed evidence (installs and tests on Node 20/22/24, yarn audit, OSV scan, dist/ comparison, registry and Actions lookups). Four rounds.

Pre-push review (branch diff): no blocking issues found. Advisory status in yarn.lock on the branch:

  • fast-uri: CLOSED (yarn.lock:2256, 3.1.8)
  • js-yaml 3.x / 4.x: CLOSED (yarn.lock:3296 3.15.2, yarn.lock:3304 4.3.2)
  • brace-expansion 1.x / 2.x / 5.x: CLOSED (yarn.lock:1541 1.1.21, :1549 2.1.7, :1556 5.0.12)
  • browserslist: CLOSED (yarn.lock:1563, 4.29.1)
  • baseline-browser-mapping: CLOSED (yarn.lock:1536, 2.11.26)

Description fact-check:

  • Round 1: FIX FIRST. 2 wrong claims (browserslist 4.29.1 called a "floor"; OSV called the only check, which ignored yarn audit). Also misleading wording about "published" dist/, the relay job, and the resolution section, plus missing CI results and Node 22 docs coverage.
  • Round 2: 10 of 12 fixed. Lockfile churn totals included package.json; "logs expired" had no evidence.
  • Round 3: both fixed. New slips in the churn paragraph (per-commit arithmetic, category labels).
  • Round 4: all fixed. VERDICT: POST AS IS.

Copilot comment (CHANGELOG.md): INVALID. CONTRIBUTING.md:9 refers to a changelog that commit b46936c deleted. A version bump does not publish; publish.yml runs on a published GitHub release. Keep the bump.

@aarsilv
aarsilv requested a review from greghuels September 27, 2026 01:10
@aarsilv
aarsilv marked this pull request as ready for review September 27, 2026 01:10
@aarsilv
aarsilv merged commit e78eb4b into main Oct 2, 2026
8 checks passed
@aarsilv
aarsilv deleted the aarsilv/ffesupport-996/fix-vulnerabilities branch October 2, 2026 13:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants