fix(FFESUPPORT-999): remediate September 2026 vulnerabilities - #163
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The changes require final human review because they are too complex or risky for automated approval.
Review effort: Lite
Findings: None
What changed in this PR
This PR remediates September 2026 dependency vulnerabilities across SDK test infrastructure while preserving SDK versions and test data.
Changes:
- Updates vulnerable npm, Maven, and Gradle dependencies.
- Upgrades TypeScript, ESLint, and related tooling.
- Removes the vulnerable npm
httppackage and excludes redundant Androidorg.json.
| File | Description |
|---|---|
| tsconfig.json | Updated as part of this pull request. |
| package.json | Updated as part of this pull request. |
| package-testing/testing-api/yarn.lock | Updated as part of this pull request. |
| package-testing/testing-api/tsconfig.json | Updated as part of this pull request. |
| package-testing/testing-api/src/routes.ts | Updated as part of this pull request. |
| package-testing/testing-api/package.json | Updated as part of this pull request. |
| package-testing/sdk-test-runner/yarn.lock | Updated as part of this pull request. |
| package-testing/sdk-test-runner/tsconfig.json | Updated as part of this pull request. |
| package-testing/sdk-test-runner/package.json | Updated as part of this pull request. |
| package-testing/react-native-sdk-relay/yarn.lock | Updated as part of this pull request. |
| package-testing/react-native-sdk-relay/package.json | Updated as part of this pull request. |
| package-testing/node-sdk-relay/package.json | Updated as part of this pull request. |
| package-testing/java-server-sdk-relay/build.gradle | Updated as part of this pull request. |
| package-testing/android-relay/gradle/libs.versions.toml | Updated as part of this pull request. |
| package-testing/android-relay/app/build.gradle.kts | Updated as part of this pull request. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
e9b3a0f to
17554f1
Compare
|
🤖 Response from codex: Pre-push review (branch diff, lockfile greps, manifests, workflows): no blocking issues found. Every in-scope advisory is CLOSED at its lockfile line, except the items listed as deferred: decode-uri-component 0.2.2 and image-size 1.2.1 (react-native-sdk-relay), five Jetty 9.4 GHSAs, and the jackson/logback that PR description fact-check, 3 rounds:
|
Raise ts-jest to 29.4.14 and TypeScript to 6. Regenerate yarn.lock. brace-expansion, browserslist, baseline-browser-mapping, and js-yaml now resolve to patched versions. Keep jest at 30.4.2. jest 30.5 pulls brace-expansion 5, which needs Node 20. validate-test-data.yml runs Node 18. Move "types" into compilerOptions. It was ignored at the top level, and TypeScript 6 no longer includes @types packages by default. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…isories Raise the NestJS 11 packages to ^11.2.6. @nestjs/platform-express 11.2.6 pins multer 2.4.0. Raise the lint and test tooling to the newest releases in their current majors. Regenerate yarn.lock. fast-uri, multer, qs, js-yaml, brace-expansion, browserslist, and baseline-browser-mapping now resolve to patched versions. @eppo/node-server-sdk stays at 4.0.0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ries Raise express to ^5.2.1, dotenv to ^18.0.4, TypeScript to ^6.0.3, and the lint tooling to the newest releases. Regenerate yarn.lock. body-parser, qs, and brace-expansion now resolve to patched versions. Set rootDir. Without it, TypeScript 6 stops this build with TS5011. The emitted JavaScript does not change. Add the missing globals and @eslint/js dev dependencies so that `yarn lint` runs. Fix the one formatting error it reports. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…visories Remove the `http` dependency. It is the npm security holding package (MAL-2025-22760), and `import ... from 'http'` loads the Node core module. Raise socket.io to ^4.8.4, axios to ^1.20.0, dotenv to ^18.0.4, TypeScript to ^6.0.3, and the lint tooling to the newest releases. Regenerate yarn.lock. socket.io-parser and brace-expansion now resolve to patched versions. Remove the brace-expansion and ws resolutions and their rationales. The lockfile resolves brace-expansion 5.0.12 and ws 8.21.3 without them. minimatch asks for brace-expansion ^5.0.8, and engine.io asks for ws ~8.21.0. Set rootDir. Without it, TypeScript 6 stops this build with TS5011. The emitted JavaScript does not change. Add the missing globals and @eslint/js dev dependencies so that `yarn lint` runs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Expo 52 Raise the resolutions floors for @xmldom/xmldom (^0.9.12), postcss (^8.5.28), and tar (^7.5.22). Re-resolve fast-uri, nanoid, undici, js-yaml, browserslist, baseline-browser-mapping, and brace-expansion to patched versions in range. Raise the prettier, eslint-config-prettier, TypeScript, and @types/react floors in their current majors. Remove the fast-uri resolution. Its only requester, ajv, asks for ^3.0.1, and that range resolves to 3.1.8. Update the rationales of the changed resolutions. @eppo/react-native-sdk stays at 3.8.0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
spark-core 2.9.4 is the last Spark release and pulls Jetty 9.4.48.v20220622. Import jetty-bom 9.4.58.v20250814, the newest public 9.4.x release, so every Jetty artifact resolves to 9.4.58. This clears the Jetty advisories that have a fix at or below 9.4.58. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Raise the relay's own jackson-databind pin from 2.18.4 to 2.18.11. jackson-core follows through jackson-bom. Exclude org.json:json 20090211 from socket.io-client. Android provides org.json, and the socket.io-client-java install guide excludes it the same way. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
17554f1 to
98c209d
Compare
…lock The testing-api Dockerfile copied only package.json before `yarn install`, so the image resolved dependencies from the package.json ranges at build time and ignored yarn.lock. Copy yarn.lock first and install with --frozen-lockfile. The sdk-test-runner Dockerfile already copied yarn.lock. Add --frozen-lockfile so that a stale lockfile stops the build, instead of yarn rewriting the lockfile inside the image. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

🤖 Generated from Claude
Jira: FFESUPPORT-999
This PR clears the open and auto-dismissed Dependabot alerts in
sdk-test-data, except the three advisories listed under Deferred. It also clears advisories that an OSV scan finds and Dependabot does not report. This repo is test infrastructure, so the upgrades are aggressive where the tests pass. No relay changes the Eppo SDK version that it tests. No test-data or workflow changes. The testing-api and sdk-test-runner Dockerfiles change only in how they install fromyarn.lock.Advisories
yarn.lockbuild.gradlelibs.versions.tomlapp/build.gradle.kts"Ships?" means that the vulnerable version was in a published artifact before this PR. The
sdk-test-runnerandtesting-apiimages push to GAR:latestwhen this merges. Both Dockerfiles runyarn install, which also installs dev tooling. Before this PR, the testing-api Dockerfile ranyarn installbefore it copiedyarn.lock, so its image resolved from thepackage.jsonranges at build time. This PR makes both images install fromyarn.lock(see Dockerfiles below). The relays are not published. CI builds the node, php, python, ruby, java, and go relays from source.What changed and why
validate:tests): ts-jest 29.4.14 and TypeScript 6. The lockfile is regenerated. jest stays at 30.4.2, because jest 30.5 pulls brace-expansion 5, and brace-expansion 5.0.9+ needs Node 20.validate-test-data.ymlruns Node 18.typesmoves intocompilerOptions. At the top level TypeScript ignored it, and TypeScript 6 no longer includes@typespackages by default.@eppo/node-server-sdkstays 4.0.0. TypeScript stays 5.9, because the NestJS 11 CLI ships TypeScript 5.9.3.rootDiris set. Without it, TypeScript 6 stops this build with TS5011. The emitted JavaScript is identical.globalsand@eslint/jswere missing, soyarn lintcrashed. They are added, and the one formatting error that lint then reports is fixed.httpdependency is removed. It is the npm security holding package, andimport { createServer } from 'http'loads the Node core module. socket.io ^4.8.4, axios ^1.20.0, dotenv ^18.0.4, TypeScript ^6.0.3, and the newest lint tooling. The lockfile is regenerated. Thebrace-expansionandwsresolutions are removed. Without them, the lockfile resolves brace-expansion 5.0.12 and ws 8.21.3. minimatch asks for^5.0.8, which also admits the vulnerable 5.0.8, so the lockfile holds the patched version, not the range.rootDirand the missing lint dependencies are added, as in testing-api. The emitted JavaScript is identical.@xmldom/xmldom,postcss, andtarresolution floors go up. Thefast-uriresolution is removed, because its only requester (ajv) asks for^3.0.1. The other transitives re-resolve in range, with no full lockfile refresh. The prettier, eslint-config-prettier, TypeScript, and@types/reactfloors go up in their current majors.@eppo/react-native-sdkstays 3.8.0.jetty-bom9.4.58.v20250814, the newest public 9.4 release, so all Jetty artifacts resolve to 9.4.58.eppo-server-sdkstays 5.2.0.jacksonDatabindpin goes from 2.18.4 to 2.18.11.org.jsonis excluded from socket.io-client, as the socket.io-client-java install guide shows, because Android provides it.yarn.lockbeforeyarn install. Both Dockerfiles now runyarn install --frozen-lockfile. The runner Dockerfile already copiedyarn.lock. With the flag, the build stops whenpackage.jsonasks for a package or a range thatyarn.lockdoes not have. Without the flag, the runner builds in the tested cases, and its image installs versions that are not inyarn.lock.build-and-push.ymltags the images with a hardcodedVERSIONandlatest.How the tests and CI protect this change
All results are from a clean
git archive HEADcopy with fresh installs, unless noted. The Docker and Lockfile pinning results are fromd183376, which changes only the two Dockerfiles.--frozen-lockfile. node-sdk-relay, testing-api, and sdk-test-runner also install with--frozen-lockfileon Node 20.19.1.validate:tests225/225 andobfuscate:ufc1/1 on Node 24, and again in anode:18container.ufc/flags-v1-obfuscated.jsondoes not change.configuration-wire/generate.tsruns and changes no file. Roottsc -p .is not a gate: it also sweeps the relays with the root config. It reports 30 errors onmainand 31 on this branch, all underpackage-testing/. The root's own files have 0 errors on both.nest build, jest 2/2, e2e 1/1, eslint, andtsc --noEmitpass.tscbuild and eslint pass. On both,dist/built with TypeScript 6 is identical todist/built onmainwith TypeScript 5.9.3. That proves the compiler change only. The runs below exercise the upgraded runtime dependencies on the runner's server mode (HTTP through axios), the runner's client mode (socket.io), and the testing-api HTTP API (express).main), andtsc1 error (the same error as onmain). An android metro bundle (expo export --platform android) builds onmainand on this branch with a temporary, uncommittedmetro.config.js. See Not validated before merge.maingives the same results. The java relay also builds and passes 256/258 on JDK 17 (the CI version) in a docker network with this branch's images.--type=clientin docker. A small socket.io client forwards each request to the node relay over HTTP. Themainimage (socket.io 4.8.3, socket.io-parser 4.2.6) and this branch's image (4.8.4, 4.2.7) both pass 264/264. No CI job runs client mode.docker build --no-cachebuilds the testing-api image onnode:22and the runner image onnode:22-alpine. The images contain body-parser 2.3.0, qs 6.16.0, socket.io-parser 4.2.7, and nohttppackage. The testing-api image, the runner image, and the node relay on one docker network pass 264/264.name@versionin each image'snode_moduleswith that project'syarn.lock. Built today with themainDockerfile, the testing-api image has 16 versions that are not inyarn.lock. One is the runtime dependency dotenv: 18.0.5 (published 2026-09-30) in the image, 18.0.4 in the lockfile. The other 15 are dev tooling. With thed183376Dockerfile, every installed version is inyarn.lock. The only lockfile entry that the image does not install is fsevents, which declares"os": ["darwin"]. The runner image matches itsyarn.lock(178 of 178) with both Dockerfiles. With a stalepackage.json, an added dependency or a range that excludes the locked version stops bothd183376builds. Removingcors(testing-api) orargs-parser(runner) does not stop the build, and the image installs a subset ofyarn.lock. Themainrunner Dockerfile builds in both stale cases, and the image installs versions that are not inyarn.lock.yarn audit: 0 advisories in root, node-sdk-relay, testing-api, and sdk-test-runner. react-native-sdk-relay reports only decode-uri-component and image-size (Deferred).yarn.lock,composer.lock,Gemfile.lock,go.sum,requirements.txt): only the same two react-native-sdk-relay packages. OSV scan of the resolved Gradle graphs: android-relay 0 rows. java-server-sdk-relay has only deferred Jetty, jackson, and logback rows. OSV stops reporting GHSA-wjpw-4j6x-6rwh at 9.4.58.v20250814 only because of how it orders the.v2025…suffix. The advisory lists 9.4.58 as last affected, so it stays open.main, which now includes Fix java relay host binding for CI #159 (java relay binds0.0.0.0). No file overlaps. I dispatched two workflows at98c209d. The next commit,d183376, changes only the two Dockerfiles, and neither workflow builds those images:Validate Test Data(run): passes.Test Packaged SDKs(run): java 256/258 (2 skipped) and node 264/264; go, ruby, and python pass. php fails with the same signature asmain("SDK Relay server failed to start" after 60 health checks). The cause is the php-sdk-relay lock, which needs PHP 8.4 on a PHP 8.3 runner (FFESUPPORT-969). This PR does not change that relay. fix(FFESUPPORT-969): re-lock php relay for PHP 8.3; honor sdk_ref, fail fast, pin checkout in package tests #164 fixes it; on its branch, everyTest Packaged SDKsjob passes, php included (run). This workflow uses the GAR:latestrunner and testing-api images.17554f1ande9b3a0falso failed java (ECONNREFUSED 172.17.0.1:4000), asmaindid before Fix java relay host binding for CI #159.Test Packaged SDKsran on a throwaway branch,workflow-test/ffesupport-999-branch-images(run). The branch wasd183376plus one commit,2fa99a6, which changes only the shared test action. With that commit, each job builds the runner and testing-api images from the checkout, withyarn install --frozen-lockfile, instead of pulling them from GAR. Each job logs the build commit and these image versions: body-parser 2.3.0, qs 6.16.0, dotenv 18.0.4, socket.io-parser 4.2.7, and nohttppackage. Results: node 264/264, java 256/258 (2 skipped), and go, python, and ruby 229/239 each (10 skipped), with 0 failures. Each count equals the count in the98c209drun on the GAR:latestimages. php fails as in the98c209drun: its relay'scomposer.lockneeds PHP >= 8.4.1, and the runner has PHP 8.3.6 (FFESUPPORT-969). The throwaway branch is deleted.Not validated before merge
Test Packaged SDKspulls the runner and testing-api images from GAR:latest, so a normal run does not test this branch's runner or testing-api code. The throwaway run above builds them from this branch instead. The php relay did not run against them, because it does not start (FFESUPPORT-969).yarn.lockversions. The base imagesnode:22andnode:22-alpineare floating tags, so the published images can have a newer OS layer and Node 22 release than the images tested here.:lateston merge.build-and-push.ymlalso overwrites the1.1.0tag and keeps no per-build tag. Record the current image digests before merge. After both release workflows finish, dispatchTest Packaged SDKsonmain.uuid: ^14resolution onmainis ESM-only. That is pre-existing, and this PR does not change it. android-relay does not compile against android-sdk 4.4.0 onmain(apiUrl,TestClientActivity.kt:186). On this branch it fails with the same single error. Its change is verified only by the resolved dependency graph.Deferred
require('query-string')without declaring it, and gets the query-string 7 copy that @react-navigation/core 7.17 brings. A trial bump of @react-navigation removed that copy and broke the metro bundle. The clean fix is the Expo upgrade.eppo-server-sdk5.2.0, the SDK under test. The fix belongs in the SDK repository..eslintrcsupport, which this relay uses. jest-expo 52 is built on jest 29. No CI runs this relay.require(esm)path under Node and jest. That is more than a version bump. It was not tried.<7) and typescript-eslint (peer<6.1.0) exclude it. Its npm package exposes no compiler API for ts-node.validate-test-data.yml.Dependabot PRs
No Dependabot PR is open in this repo, so this PR supersedes none.
🤖 Generated with Claude Code