Skip to content

fix(FFESUPPORT-999): remediate September 2026 vulnerabilities - #163

Merged
aarsilv merged 8 commits into
mainfrom
aarsilv/ffesupport-999/fix-vulnerabilities
Oct 3, 2026
Merged

aarsilv merged 8 commits into
mainfrom
aarsilv/ffesupport-999/fix-vulnerabilities

Conversation

@aarsilv

@aarsilv aarsilv commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated from Claude

Jira: FFESUPPORT-999

This PR clears the open and auto-dismissed Dependabot alerts in sdk-test-data, except the three advisories listed under Deferred. It also clears advisories that an OSV scan finds and Dependabot does not report. This repo is test infrastructure, so the upgrades are aggressive where the tests pass. No relay changes the Eppo SDK version that it tests. No test-data or workflow changes. The testing-api and sdk-test-runner Dockerfiles change only in how they install from yarn.lock.

Advisories

Package Advisories Lockfile or build file Before → after Ships?
brace-expansion GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 all 5 yarn.lock 1.1.14 / 1.1.16 → 1.1.21; 2.1.0 / 2.1.2 → 2.1.7; 5.0.7 → 5.0.12 Both images, as dev tooling that the entrypoints do not run
browserslist GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx root, node-sdk-relay, react-native-sdk-relay 4.28.2 → 4.29.1 No
baseline-browser-mapping GHSA-w5vr-8v7q-w6rv root, node-sdk-relay, react-native-sdk-relay 2.10.24 → 2.11.26 No
js-yaml GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh root, node-sdk-relay, react-native-sdk-relay 3.15.0 → 3.15.2; 4.3.0 → 4.3.2 No
fast-uri GHSA-4c8g-83qw-93j6, GHSA-v2hh-gcrm-f6hx, GHSA-7p8r-x3mc-p8w7, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc, GHSA-jqff-g426-hqxp node-sdk-relay, react-native-sdk-relay 3.1.2 → 3.1.8 No
multer GHSA-qfvm-cv95-jqjf, GHSA-wc9g-mqfw-jrwm, GHSA-535w-7cp7-47q4, GHSA-qvfw-j98x-7q72 node-sdk-relay 2.2.0 → 2.4.0 No
qs GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g node-sdk-relay, testing-api 6.15.3 / 6.15.2 → 6.16.0 testing-api image
body-parser GHSA-v422-hmwv-36x6 testing-api 2.2.2 → 2.3.0 testing-api image
socket.io-parser GHSA-2m8v-j782-fhvr sdk-test-runner 4.2.6 → 4.2.7 runner image
http (npm) MAL-2025-22760 (OSV only) sdk-test-runner 0.0.1-security → removed runner image
@xmldom/xmldom 13 GHSAs, one Dependabot alert each (#376, #378–#388, #356) react-native-sdk-relay 0.9.10 → 0.9.12 No
nanoid GHSA-xwg4-73v4-xw9w, GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8 react-native-sdk-relay 3.3.11 / 3.3.12 → 3.3.19 No
postcss GHSA-r28c-9q8g-f849, GHSA-fxqj-rqcc-2cmp react-native-sdk-relay 8.5.15 → 8.5.28 No
tar GHSA-r292-9mhp-454m react-native-sdk-relay 7.5.20 → 7.5.22 No
undici GHSA-v3r7-h72x-cjcm, GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5 react-native-sdk-relay 6.27.0 → 6.29.0 No
Jetty 9.4 6 of 11 GHSAs (OSV only): GHSA-qw69-rqj8-6qw8, GHSA-p26g-97m4-6q7c, GHSA-hmr7-m48g-48f6, GHSA-58qw-p7qm-5rvh, GHSA-g8m5-722r-8whq, GHSA-q4rv-gq96-w7c5 java-server-sdk-relay build.gradle 9.4.48.v20220622 → 9.4.58.v20250814 No
jackson-core / jackson-databind 9 GHSAs (OSV only): GHSA-72hv-8253-57qq, GHSA-r7wm-3cxj-wff9, GHSA-3pjw-73gf-8qr5, GHSA-5gvw-p9qm-jgwh, GHSA-5jmj-h7xm-6q6v, GHSA-hgj6-7826-r7m5, GHSA-j3rv-43j4-c7qm, GHSA-mhm7-754m-9p8w, GHSA-rmj7-2vxq-3g9f android-relay libs.versions.toml 2.18.4 → 2.18.11 No
org.json:json GHSA-3vqj-43w4-2q58, GHSA-4jq9-2xhw-jpx7 (OSV only) android-relay app/build.gradle.kts 20090211 → excluded No

"Ships?" means that the vulnerable version was in a published artifact before this PR. The sdk-test-runner and testing-api images push to GAR :latest when this merges. Both Dockerfiles run yarn install, which also installs dev tooling. Before this PR, the testing-api Dockerfile ran yarn install before it copied yarn.lock, so its image resolved from the package.json ranges at build time. This PR makes both images install from yarn.lock (see Dockerfiles below). The relays are not published. CI builds the node, php, python, ruby, java, and go relays from source.

What changed and why

  • Root (jest tooling for validate:tests): ts-jest 29.4.14 and TypeScript 6. The lockfile is regenerated. jest stays at 30.4.2, because jest 30.5 pulls brace-expansion 5, and brace-expansion 5.0.9+ needs Node 20. validate-test-data.yml runs Node 18. types moves into compilerOptions. At the top level TypeScript ignored it, and TypeScript 6 no longer includes @types packages by default.
  • node-sdk-relay: NestJS 11.2.6, which pins multer 2.4.0. The lint and test tooling moves to the newest release in its current major. The lockfile is regenerated. @eppo/node-server-sdk stays 4.0.0. TypeScript stays 5.9, because the NestJS 11 CLI ships TypeScript 5.9.3.
  • testing-api: express ^5.2.1, dotenv ^18.0.4, TypeScript ^6.0.3, and the newest lint tooling. The lockfile is regenerated. rootDir is set. Without it, TypeScript 6 stops this build with TS5011. The emitted JavaScript is identical. globals and @eslint/js were missing, so yarn lint crashed. They are added, and the one formatting error that lint then reports is fixed.
  • sdk-test-runner: the http dependency is removed. It is the npm security holding package, and import { createServer } from 'http' loads the Node core module. socket.io ^4.8.4, axios ^1.20.0, dotenv ^18.0.4, TypeScript ^6.0.3, and the newest lint tooling. The lockfile is regenerated. The brace-expansion and ws resolutions are removed. Without them, the lockfile resolves brace-expansion 5.0.12 and ws 8.21.3. minimatch asks for ^5.0.8, which also admits the vulnerable 5.0.8, so the lockfile holds the patched version, not the range. rootDir and the missing lint dependencies are added, as in testing-api. The emitted JavaScript is identical.
  • react-native-sdk-relay (stays on Expo 52): the @xmldom/xmldom, postcss, and tar resolution floors go up. The fast-uri resolution is removed, because its only requester (ajv) asks for ^3.0.1. The other transitives re-resolve in range, with no full lockfile refresh. The prettier, eslint-config-prettier, TypeScript, and @types/react floors go up in their current majors. @eppo/react-native-sdk stays 3.8.0.
  • java-server-sdk-relay: spark-core 2.9.4 is the last Spark release. The relay imports jetty-bom 9.4.58.v20250814, the newest public 9.4 release, so all Jetty artifacts resolve to 9.4.58. eppo-server-sdk stays 5.2.0.
  • android-relay: the relay's own jacksonDatabind pin goes from 2.18.4 to 2.18.11. org.json is excluded from socket.io-client, as the socket.io-client-java install guide shows, because Android provides it.
  • Dockerfiles (testing-api, sdk-test-runner), from review: the testing-api Dockerfile now copies yarn.lock before yarn install. Both Dockerfiles now run yarn install --frozen-lockfile. The runner Dockerfile already copied yarn.lock. With the flag, the build stops when package.json asks for a package or a range that yarn.lock does not have. Without the flag, the runner builds in the tested cases, and its image installs versions that are not in yarn.lock.
  • No version bump. No earlier remediation (Address all known vulnerabilities across packages #151, fix(FFESUPPORT-750): address open Dependabot vulnerabilities #158, fix(FFESUPPORT-889): remediate July 2026 dependabot vulnerabilities #160, fix(FFESUPPORT-889): re-resolve axios + brace-expansion in relay harnesses (Vanta 2026-07) #162) bumped a harness version. build-and-push.yml tags the images with a hardcoded VERSION and latest.

How the tests and CI protect this change

All results are from a clean git archive HEAD copy with fresh installs, unless noted. The Docker and Lockfile pinning results are from d183376, which changes only the two Dockerfiles.

  • Every changed yarn project installs with --frozen-lockfile. node-sdk-relay, testing-api, and sdk-test-runner also install with --frozen-lockfile on Node 20.19.1.
  • Root: validate:tests 225/225 and obfuscate:ufc 1/1 on Node 24, and again in a node:18 container. ufc/flags-v1-obfuscated.json does not change. configuration-wire/generate.ts runs and changes no file. Root tsc -p . is not a gate: it also sweeps the relays with the root config. It reports 30 errors on main and 31 on this branch, all under package-testing/. The root's own files have 0 errors on both.
  • node-sdk-relay: nest build, jest 2/2, e2e 1/1, eslint, and tsc --noEmit pass.
  • testing-api and sdk-test-runner: tsc build and eslint pass. On both, dist/ built with TypeScript 6 is identical to dist/ built on main with TypeScript 5.9.3. That proves the compiler change only. The runs below exercise the upgraded runtime dependencies on the runner's server mode (HTTP through axios), the runner's client mode (socket.io), and the testing-api HTTP API (express).
  • react-native-sdk-relay: jest 1/1, eslint 0 errors (9 warnings, as on main), and tsc 1 error (the same error as on main). An android metro bundle (expo export --platform android) builds on main and on this branch with a temporary, uncommitted metro.config.js. See Not validated before merge.
  • Local package tests: testing-api, the relay, and sdk-test-runner from this branch run as host processes. The node relay passes 264/264 and the java relay passes 256/258 (2 skipped). main gives the same results. The java relay also builds and passes 256/258 on JDK 17 (the CI version) in a docker network with this branch's images.
  • Runner client mode (socket.io): the runner image runs with --type=client in docker. A small socket.io client forwards each request to the node relay over HTTP. The main image (socket.io 4.8.3, socket.io-parser 4.2.6) and this branch's image (4.8.4, 4.2.7) both pass 264/264. No CI job runs client mode.
  • Docker: docker build --no-cache builds the testing-api image on node:22 and the runner image on node:22-alpine. The images contain body-parser 2.3.0, qs 6.16.0, socket.io-parser 4.2.7, and no http package. The testing-api image, the runner image, and the node relay on one docker network pass 264/264.
  • Lockfile pinning: a script compares every name@version in each image's node_modules with that project's yarn.lock. Built today with the main Dockerfile, the testing-api image has 16 versions that are not in yarn.lock. One is the runtime dependency dotenv: 18.0.5 (published 2026-09-30) in the image, 18.0.4 in the lockfile. The other 15 are dev tooling. With the d183376 Dockerfile, every installed version is in yarn.lock. The only lockfile entry that the image does not install is fsevents, which declares "os": ["darwin"]. The runner image matches its yarn.lock (178 of 178) with both Dockerfiles. With a stale package.json, an added dependency or a range that excludes the locked version stops both d183376 builds. Removing cors (testing-api) or args-parser (runner) does not stop the build, and the image installs a subset of yarn.lock. The main runner Dockerfile builds in both stale cases, and the image installs versions that are not in yarn.lock.
  • yarn audit: 0 advisories in root, node-sdk-relay, testing-api, and sdk-test-runner. react-native-sdk-relay reports only decode-uri-component and image-size (Deferred).
  • OSV scan of all tracked lockfiles (5 yarn.lock, composer.lock, Gemfile.lock, go.sum, requirements.txt): only the same two react-native-sdk-relay packages. OSV scan of the resolved Gradle graphs: android-relay 0 rows. java-server-sdk-relay has only deferred Jetty, jackson, and logback rows. OSV stops reporting GHSA-wjpw-4j6x-6rwh at 9.4.58.v20250814 only because of how it orders the .v2025… suffix. The advisory lists 9.4.58 as last affected, so it stays open.
  • CI: no workflow runs on a PR that changes only these paths. This branch is rebased on main, which now includes Fix java relay host binding for CI #159 (java relay binds 0.0.0.0). No file overlaps. I dispatched two workflows at 98c209d. The next commit, d183376, changes only the two Dockerfiles, and neither workflow builds those images:
  • CI with this branch's images: Test Packaged SDKs ran on a throwaway branch, workflow-test/ffesupport-999-branch-images (run). The branch was d183376 plus one commit, 2fa99a6, which changes only the shared test action. With that commit, each job builds the runner and testing-api images from the checkout, with yarn install --frozen-lockfile, instead of pulling them from GAR. Each job logs the build commit and these image versions: body-parser 2.3.0, qs 6.16.0, dotenv 18.0.4, socket.io-parser 4.2.7, and no http package. Results: node 264/264, java 256/258 (2 skipped), and go, python, and ruby 229/239 each (10 skipped), with 0 failures. Each count equals the count in the 98c209d run on the GAR :latest images. php fails as in the 98c209d run: its relay's composer.lock needs PHP >= 8.4.1, and the runner has PHP 8.3.6 (FFESUPPORT-969). The throwaway branch is deleted.

Not validated before merge

  • Test Packaged SDKs pulls the runner and testing-api images from GAR :latest, so a normal run does not test this branch's runner or testing-api code. The throwaway run above builds them from this branch instead. The php relay did not run against them, because it does not start (FFESUPPORT-969).
  • Both images now install the yarn.lock versions. The base images node:22 and node:22-alpine are floating tags, so the published images can have a newer OS layer and Node 22 release than the images tested here.
  • The new images push to :latest on merge. build-and-push.yml also overwrites the 1.1.0 tag and keeps no per-build tag. Record the current image digests before merge. After both release workflows finish, dispatch Test Packaged SDKs on main.
  • No CI builds or runs react-native-sdk-relay or android-relay. The react-native metro bundle only builds with package exports enabled, because the uuid: ^14 resolution on main is ESM-only. That is pre-existing, and this PR does not change it. android-relay does not compile against android-sdk 4.4.0 on main (apiUrl, TestClientActivity.kt:186). On this branch it fails with the same single error. Its change is verified only by the resolved dependency graph.
  • Dependabot closes the alerts after merge, not on this branch.

Deferred

  • decode-uri-component 0.2.2 (react-native-sdk-relay, GHSA-vcc3-ghjq-m6fr): the fix is 0.5.0. Only query-string 9.5 and later use it, and those releases are ESM-only. expo-router 4 calls require('query-string') without declaring it, and gets the query-string 7 copy that @react-navigation/core 7.17 brings. A trial bump of @react-navigation removed that copy and broke the metro bundle. The clean fix is the Expo upgrade.
  • image-size 1.2.1 (react-native-sdk-relay, GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq): React Native 0.76 pins metro ^0.81, and every metro 0.81.x release requires image-size ^1. metro 0.83.8 and later drop image-size. The practical fix is the Expo / React Native upgrade.
  • Jetty advisories with no public 9.4 fix (java-server-sdk-relay): GHSA-355h-qmc2-wpwf (9.4.60) and GHSA-2fvj-hgj9-j2gr (9.4.63) are not on Maven Central. GHSA-qh8g-58pp-2wxh and GHSA-7p3p-8qv8-m2vh are fixed only in 12.x. GHSA-wjpw-4j6x-6rwh lists 9.4.58 as last affected. The practical fix is a relay without Spark.
  • jackson and logback in java-server-sdk-relay (13 GHSAs, OSV only): jackson-core 2.18.3 (GHSA-72hv-8253-57qq, GHSA-r7wm-3cxj-wff9), jackson-databind 2.18.3 (GHSA-3pjw-73gf-8qr5, GHSA-5gvw-p9qm-jgwh, GHSA-5jmj-h7xm-6q6v, GHSA-hgj6-7826-r7m5, GHSA-j3rv-43j4-c7qm, GHSA-mhm7-754m-9p8w, GHSA-rmj7-2vxq-3g9f), and logback-core 1.3.15 (GHSA-25qh-j22f-pwp8, GHSA-jhq6-gfmj-v8fx, GHSA-p47f-322f-whfh, GHSA-qqpg-mvqg-649v). They come only from eppo-server-sdk 5.2.0, the SDK under test. The fix belongs in the SDK repository.
  • Expo SDK 53 or later for react-native-sdk-relay (React Native 0.79 or later, React 19). eslint 10 drops .eslintrc support, which this relay uses. jest-expo 52 is built on jest 29. No CI runs this relay.
  • NestJS 12 and TypeScript 6 in node-sdk-relay: NestJS 12 ships as ESM only. The relay compiles to CommonJS and tests with ts-jest in CommonJS mode. The upgrade needs a module-system change, or a verified require(esm) path under Node and jest. That is more than a version bump. It was not tried.
  • TypeScript 7: ts-jest (peer <7) and typescript-eslint (peer <6.1.0) exclude it. Its npm package exposes no compiler API for ts-node.
  • jest 30.5 at the root: it needs Node 20 in validate-test-data.yml.
  • chalk 6 in sdk-test-runner: it is ESM-only and needs Node 22. The runner compiles to CommonJS. No advisory.

Dependabot PRs

No Dependabot PR is open in this repo, so this PR supersedes none.

🤖 Generated with Claude Code

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The changes require final human review because they are too complex or risky for automated approval.

Review effort: Lite
Findings: None

What changed in this PR

This PR remediates September 2026 dependency vulnerabilities across SDK test infrastructure while preserving SDK versions and test data.

Changes:

  • Updates vulnerable npm, Maven, and Gradle dependencies.
  • Upgrades TypeScript, ESLint, and related tooling.
  • Removes the vulnerable npm http package and excludes redundant Android org.json.
File Description
tsconfig.json Updated as part of this pull request.
package.json Updated as part of this pull request.
package-testing/​testing-api/​yarn.lock Updated as part of this pull request.
package-testing/​testing-api/​tsconfig.json Updated as part of this pull request.
package-testing/​testing-api/​src/​routes.ts Updated as part of this pull request.
package-testing/​testing-api/​package.json Updated as part of this pull request.
package-testing/​sdk-test-runner/​yarn.lock Updated as part of this pull request.
package-testing/​sdk-test-runner/​tsconfig.json Updated as part of this pull request.
package-testing/​sdk-test-runner/​package.json Updated as part of this pull request.
package-testing/​react-native-sdk-relay/​yarn.lock Updated as part of this pull request.
package-testing/​react-native-sdk-relay/​package.json Updated as part of this pull request.
package-testing/​node-sdk-relay/​package.json Updated as part of this pull request.
package-testing/​java-server-sdk-relay/​build.gradle Updated as part of this pull request.
package-testing/​android-relay/​gradle/​libs.versions.toml Updated as part of this pull request.
package-testing/​android-relay/​app/​build.gradle.kts Updated as part of this pull request.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@aarsilv
aarsilv force-pushed the aarsilv/ffesupport-999/fix-vulnerabilities branch from e9b3a0f to 17554f1 Compare September 26, 2026 22:43
@aarsilv

aarsilv commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Response from codex:

Pre-push review (branch diff, lockfile greps, manifests, workflows): no blocking issues found. Every in-scope advisory is CLOSED at its lockfile line, except the items listed as deferred: decode-uri-component 0.2.2 and image-size 1.2.1 (react-native-sdk-relay), five Jetty 9.4 GHSAs, and the jackson/logback that eppo-server-sdk 5.2.0 brings. RUNTIME: none found. SCOPE: no change to an SDK under test, test data, a workflow, or a Dockerfile.

PR description fact-check, 3 rounds:

  • Round 1 (FIX FIRST): 6 wrong claims and several gaps. The wrong claims: "requesters ask for patched ranges" (^5.0.8 admits the vulnerable 5.0.8); "TypeScript 6 requires rootDir" (overbroad); "testing-api does not copy yarn.lock" (it copies the file after yarn install); "relays are built from source in CI" (not the react-native or android relays); the "Ships?" meaning for the removed http; and "Expo 53 = React Native 0.8x" (it is 0.79). The gaps: advisory-ID inventories, the OSV false negative for GHSA-wjpw-4j6x-6rwh, and the relays not run against the branch images. The two affected commit messages were also corrected; the tree is unchanged.
  • Round 2 (FIX FIRST): all round-1 items fixed. One new point: the runner's socket.io is used only in client mode, and no reported run exercised it. Claude then ran client mode on the main and branch runner images: both pass 264/264.
  • Round 3: POST AS IS. The three edits match the evidence. The only open item is a judgement call on the disclosed rollout risk: mutable image tags, testing-api resolving at build time, and branch images not run with the go, ruby, python, and php relays.

aarsilv and others added 7 commits September 26, 2026 20:43
Raise ts-jest to 29.4.14 and TypeScript to 6. Regenerate yarn.lock.
brace-expansion, browserslist, baseline-browser-mapping, and js-yaml
now resolve to patched versions.

Keep jest at 30.4.2. jest 30.5 pulls brace-expansion 5, which needs
Node 20. validate-test-data.yml runs Node 18.

Move "types" into compilerOptions. It was ignored at the top level, and
TypeScript 6 no longer includes @types packages by default.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…isories

Raise the NestJS 11 packages to ^11.2.6. @nestjs/platform-express
11.2.6 pins multer 2.4.0. Raise the lint and test tooling to the
newest releases in their current majors. Regenerate yarn.lock.

fast-uri, multer, qs, js-yaml, brace-expansion, browserslist, and
baseline-browser-mapping now resolve to patched versions.
@eppo/node-server-sdk stays at 4.0.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ries

Raise express to ^5.2.1, dotenv to ^18.0.4, TypeScript to ^6.0.3, and
the lint tooling to the newest releases. Regenerate yarn.lock.
body-parser, qs, and brace-expansion now resolve to patched versions.

Set rootDir. Without it, TypeScript 6 stops this build with TS5011.
The emitted JavaScript does not change.

Add the missing globals and @eslint/js dev dependencies so that
`yarn lint` runs. Fix the one formatting error it reports.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…visories

Remove the `http` dependency. It is the npm security holding package
(MAL-2025-22760), and `import ... from 'http'` loads the Node core
module.

Raise socket.io to ^4.8.4, axios to ^1.20.0, dotenv to ^18.0.4,
TypeScript to ^6.0.3, and the lint tooling to the newest releases.
Regenerate yarn.lock. socket.io-parser and brace-expansion now resolve
to patched versions.

Remove the brace-expansion and ws resolutions and their rationales.
The lockfile resolves brace-expansion 5.0.12 and ws 8.21.3 without
them. minimatch asks for brace-expansion ^5.0.8, and engine.io asks
for ws ~8.21.0.

Set rootDir. Without it, TypeScript 6 stops this build with TS5011.
The emitted JavaScript does not change. Add the missing globals and
@eslint/js dev dependencies so that `yarn lint` runs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Expo 52

Raise the resolutions floors for @xmldom/xmldom (^0.9.12), postcss
(^8.5.28), and tar (^7.5.22). Re-resolve fast-uri, nanoid, undici,
js-yaml, browserslist, baseline-browser-mapping, and brace-expansion
to patched versions in range. Raise the prettier,
eslint-config-prettier, TypeScript, and @types/react floors in their
current majors.

Remove the fast-uri resolution. Its only requester, ajv, asks for
^3.0.1, and that range resolves to 3.1.8. Update the rationales of the
changed resolutions.

@eppo/react-native-sdk stays at 3.8.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
spark-core 2.9.4 is the last Spark release and pulls Jetty
9.4.48.v20220622. Import jetty-bom 9.4.58.v20250814, the newest public
9.4.x release, so every Jetty artifact resolves to 9.4.58. This clears
the Jetty advisories that have a fix at or below 9.4.58.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Raise the relay's own jackson-databind pin from 2.18.4 to 2.18.11.
jackson-core follows through jackson-bom.

Exclude org.json:json 20090211 from socket.io-client. Android provides
org.json, and the socket.io-client-java install guide excludes it the
same way.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aarsilv
aarsilv force-pushed the aarsilv/ffesupport-999/fix-vulnerabilities branch from 17554f1 to 98c209d Compare September 27, 2026 00:43
@aarsilv
aarsilv requested a review from typotter September 27, 2026 01:08
@aarsilv
aarsilv marked this pull request as ready for review September 27, 2026 01:08
Copilot AI review requested due to automatic review settings September 27, 2026 01:08

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The testing-api Docker build does not install the patched lockfile, leaving vulnerable dependency resolution unreproducible.

Review effort: Lite
Findings: 1 High severity

Open (1)

Comment thread package-testing/testing-api/package.json
Comment thread package-testing/testing-api/package.json
…lock

The testing-api Dockerfile copied only package.json before `yarn
install`, so the image resolved dependencies from the package.json
ranges at build time and ignored yarn.lock. Copy yarn.lock first and
install with --frozen-lockfile.

The sdk-test-runner Dockerfile already copied yarn.lock. Add
--frozen-lockfile so that a stale lockfile stops the build, instead
of yarn rewriting the lockfile inside the image.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 13:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Moderate issues remain around Docker image validation ordering and dependency-only CI coverage.

Review effort: Lite
Findings: 1 High severity

Open (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It spans multiple ecosystems and includes React Native and Android dependency changes without automated CI coverage.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@aarsilv
aarsilv merged commit 33da68c into main Oct 3, 2026
3 checks passed
@aarsilv
aarsilv deleted the aarsilv/ffesupport-999/fix-vulnerabilities branch October 3, 2026 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants