fix(deps): patch frontend audit security floors - #1623
seonghobae wants to merge 20 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
📝 WalkthroughWalkthroughThe frontend updates Next.js, eslint-config-next, Vitest, js-yaml, and sharp versions. New tests validate manifest values, workspace overrides, lockfile consistency, and dependency security floors. ChangesFrontend security floor enforcement
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: 🟡 Moderate · up to The frontend dependency update raises Vitest security floors, but its validation can still accept a mismatched root lockfile resolution or missing referenced snapshot. This can allow future dependency drift to bypass the intended security-floor contract and should be corrected before merge. 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@codex review Please review only the current exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d76f7b4508
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
exact-head validation receiptHead:
Visual Inspection: directly inspected the production build in a real browser at 1280×720, locale |
Exact-head dependency repair — 2026-09-09Current head: The prior clean audit became stale when GitHub published new
Exact-head local evidence:
The lockfile-generation commands that emitted deprecation or peer warnings are retained as failed investigative evidence and are not counted as verification. Required hosted Checks and a fresh current-head independent review still govern merge. |
|
Central-prerequisite refresh only; Naruon source/head remains Protected #2040's repository-identity traversal RED remains unfixed. A whole-file mutation attempt created ordinary Do not copy the central scheduler into Naruon or reuse this PR's old CodeQL receipt. Normal path remains #2040 bounded/path-wise security repair + current-main reconciliation + exact-head checks/review → unchanged external dispatch canary → a new #1623 protected-lineage CodeQL generation. |
|
Fresh downstream evidence validates this dependency-security lane as a still-live shared-base prerequisite. Utility-tools #1718 exact This does not make #1623 merge-ready: its own historical CodeQL generation remains terminal FAILURE and central #2040/external-dispatch prerequisites remain unsettled. It does show that duplicating the fix into #1718 would violate owner boundaries. Keep #1623 as canonical frontend dependency-security owner, obtain a new protected-lineage terminal Security/CodeQL generation after the central prerequisite settles, then let dependent PRs ordinary-restack onto the protected fix. |
|
Central repair-plane topology correction — 2026-09-18 KST
This does not make #2175 a workaround for
|
Fresh central-owner handoff —
|
|
2026-09-18 fresh owner-path handoff: central |
|
2026-09-18 central prerequisite refresh: |
|
Fresh prerequisite correction from canonical
After that reconciled head: focused scheduler/repository-identity GREEN → fresh exact-head hosted checks + qualifying independent approval → unchanged external dispatch canary → only then revalidate/integrate this #1623 lane. #1623’s current six local workflow successes and exact-head approval remain valid evidence for its existing head, but they do not satisfy or transfer across the central reconciliation boundary. |
|
Central prerequisite update — 2026-09-19 KST. New central lane #2272 is not accepted yet: its five exact-head hosted runs are still queued, CodeRabbit has an unresolved current-head redirect-credential finding on the CodeQL identity helper, and a second review records missing deploy-pages regression coverage plus incomplete inheritance of sibling #2269's focused CodeQL URL-origin test. #2269 and #2272 therefore remain sibling repair authorities until a complete successor demonstrably carries every valid production/test delta. Do not change #1623 source for this. Its dependency-security source and historical six-GREEN exact-head generation remain valid for that generation, while the later #1718 Trivy receipt still requires current-database revalidation after central acceptance. Merge boundary now explicitly includes verified central base-SAST/security convergence (#2269/#2272 or complete successor) as part of the central owner acceptance step before external dispatch canary and fresh #1623 revalidation. No predecessor-central GREEN, scanner suppression, unchanged-head rerun, or feature-level duplicate repair should be used to bypass it. |
2026-09-19 prerequisite handoffThe exact Central base-SAST/security is not yet accepted: Keep this lane Draft. Required order is #2269/#2272 convergence or verified complete successor → #2040 path-wise protected-main reconciliation (+ #2268/#2271 adopt/adapt where applicable) → fresh central hosted/review acceptance → unchanged external dispatch canary → ordinary/current-base revalidation of #1623. When this lane is revalidated, reacquire Security against the then-current vulnerability database; do not transfer the older Security SUCCESS over the later #1718 Trivy observation. |
Central prerequisite delta — 2026-09-19 KSTFresh owner evidence adds one material condition before this dependency-security lane may reacquire current vulnerability evidence:
Therefore #1623’s historical six-GREEN generation remains valid only for its own exact generation. Revalidation must wait until the central #2269/#2272 security delta is converged and #2040’s protected-main reconciliation is accepted, then reacquire Security against the then-current protected ancestry and vulnerability database before normal integration. No dependency-source churn, scanner suppression, blind rerun, or predecessor-receipt transfer in this lane. |
2026-09-19 prerequisite refinement — central CodeQL GHAS credential ownerFresh central owner state adds #2275 is not acceptance-ready. Its exact head has Security/CodeQL/Semgrep PR runs queued, and CodeRabbit has one unresolved current-head correctness thread: the fail-closed test checks Also update the base-SAST state: Therefore #1623's next admissible transition remains evidence-only after central integration: #2269/#2272 convergence + #2275 correction/acceptance → #2040 path-wise protected-main reconciliation/current central GREEN + qualifying review → external dispatch canary → ordinary adoption of the then-protected central/workflow ancestry → fresh Security scan against the then-current vulnerability database and exact-head CodeQL/review evidence. The existing six-GREEN |
#2275 intervening deltaCentral The successor is still not accepted: fresh exact-head Security #1623 therefore stays source-stable. Its next admissible transition remains #2269/#2272 convergence + #2275 exact-head acceptance → #2040 protected-main path-wise reconciliation/current central GREEN + qualifying review → external dispatch canary → ordinary adoption of then-protected central ancestry → fresh Security against the then-current vulnerability database plus exact-head CodeQL/review evidence. Existing |
#2275 exact-head advanceCurrent central authority is now |
Central prerequisite refinement — 2026-09-19Keep the dependency-security source/evidence boundary unchanged, but supersede the older central snapshot in this PR body with the current owner topology.
Therefore #1623's older six-GREEN generation remains valid only for its own exact historical workflow/database generation. Do not restack or rerun this dependency owner until the central security/CodeQL owner set has converged through normal ancestry and the external dispatch boundary is accepted. At that point reacquire Security against the then-current vulnerability DB and only the other evidence invalidated by the changed workflow/base contract; do not duplicate dependency source into feature lanes. |
|
Central prerequisite refinement, 2026-09-19 KST: keep this dependency-security head source-stable. |
|
2026-09-19 prerequisite refresh: central GHAS/security topology advanced and this dependency owner must not consume the old #2275 state as acceptance. |
Central prerequisite refresh — 2026-09-19The dependency-security source/evidence on this branch is unchanged; only the upstream acceptance graph changed. Fresh central authority is now:
Do not transfer #1623's older six-GREEN generation across that central change. After central owner acceptance and the real external canary, reacquire Security against the then-current Trivy/vulnerability DB generation and any other evidence invalidated by the changed protected/required-workflow ancestry. No second dependency writer, blind rerun, source-neutral wake, central source copy, or scanner weakening. |
Central prerequisite refresh — #2279 scope repair and #2272 executable Pages gate adoptedDependency-security source on #1623 is unchanged. Upstream authority advanced and the current handoff is:
Keep #1623 source-stable. Its earlier six-GREEN generation is historical evidence only. Reacquire Security against the then-current protected ancestry and vulnerability database only after the full central security/capability/permission/scheduler path is accepted; do not create a source-neutral wake commit or transfer predecessor receipts. |
|
2026-09-19 prerequisite refresh: central #2272 is separately exact |
|
Current central prerequisite correction (2026-09-19 KST): This does not invalidate #1623 source or its historical exact-head six-workflow GREEN/approval generation; it changes only the external acceptance ordering. Keep |
Current authority — 2026-09-20 KST
develop@042b0c70531b229af3acbd0421a2f23098d848b3509be4c1d9b6c7ba239a108656e2382681a853419a4271cfc635ebe58ebd7003d67aa87a7912ce03Retained causal repair
This lane owns the frontend dependency-security floors and their regressions. Exact source pins
next/eslint-config-nextto16.3.4and carries the lockfile line resolvingsharpat fixed0.35.4. No scanner suppression, baseline waiver, generated-lockfile hand edit, or source-neutral wake commit is used.Exact
509be4c...repository-local evidence for its own generation remains valid historical evidence:35057412289— SUCCESS35057412239— SUCCESS35057412283— SUCCESS35057412507— SUCCESS35057412234— SUCCESS35057412233— SUCCESSPRR_kwDOSNjZ2s8AAAABNw7GIA— APPROVED, anchored to exact headThose receipts do not prove safety against vulnerability databases or central workflow generations observed later.
Fresh inherited-vulnerability evidence
Two later product lanes independently confirm that frontend dependency evidence must be refreshed through this owner rather than copied into feature PRs.
a9fa22197302afe1e53cd14d0f6192ed3679e325produced a Trivy failure reporting protected-basenext/sharpfindings includingCVE-2026-75604,GHSA-2xp9-vwfh-vxw4, andGHSA-rgj7-g3m4-5g8c. feat(tools): hash_generator 및 json_formatter 도구 추가 #1718 does not own dependency manifests.477a333be738da0ca1f02faa809db98a59f250d2now has Application CI/Bandit/Semgrep/Docker success, while Security fails specifically intrivy-fs; scorecard, dependency-review and OSV are GREEN. That Calendar lane changes frontend product/tests plusfrontend/package.json, not the canonical dependency-security graph. It must not become a second lockfile/security owner.The exact #1623 source already carries the intended Next/Sharp floors, but the later Trivy observations are newer than #1623's existing Security receipt. Reacquire the current database evidence on the then-current owner/protected ancestry before merge; if a new vulnerability is actually present after that refresh, repair it here or in a verified successor, not in #1682/#1718.
Central control-plane prerequisite
Protected central authority is now
.github/main@e6334e229581a918e2f22de18733b76fa65d7e71; #2279 is already protected ancestry..github#2040has completed current-main ordinary/non-force reconciliation at exact652764a37fc8af032f03cbe75da84ca88aee96bb. It is mergeable/Draft, 175 ahead / 0 behind, and its repository-identity production repair is present. Fresh exact-head CodeQL/Python Security/Security/SAST/Runtime Quality/Trusted-uv runs remain queued; current-head independent approval is still required..github#2271@a0e1424de409ec474e7bc6e9f91a9e99b8a0915eis Draft / Proposed on current protected main. Exact-head checks and a qualifying independent current-head approval remain mandatory before Ready; predecessor evidence does not transfer..github#2275@572cfed270ae3b3cd38faca4d97ce028093e5373remains Draft on current #2271 and proves the analyses-endpoint capability-selection contract only..github#2272@cd3b41b8989e096d1ee375d332347c8bb819acf9remains the separate Pages/SAST successor lane and is still Draft..github#2276remains the real target-repositorycode-scanning/analysespermission/canary boundary; selector logic cannot manufacture installation permission..github#712remains the Actions execution-capacity owner; the current observation still has a three-digit queued backlog with no stable in-progress execution. Do not blind-rerun this unchanged dependency head to work around the central queue/control plane.#1623's historical local CodeQL GREEN is therefore not a substitute for current central acceptance or a current vulnerability-database scan.
Merge boundary
Keep Draft. Required order:
No synthetic verdict/status, blind rerun, no-op wake commit, temporary retarget, admin bypass, self-approval, force push/destructive rebase, scanner weakening, central source copy, duplicate feature-level dependency writer, predecessor-evidence transfer, or gate weakening.