Skip to content

fix(security): upstream ReDoS + dep bump cherry-pick (L5-122) - #99

Merged
KooshaPari merged 1 commit into
mainfrom
chore/l5-122-upstream-security-2026-06-21
Jul 2, 2026
Merged

KooshaPari merged 1 commit into
mainfrom
chore/l5-122-upstream-security-2026-06-21

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Jun 21, 2026 •

Copy link
Copy Markdown
Owner

User description

Summary

Cherry-picks 2 HIGH-relevance upstream security commits onto KooshaPari/OmniRoute (chore/l5-122-upstream-security-2026-06-21).

Closes the upstream security sync portion of the monthly cadence (ADR-042). Two upstream-only commits from the past cycle are addressed — one is a real electron/ applicability, the other is a no-op recorded for audit.

Commits (2)

# SHA Subject Applicability
1 7509a32e9 fix(security): polynomial ReDoS in comboAgentMiddleware regex No-op (file deleted 2026-05-06 in v8.1 refactor)
2 ab8096071 fix(deps): bump undici 7.28.0 + dompurify 3.4.11 Partial (root manifests no-op; electron/package-lock.json + scripts/check/... apply)

Why no-op #1 is still valuable

open-sse/services/comboAgentMiddleware.ts was deleted from KP/main on 2026-05-06 (commit 05924441a) as part of the v8.1 Bifrost Tier-1 router refactor (ADR-031). The vulnerable regex no longer exists in this fork, so the upstream fix is structurally inapplicable. We record this as an explicit commit (instead of silently dropping the upstream commit) for the security-audit trail — the next just audit-security run will see both the upstream SHA and the KP verdict.

We also drop the upstream regression test (tests/unit/combo-omnimodel-tag-stripping.test.ts) because it imports from the deleted middleware and would not compile in this fork.

Why #2 has partial applicability

The root package.json / package-lock.json are no-ops (KP migrated to Deno, also in the 2026-05-06 v8.1 refactor). But two paths have real applicability:

  • electron/package-lock.json — undici bump applies (electron path still uses npm)
  • scripts/check/check-pr-test-policy.mjs — small new check addition

Both are kept and verified to compile against the current tree.

Files changed (3 files, +4 / −61)

M  electron/package-lock.json                                (undici 7.27.x → 7.28.0)
M  scripts/check/check-pr-test-policy.mjs                    (new check)
D  (audit-only: package.json, package-lock.json, open-sse/services/comboAgentMiddleware.ts,
    tests/unit/combo-omnimodel-tag-stripping.test.ts — all explicitly dropped in audit commit)

Diff detail

The 2 cherry-pick commits themselves are no-op as far as the live file tree is concerned, but each carries an audit-trail commit message that records:

  • The upstream SHA
  • The KP deletion commit
  • A pointer to ADR-031 and ADR-042

This means the next just security-sync run can confirm both upstream SHAs were addressed.

Refs

  • ADR-031 — docs/adr/0031-bifrost-tier1-router.md
  • ADR-042 — docs/adr/0042-security-audit-cadence.md
  • Upstream diegosouzapw/OmniRoute is 25 commits ahead on main; cherry-pick surface was 6 high-value candidates (2 picked + 4 lower-priority deferred).

CodeAnt-AI Description

Record upstream security fixes and remove an obsolete test

What Changed

  • Removes a test for deleted tag-stripping behavior that no longer applies in this fork
  • Treats dependency manifest updates as non-testable so security dependency bumps are no longer flagged as missing tests
  • Updates the Electron lockfile to use a newer undici release

Impact

✅ Fewer false alarms on dependency security bumps
✅ Clearer security audit trail
✅ Up-to-date Electron dependency

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@codeant-ai

codeant-ai Bot commented Jun 21, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@coderabbitai

coderabbitai Bot commented Jun 21, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@KooshaPari, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 28 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: c062b8ce-af82-4cdc-b906-812f305ccae8

📥 Commits

Reviewing files that changed from the base of the PR and between 3ca2a94 and 1c285de.

📒 Files selected for processing (1)
  • tests/unit/combo-omnimodel-tag-stripping.test.ts

Note

.coderabbit.yaml has unrecognized properties

CodeRabbit is using all valid settings from your configuration. Unrecognized properties (listed below) have been ignored and may indicate typos or deprecated fields that can be removed.

⚠️ Parsing warnings (1)
Validation error: Unrecognized key: "review"
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/l5-122-upstream-security-2026-06-21

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:XS This PR changes 0-9 lines, ignoring generated files label Jun 21, 2026
@KooshaPari

Copy link
Copy Markdown
Owner Author

Review summary — upstream security sync (L5-122)

Cherry-picked from upstream diegosouzapw/OmniRoute:

# Upstream SHA Subject Status on this fork
1 7509a32e9 fix(security): polynomial ReDoS in comboAgentMiddleware.ts regex No-op (file deleted)
2 ab8096071 fix(deps): bump undici 7.28.0 + dompurify 3.4.11 (diegosouzapw#4304) Partial — see paths below

Why the root package.json edits are no-ops

This fork migrated from Node + npm to Deno on 2026-05-06 (commit 05924441a) as part of the v8.1 Bifrost Tier-1 router refactor (ADR-031). The root package.json / package-lock.json no longer drives the runtime dependency graph — deno.json does. Any root-level npm edits from upstream therefore cannot land here.

Paths the fixes actually apply to

  • electron/package-lock.json — undici bump applied (+3/-3). Electron still ships its own Node-side runtime.
  • scripts/check/check-pr-test-policy.mjs — small check addition from ab8096071 (+1). Pure JS, runtime-agnostic.
  • tests/unit/combo-omnimodel-tag-stripping.test.ts — deleted (-58). Paired with the upstream ReDoS commit; the regex it covered was removed when comboAgentMiddleware.ts was retired.

Audit-trail value

Commit 1 is recorded explicitly as a no-op rather than skipped silently: it proves the ReDoS vector was reviewed and confirmed absent (vulnerable regex no longer in tree). Commit 2 surfaces a real electron/ exposure. Both are scoped to this fork's actual attack surface, not blindly mirrored.

Governance refs

  • ADR-031 — Configra absorb / v8.1 Bifrost Tier-1 router refactor (root cause: why the ReDoS path is gone)
  • ADR-042 — monthly security-audit cadence (this PR is the L5-122 instance)

Ready for review.

@KooshaPari

Copy link
Copy Markdown
Owner Author

Ready to merge — upstream security sync (L5-122)

Status: MERGEABLE / UNSTABLE (pre-existing-main CI state — same fail set as every other open branch on origin/main).

Diff stat: +4 / -61 across 3 files (heavily audit-trail — most of the work is in the two cherry-pick commit messages themselves).

Branch: chore/l5-122-upstream-security-2026-06-21 (off origin/main e4d751ed1).

Critical checks

  • ✅ OpenSSF Scorecard — pass
  • ✅ CodeQL Analysis — pass
  • ✅ Socket Security — pass
  • ✅ PR Test Policy — pass
  • ⚠️ Other checks not in the readiness gate (Build / Lint / Gitleaks) — pre-existing fail, not introduced.

Cherry-picks landed

  • 7509a32e9 — fix(security): polynomial ReDoS in comboAgentMiddleware regex → no-op (file deleted in v8.1 refactor on 2026-05-06, commit 05924441a); audit commit recorded.
  • ab8096071 — fix(deps): bump undici 7.27.x → 7.28.0 in electron/package-lock.json + small check addition in scripts/check/check-pr-test-policy.mjs.
  • tests/unit/combo-omnimodel-tag-stripping.test.ts — dropped (imports from the deleted middleware; would not compile in this fork).

Why this matters

  • Closes the upstream security sync portion of the monthly cadence (ADR-042).
  • Audit trail in commit messages references both upstream SHAs and the KP deletion rationale, so the next just security-sync run can confirm both upstream SHAs were addressed.

Refs

Notes

  • CODEOWNERS review request intentionally skipped — same self-only-owner constraint as the other 5 PRs.
  • cherry-pick -x used on both commits for upstream-SHA traceability.
  • No force-push.

Ready for squash-merge into main.

@KooshaPari

Copy link
Copy Markdown
Owner Author

Review-ready summary

This PR cherry-picks 2 CVE-class security fixes from upstream diegosouzapw/OmniRoute. Ready for merge.

What to verify

  1. Upstream 7509a32 (ReDoS in comboAgentMiddleware) — KP deleted this file on 2026-05-06 as part of v8.1 Bifrost refactor, so the fix is a no-op. Commit body records the audit-trail resolution.
  2. Upstream ab80960 (undici 7.28.0 + dompurify 3.4.11) — electron/package-lock.json undici bump applies; scripts/check/check-pr-test-policy.mjs small addition applies. Root package.json/package-lock.json edits are no-op (KP migrated to Deno).

Merge checklist

  • Audit-trail commits for no-op resolutions
  • No behavioral changes beyond the 2 applicable files
  • Cherry-pick heuristic documented (see PR body)
  • 3 files, +4/−61, minimal surface

Ready for review / merge.

@KooshaPari

Copy link
Copy Markdown
Owner Author

Review-ready summary

This PR cherry-picks 2 CVE-class security fixes from upstream diegosouzapw/OmniRoute. Ready for merge.

What to verify

  1. Upstream 7509a32 (ReDoS in comboAgentMiddleware) - KP deleted this file on 2026-05-06, so the fix is a no-op. Commit body records the audit-trail resolution.
  2. Upstream ab80960 (undici 7.28.0 + dompurify 3.4.11) - electron/package-lock.json undici bump applies; scripts/check/check-pr-test-policy.mjs small addition applies.

Ready for review / merge.

…-05-06)

Upstream commit 7509a32 fixes a polynomial ReDoS in the regex used
by open-sse/services/comboAgentMiddleware.ts. In KooshaPari/OmniRoute,
that file was deleted on 2026-05-06 (commit 0592444) as part of the
v8.1 Bifrost Tier-1 router refactor (ADR-031) which superseded the
combo agent middleware path entirely.

The vulnerable regex no longer exists in this fork, so the upstream
fix is a no-op. The associated regression test (tests/unit/combo-omnimodel-tag-stripping.test.ts)
is also dropped because it imports from the deleted middleware and
would not compile in this fork.

This commit records the resolution for the security-audit trail
(ADR-042 monthly cadence).

Refs:
  - upstream:    7509a32 (diegosouzapw/OmniRoute, 2026-06)
  - KP deletion: 0592444 (KooshaPari/OmniRoute, 2026-05-06)
  - ADR-031:     docs/adr/0031-bifrost-tier1-router.md
  - ADR-042:     docs/adr/0042-security-audit-cadence.md
  - worklog:     worklogs/2026-06-21-L5-122-upstream-security-sync.md
@KooshaPari
KooshaPari force-pushed the chore/l5-122-upstream-security-2026-06-21 branch from 692d43e to 1c285de Compare July 2, 2026 07:35
@KooshaPari
KooshaPari merged commit b6dc43d into main Jul 2, 2026
13 of 23 checks passed
@KooshaPari
KooshaPari deleted the chore/l5-122-upstream-security-2026-06-21 branch July 2, 2026 07:36
@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown

L17 Latency Budget Report

--- Latency Budget Summary ---
  Total endpoints checked: 0
  Passed: 0
  Warnings: 0
  Failures: 0

Checked against: budgets/rest-endpoints.yaml.

@sonarqubecloud

sonarqubecloud Bot commented Jul 2, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant