Repository navigation
fix(ci): clear stale audit-gate entries and bump fixed advisories - #1960
Conversation
Repo-wide required security check has failed since 2026-08-05 regardless of what a PR changes. Root cause: undici was override-pinned to exactly 7.28.0, itself inside the current advisory range (7.0.0-7.28.0, fixed at 7.29.0); ip-address had no ceiling clearing its vulnerable range (<=10.3.0). Both predate this PR — confirmed on clean main. Bumped undici to ^7.29.0 and ip-address to >=10.3.1 in root overrides. packages/frontend also had its own direct undici@7.28.0 devDependency pin, independent of the root override (same shape as the piscina fix in 10b68e6: a bare override alone doesn't reliably re-resolve a hoisted version in this workspace, a direct pin does) — bumped it too so it doesn't fight the override and break npm ci's lockfile consistency check. The react-router advisory (previously accepted with an exit condition tied to a v8 migration, #1878) cleared on its own during the lockfile regen — react-router-dom now resolves to 7.18.2, past the vulnerable range, via ordinary semver resolution. Removed the now-stale ACCEPTED entries per the gate's own hygiene check, and closed #1878 as moot. Verified: npm ci (no re-resolution, exact lockfile install) succeeds clean, node scripts/audit-gate.mjs passes with zero findings, full test suite green across all 4 workspaces (shared 1404, bot 3212, backend 1352, frontend 1038 — 8006 tests total), tsc --noEmit clean.
📝 WalkthroughWalkthroughThe pull request updates dependency constraints for ChangesSecurity and bundle updates
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Failed to generate code suggestions for PR |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Incidental fallout from the lockfile regen in the audit-gate fix — axios picked up a routine minor bump (1.18.1 -> 1.19.0) within its existing semver range, adding 133B gzipped to the vendor-state chunk (zustand + react-query + axios). Not a regression to fix by re-pinning; that reintroduces the exact override/pin fragility this PR is cleaning up. Small headroom bump.
There was a problem hiding this comment.
All reported issues were addressed
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Auto-approved: Security fix bumping vulnerable dependencies (undici, ip-address) and removing stale audit-gate accepted entries after resolved versions clear advisories; audit gate passes with zero findings and full test suite green.
Re-trigger cubic
An unbounded >=3.1.5 floor let npm resolve fast-uri to 4.1.2 on lockfile regen, even though its only consumer (ajv) declares ^3.0.1 -- npm overrides ignore that range. Caps to ^3.1.5 so the advisory fix stays within the major version ajv supports. Addresses cubic's review finding on this PR.
|
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Requires human review: Lockfile diff is omitted, so I cannot verify that resolved versions actually clear the advisories or that the 10k-line lockfile change is confined to the intended bumps. Removing the accepted advisories requires human confirmation that the new resolutions are safe.
Re-trigger cubic
🤖 I have created a release *beep* *boop* --- <details><summary>2.39.2</summary> ## [2.39.2](v2.39.1...v2.39.2) (2026-08-10) ### Bug Fixes * **bot:** guard voice/session mutations with stop/suppress flags ([#1998](#1998)) ([23eaba2](23eaba2)) * **ci:** clear stale audit-gate entries and bump fixed advisories ([#1942](#1942)) ([adf710b](adf710b)) * **ci:** clear stale audit-gate entries and bump fixed advisories ([#1960](#1960)) ([2c17c99](2c17c99)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
Closes #2010. **Unblocks the release PR #2039**, whose only failing check is `Size Limit Check`. ## The number | Bundle | Limit | Actual | Headroom | |---|---|---|---| | Main | 75 kB | 70.33 | 6.2% | | Vendor UI | 70 kB | 66.40 | 5.1% | | Vendor React | 60 kB | 55.63 | 7.3% | | **Vendor Radix** | **48 kB** | **48.94** | **-2.0% (over by 942 B)** | | Vendor Forms | 28 kB | 26.35 | 5.9% | | Vendor State | 26.5 kB | 26.14 | 1.4% | ## I tried to reduce it first Four Radix packages have **zero imports** in `packages/frontend/src` — `tabs`, `toast`, `tooltip`, `slot` — yet all four are listed in `vite.config.ts` `manualChunks` for `vendor-radix`. That looked like a free win. Removing them drops the chunk to **48.61 kB**, comfortably under the old limit. **It is a regression.** Measuring the whole output rather than the one chunk: | | Total JS, gzipped, all 63 chunks | |---|---| | current config | **496,709 B** | | 4 packages removed | **498,088 B** | | | **+1,379 B worse** | `@radix-ui/react-slot` is a shared transitive dependency of the other Radix packages. Grouping it into `vendor-radix` **deduplicates** it; splitting it out copies it into every chunk that needs it. So the "fix" shrinks the measured chunk by growing the real bundle — exactly the thing a size budget exists to prevent. `vite.config.ts` is therefore unchanged. ## So: raise it With no reduction available that does not make the bundle worse, 48.94 kB is the honest size of what the app actually uses. 50 kB gives ~2.1% headroom, in line with the other five budgets (1.4%–6.6%), and matches the `26 → 26.5 kB` precedent set for Vendor State in #1960. Verified locally: `npx size-limit` exits **0**, all six budgets pass. ## Follow-up, not done here `@radix-ui/react-tabs`, `react-toast` and `react-tooltip` have no imports anywhere in `src` and are almost certainly not in the bundle at all (unreachable from the entry, so tree-shaken before chunking). Removing them from `packages/frontend/package.json` is genuine dependency hygiene, but it touches the lockfile and will not change any bundle number — worth its own PR rather than riding along with a release unblock. Say the word and I will file it. <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Raises the Vendor Radix size-limit from 48 KB to 50 KB to match the actual gzipped chunk size (48.94 kB) and keep CI green. Old behavior: CI failed at 48 KB; new behavior: budget is 50 KB; no runtime or bundling behavior changes. - No change to `vite.config.ts` or chunking. Removing `@radix-ui/react-tabs`, `@radix-ui/react-toast`, `@radix-ui/react-tooltip`, and `@radix-ui/react-slot` from the `vendor-radix` chunk shrank that chunk but increased total gzipped JS (~1.4 kB) due to duplicated `@radix-ui/react-slot`. - New headroom is ~2.1%, consistent with other budgets; `npx size-limit` passes locally. - Single file touched: `packages/frontend/.size-limit.json` (sets "Vendor Radix (gzip)" limit to 50 KB). <sup>Written for commit 32ad800. Summary will update on new commits.</sup> <a href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2068?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. -->



Summary
Fixes #1959 — the required Security check has failed on every PR since 2026-08-05 (5+ days), regardless of what's changed.
Root cause:
undiciwas override-pinned to exactly7.28.0, itself inside the current advisory range (7.0.0-7.28.0, fixed at7.29.0);ip-addresshad no ceiling clearing its vulnerable range (<=10.3.0). Both predate this PR, confirmed viagit stash+node scripts/audit-gate.mjsagainst cleanmain.Fix:
undicito^7.29.0andip-addressto>=10.3.1in rootoverrides.packages/frontendhad its own directundici@7.28.0devDependency, independent of the root override — bumped it too. (Root cause of a detour: a bareoverridesentry alone doesn't reliably force-resolve a hoisted version when a workspace has a conflicting direct pin in this repo — same shape as the documented piscina fix in 10b68e6. The direct pin wins; bump it in place rather than fighting the override.)react-routeradvisory (previously accepted with an exit condition tied to a v8 migration, security(frontend): migrate to react-router v8 to clear GHSA-qwww-vcr4-c8h2 #1878) cleared on its own during the lockfile regen —react-router-domnow resolves to7.18.2, past the vulnerable range, via ordinary semver resolution. Removed the now-staleACCEPTEDentries per the gate's own hygiene enforcement, closed security(frontend): migrate to react-router v8 to clear GHSA-qwww-vcr4-c8h2 #1878 as moot.A detour worth flagging: mid-fix I hit what looked like nondeterministic package resolution (a
busboymodule-not-found, then an unrelatedjsdomone) even across repeated clean reinstalls. Root cause was local npm cache corruption (npm cache verifyreported garbage-collecting 94 stale entries) — unrelated to this fix, resolved withnpm cache clean --force+ reinstall. Mentioning in case it recurs for someone else.Test plan
npm ci(exact lockfile install, no re-resolution — same install mode as this repo's own CI) succeeds cleannode scripts/audit-gate.mjs— zero findingsnpx tsc --noEmitclean across all 4 workspacesnpm run lint— no new findings (pre-existing warnings in.agents/browser-automation/*.jsuntouched)Follow-up
Once this merges, #1950 and #1958 (both currently blocked on this same check) should pass once rebased.
Summary by cubic
Unblocks the failing Security check by bumping vulnerable packages and removing stale audit-gate overrides. Fixes #1959.
Dependencies
undicito^7.29.0; bump frontend devDependency to^7.29.0.ip-addressto>=10.3.1.fast-urioverride^3.1.5(cap to 3.x to matchajv).axiosminor update increased bundle size slightly.Bug Fixes
ACCEPTEDentries forreact-router/react-router-domnow that resolved versions are past advisories.undici@7.28.0and missingip-addressceiling keeping installs in vulnerable ranges.npm ci; CI is unblocked.Written for commit 153c909. Summary will update on new commits.