Skip to content

chore(security): defer js-yaml remediation until September 10 - #11254

Closed
rsliter wants to merge 1 commit into
mainfrom
codex/release-js-yaml-exception
Closed

chore(security): defer js-yaml remediation until September 10#11254
rsliter wants to merge 1 commit into
mainfrom
codex/release-js-yaml-exception

Conversation

@rsliter

@rsliter rsliter commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Outcome

Temporarily accept GHSA-2883-xcg3-v3hh for js-yaml 4.3.1 in the CLI production graph through September 10, 2026 UTC. Keep the dependency upgrade deferred from v0.0.121.

Reason

The refreshed release image audit blocks on this advisory. The maintainer accepted the risk temporarily while the upgrade remains tracked separately.

Related issues

Refs #11252.

Changes

  • Scope the existing audit exception mechanism to one advisory, package, installed version, severity, and production graph.
  • Record the owner, expiry, rationale, and manifest-control precautions.
  • Narrow the brace-expansion regression to prohibit its old exception without prohibiting unrelated exceptions.

Verification

  • npm run validate:pr: passed against canonical main 7c54bc0 after building CLI and plugin prerequisites.
  • Focused reviewed-npm-audit integration suite: 42 tests passed.
  • Live production audit through runReviewedNpmAudit: accepted-exceptions for only GHSA-2883-xcg3-v3hh; no unaccepted blocking advisories.
  • Expiry boundary: accepted at 2026-09-10T23:59:59Z and rejected at 2026-09-11T00:00:00Z.
  • No dependency versions, runtime code, audit thresholds, secrets, API keys, or credentials changed.

Review notes

Maintainer risk acceptance: #11252 (comment). The authenticated author rsliter had MAINTAIN permission when this record was created. This exception does not waive image publication, E2E decisions, or release confirmation. Independent PR review remains pending.


Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com

Summary by CodeRabbit

  • Security

    • Updated security audit tracking with a temporary, documented exception and compensating controls for a known high-severity advisory.
    • Included an expiration date, ownership, rationale, and remediation tracking to support follow-up.
  • Tests

    • Updated automated validation to confirm that resolved audit exceptions are no longer listed.

Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 9, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: fd135fb9-c58b-49ad-97e5-27b1bab979b3

📥 Commits

Reviewing files that changed from the base of the PR and between 7c54bc0 and 994a822.

📒 Files selected for processing (2)
  • ci/npm-audit-exceptions.json
  • test/automation/releases/reviewed-npm-audit.test.ts

Included review availability: Your plan provides up to 12 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The checked-in npm audit policy adds a temporary exception for js-yaml 4.3.1. The remediation test now verifies removal of the brace-expansion exception without requiring an empty policy.

Changes

npm audit policy

Layer / File(s) Summary
Audit exception and remediation validation
ci/npm-audit-exceptions.json, test/automation/releases/reviewed-npm-audit.test.ts
The policy documents the temporary js-yaml exception, its controls, owner, expiration, rationale, and tracking issue. The test checks that the brace-expansion exception is absent.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 994a8

This change records a bounded temporary js-yaml audit exception and preserves validation that the prior brace-expansion exception is removed. No merge-blocking implementation risk remains.

Suggested reviewers: cv, laitingsheng

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the security change: deferring js-yaml remediation until September 10. This matches the temporary audit exception and deferred dependency upgrade described in the pull req…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/release-js-yaml-exception

Comment @coderabbitai help to get the list of available commands.

@rsliter

rsliter commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@github-code-quality

github-code-quality Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 994a822 in the codex/release-js-yam... branch remains at 96%, unchanged from commit 7c54bc0 in the main branch.

TypeScript / code-coverage/cli

The overall line coverage in commit 994a822 in the codex/release-js-yam... branch remains at 83%, unchanged from commit 7c54bc0 in the main branch.

Show a line coverage summary of the most impacted files.
File main 7c54bc0 codex/release-js-yam... 994a822 +/-
src/lib/onboard...ntime-marker.ts 71% 65% -6%
src/lib/onboard...eate-journal.ts 87% 82% -5%
src/lib/actions...oy-execution.ts 94% 91% -3%
src/lib/actions...dbox/destroy.ts 91% 89% -2%
src/lib/onboard...ce-lifecycle.ts 82% 80% -2%
src/lib/onboard...u-patch-mode.ts 90% 88% -2%
src/lib/inference/health.ts 90% 89% -1%
src/lib/onboard...box-prebuild.ts 91% 94% +3%
src/lib/onboard...wn-authority.ts 91% 98% +7%
src/lib/onboard...dns-fallback.ts 65% 85% +20%

Updated September 09, 2026 02:12 UTC

@wscurran wscurran added area: ci CI workflows, checks, release automation, or GitHub Actions area: security Security controls, permissions, secrets, or hardening chore Build, CI, dependency, or tooling maintenance labels Sep 9, 2026
@rsliter rsliter closed this Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci CI workflows, checks, release automation, or GitHub Actions area: security Security controls, permissions, secrets, or hardening chore Build, CI, dependency, or tooling maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants