Skip to content

fix(security): remediate August dependency alerts - #66

Merged
aivrar merged 2 commits into
mainfrom
agent/remediate-august-security-alerts
Aug 3, 2026
Merged

aivrar merged 2 commits into
mainfrom
agent/remediate-august-security-alerts

Conversation

@aivrar

@aivrar aivrar commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Attribution

The Feishu commit preserves Eugeniusz Gilewski's authorship. The compression commit credits Yingliang Zhang and Teknium as co-authors, and follows the security report by YLChen-007.

Validation

  • pytest tests/gateway/test_feishu.py tests/gateway/test_setup_feishu.py: 239 passed, 19 skipped
  • pytest tests/agent/test_compression_rotation_state.py -k TestTodoSnapshotAuthority: 6 passed
  • focused Python ruff check: passed
  • npm audit --prefix website --package-lock-only --audit-level=high: 0 vulnerabilities
  • npm --prefix website run typecheck: passed
  • npm --prefix website run build: passed for English and zh-Hans (pre-existing link warnings remain)
  • git diff --check: passed

egilewski and others added 2 commits August 2, 2026 22:42
Feishu webhook requests consumed the shared per-IP delivery bucket before
their verification token and signature were checked. An unauthenticated
caller could therefore exhaust legitimate Feishu delivery capacity, while
malformed nested JSON and unbounded anomaly keys added avoidable pre-auth
resource pressure.

Validate bounded object payloads, decrypt protocol-correct Encrypt Key
envelopes, and authenticate URL challenges or signed events before charging
the delivery quota. Bound outer and nested message JSON work, contain
malformed content before dispatch, and cap anomaly tracking without weakening
the token or raw-body signature trust boundaries.

Preserve websocket mode, plaintext signed callbacks, valid message dispatch,
and unknown-event no-op behavior. URL re-verification now deliberately
requires a Verification Token because Feishu challenge callbacks are
unsigned; the setup output and both user guides document that migration.

Validation covers 251 focused SDK-present tests and 205 SDK-denied tests,
including 14 subtests in each mode, plus current-main relay capability tests,
Ruff, compilation, documentation structure, and diff checks. The full
repository run passed 48,020 tests; its 51 failures are confined to unrelated
missing optional dependencies, installer/WeCom state, lazy dependency
resolution, and a context-compressor timeout.

The last completed CodeRabbit review found no issues; its current-main replay
failed open after the bounded rate-limit retry. Independent current-base deep
security and compatibility reviews found no worth-addressing issue.

Fixes #29154
Backport the todo-snapshot authority fix from NousResearch/hermes-agent#69860 and update brace-expansion to 1.1.17.

Co-authored-by: Yingliang Zhang <zhangyingliang@outlook.com>

Co-authored-by: Teknium <127238744+teknium1@users.noreply.github.com>
@aivrar
aivrar marked this pull request as ready for review August 3, 2026 05:51
@aivrar
aivrar merged commit 4101260 into main Aug 3, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants