Skip to content

fix(deps): clear the devalue advisories and catch up on dependencies - #45

Merged
cgaravitoq merged 6 commits into
mainfrom
cgaravitoq/restyle-d1
Oct 2, 2026
Merged

cgaravitoq merged 6 commits into
mainfrom
cgaravitoq/restyle-d1

Conversation

@cgaravitoq

Copy link
Copy Markdown
Owner

Clears the devalue advisories that make bun run audit:production fail on main and lands the dependency bumps Dependabot cannot. Verified on 30169d918d14c8f3d26c373381492fab271b1063.

Why main is red

bun audit --production exits 1 on devalue@5.9.2, pulled transitively by astro@7.3.4 > devalue:

high:     GHSA-j22f-vq7h-c4qm  stringify/uneval serialize shared memory
high:     GHSA-mcm9-63f2-9j32  repeated primitive strings cause quadratic expansion in uneval
high:     GHSA-x5rw-q4pp-hg5g  stringifyAsync can cause an unhandled rejection
moderate: GHSA-hx4r-w6wj-j8fg  residual sparse-array CPU amplification in uneval
moderate: GHSA-4q55-j62x-fr9h  malformed null-prototype object keys bypass __proto__ rejection
low:      GHSA-wf3x-273g-mvxv  sparse arrays emitted by uneval cause eager allocation

Nothing changed in this repo; new advisories were published against <=5.9.2, so every CI rerun went red.

Bumps

Package From To Scope
devalue 5.9.2 5.9.4 transitive via astro
@commitlint/config-conventional ^21.2.2 ^21.2.3 root
oxlint 1.83.0 1.86.0 root, exact
wrangler ^4.135.0 ^4.147.0 apps/worker
cloudflare/wrangler-action ebbaa15 (v4.0.0) 953926a (v4.1.3) .github/workflows/ci.yml

astro@7.3.4 declares devalue: ^5.8.1 and 5.9.4 is inside that range, so bun update devalue resolves it and the audit goes clean without a root overrides entry. The lockfile refresh also corrects a stale field it already carried: packages/collector.version was pinned at 0.4.0 while package.json said 0.5.0.

bun pm ls --all | grep devalue is now devalue@5.9.4.

Dependabot could not land any of these: it cannot rewrite the bun.lock v3 lockfile (dependabot-core#16071), so its pull requests stay stale. They are untouched by this PR.

oxlint 1.86.0 runs clean under the ultracite anti-slop preset, so no rule was disabled.

wrangler-action review: v4.0.0 ebbaa15 -> v4.1.3 953926a

Two changes beyond release plumbing.

  1. v4.1.0 minor (PR #450, 9500699 plus fixups, 429a99d, d3cfe74) adds Workers Previews. The branch is only entered when command starts with preview and takes no argument, so it is unreachable for the command: deploy this workflow passes. It adds the preview-url, preview-deployment-url, preview-name, preview-id and preview-deployment-id outputs, plus a GitHub Deployment and job summary for previews.
  2. v4.1.0 patch (PR #418, 789ac84) logs wrangler's stderr before rethrowing when a command fails, instead of surfacing only the generic exec failure. This does touch the deploy step, but only when it fails, and only its diagnostics.

Everything else is release plumbing: Changesets and immutable-release ordering (7e340a9, 876f5b5, ecefb49, d7fd981, 5fa9855, the Version Packages commits), floating-tag verification, a Prettier catch-up, v3-to-v4 doc references, action.yml descriptions and the compiled dist/index.mjs.

Reviewed and approved before pinning.

The golden in scripts/ci-deploy-jobs.test.ts moves with the pin. The negative fixture that flips the last hex character of the SHA still proves an unreviewed commit fails, and the appended-second-deploy-step fixture now carries the reviewed SHA so the extra step is the only reason it can be rejected. Mutation-probed: reverting the golden constant to another SHA turns the suite red.

Gates

All run on 30169d918d14c8f3d26c373381492fab271b1063, in CI's order.

Gate Result
bun install --frozen-lockfile Checked 544 installs across 702 packages (no changes)
printf '%s' '<PR title>' | bunx commitlint exit 0
bun run format Checked 96 files in 32ms. No fixes applied.
bun run lint:slop clean, exit 0
bun run check-types worker 30 files, 0 errors, 0 warnings, 0 hints; collector Exited with code 0
bun run test worker 16 files, 212 tests passed; collector 12 files, 140 tests passed
bun run test:dependency-policy 68 pass, 0 fail, 316 expect() calls
bun run test:package 1 file, 1 test passed
bun run audit:production No vulnerabilities found (checked 408 packages) - exit 0
bun run build Complete! - exit 0

Commits

30169d9 ci: pin wrangler-action to v4.1.3
552cff5 chore(deps): update wrangler to 4.147.0 in the worker
4669340 docs: name oxlint 1.86 in the agent context
05f5f00 chore(deps): update oxlint to 1.86.0
c130314 chore(deps): update @commitlint/config-conventional to 21.2.3
873a9e5 fix(deps): move devalue to 5.9.4

No merge, no auto-merge.

`bun audit --production` exits 1 on devalue 5.9.2, which astro 7.3.4 pulls
transitively through its `^5.8.1` range, for GHSA-j22f-vq7h-c4qm,
GHSA-mcm9-63f2-9j32, GHSA-x5rw-q4pp-hg5g (high) and three lower advisories.
5.9.4 is inside that range, so a lockfile refresh clears it without an
override.

The refresh also corrects the stale `packages/collector` version the lockfile
still carried at 0.4.0.
Dependabot cannot land the bump itself: it cannot rewrite the bun.lock v3
lockfile (dependabot-core#16071), so its own pull request stays red.
oxlint runs clean at 1.86.0 under the ultracite anti-slop preset, so no rule
needed disabling. Same reason as the commitlint bump: Dependabot cannot write
the bun.lock v3 lockfile (dependabot-core#16071).
The context file still described the linter at the version the bump replaced.
`wrangler deploy --dry-run` and the wrangler types check pass at 4.147.0, and
the miniflare undici override still resolves. Same reason as the other bumps:
Dependabot cannot write the bun.lock v3 lockfile (dependabot-core#16071).
The reviewed golden moves with it: the negative fixture that mutates the SHA
still proves an unreviewed commit fails, and the appended-second-deploy-step
fixture now carries the reviewed SHA so the extra step is the only reason it
can be rejected.

v4.0.0..v4.1.3 holds two changes beyond release plumbing:

- v4.1.0 (minor, PR #450, 9500699 plus fixups, 429a99d, d3cfe74) adds Workers
  Previews. That branch is only entered when the command starts with preview
  and takes no argument, so it is unreachable for the "deploy" command this
  workflow passes; it adds the preview-url, preview-deployment-url,
  preview-name, preview-id and preview-deployment-id outputs.
- v4.1.0 (patch, PR #418, 789ac84) logs wrangler's stderr before rethrowing
  when a command fails, instead of surfacing only the generic exec failure.
  That only changes failure diagnostics, and GitHub masks secrets in logs.

Everything else is release plumbing: Changesets and immutable-release ordering,
floating-tag verification, a Prettier catch-up, v3-to-v4 doc references,
action.yml descriptions and the compiled dist/index.mjs.
@cgaravitoq
cgaravitoq merged commit 954b007 into main Oct 2, 2026
4 checks passed
@cgaravitoq
cgaravitoq deleted the cgaravitoq/restyle-d1 branch October 2, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant