Security: disposition evaOS Teams canary dependency alerts - #25
Security: disposition evaOS Teams canary dependency alerts#25100yenadmin wants to merge 13 commits into
Conversation
(cherry picked from commit a3984c1)
(cherry picked from commit be38edd)
(cherry picked from commit d2f92ac)
(cherry picked from commit 38092a5)
(cherry picked from commit 147a037)
(cherry picked from commit 62e8baa)
(cherry picked from commit 120ab9c)
(cherry picked from commit 0a2ba21)
(cherry picked from commit f23538c)
(cherry picked from commit 5ded656)
(cherry picked from commit 758e869)
Co-authored-by: benclink <111811630+benclink@users.noreply.github.com> Signed-off-by: Eva <eva@100yen.org> (cherry picked from commit 1fde7c4)
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
This pre-reset staging PR is closed as superseded by merged upstream-first reset PR #37 and the current thin-adapter tracker #1/#36. No code is being deleted. The branch and review history remain available. Retained behavior was replayed narrowly in #37; dropped managed brokers, blanket guards, duplicate UI, and control-signed routine collaboration must not be revived from this PR. |
Closes #9 when merged.
Stacked on #24 (
feature/8-evaos-teams-branding) because merge authority isoutside this implementation program. Retarget to
mainafter the prerequisitestack merges.
What changed
git cherry-pick -x, preserving one commit per reviewed changev0.4.23ancestry and intentionally does not importcurrent upstream
mainlinkify-it 5.0.2,markdown-it 14.2.0, and@babel/core 7.29.6across the pnpm workspace
cmovselection to patched0.5.4payload tests through the production
tiptap-markdowndependency chaincurrent GitHub alert in
docs/security/evaos-teams-0.4.23-es.1-dependency-dispositions.mdAlert result
linkify-italerts: fixed nowmarkdown-itandcmov: fixed now@babel/core: fixed nowglib: not applicable to the arm64 macOS client or Linux relayopentelemetry_sdkandrpassword: dev-only relay pathsopentelemetry_sdkandrpassword: acceptedtradeoffs after feature-specific source review showed the vulnerable
baggage-extraction and terminal-interruption behaviors are not exercised by
the supported signed GUI path
No supported-path high vulnerability or realistic gate-relevant moderate
vulnerable behavior remains.
Local proof on
484889567373c518641d6240100652524ad697c6membership revocation, pubsub disconnect, DB migration, Hermes discovery,
and remote-agent UI: passed
pnpm audit --prod --json: zero vulnerabilities across 446 production andoptional dependencies
pnpm audit --json: zero vulnerabilities across all 641 dependenciesmesh-llmcargo-denyadvisory/license scans completed; both license checks passed
cargo test -p buzz-relay collaboration_policy --lib: passed withcmov 0.5.4contracts, dependency lock contract, and
git diff --check: passedProof boundary
This is an Electric-only release-integration and source-security staging PR.
It does not claim merge, signing, notarization, artifact publication,
deployment, relay/dashboard/VM state, runtime canary, or customer proof.