Skip to content
This repository was archived by the owner on Aug 17, 2026. It is now read-only.

Security: disposition evaOS Teams canary dependency alerts - #25

Closed
100yenadmin wants to merge 13 commits into
feature/8-evaos-teams-brandingfrom
security/9-dependency-alert-dispositions
Closed

Security: disposition evaOS Teams canary dependency alerts#25
100yenadmin wants to merge 13 commits into
feature/8-evaos-teams-brandingfrom
security/9-dependency-alert-dispositions

Conversation

@100yenadmin

Copy link
Copy Markdown
Member

Closes #9 when merged.

Stacked on #24 (feature/8-evaos-teams-branding) because merge authority is
outside this implementation program. Retarget to main after the prerequisite
stack merges.

What changed

Alert result

  • both high linkify-it alerts: fixed now
  • reachable moderate markdown-it and cmov: fixed now
  • low build-only @babel/core: fixed now
  • Linux-only glib: not applicable to the arm64 macOS client or Linux relay
  • root Mesh-origin opentelemetry_sdk and rpassword: dev-only relay paths
  • signed-client Mesh-origin opentelemetry_sdk and rpassword: accepted
    tradeoffs after feature-specific source review showed the vulnerable
    baggage-extraction and terminal-interruption behaviors are not exercised by
    the supported signed GUI path

No supported-path high vulnerability or realistic gate-relevant moderate
vulnerable behavior remains.

Local proof on 484889567373c518641d6240100652524ad697c6

  • focused integration tests for ACP continuity, relay collaboration policy,
    membership revocation, pubsub disconnect, DB migration, Hermes discovery,
    and remote-agent UI: passed
  • parser security payload tests plus Markdown regression suite: 64 passed
  • pnpm audit --prod --json: zero vulnerabilities across 446 production and
    optional dependencies
  • pnpm audit --json: zero vulnerabilities across all 641 dependencies
  • target-specific Linux relay and arm64 macOS-with-mesh-llm cargo-deny
    advisory/license scans completed; both license checks passed
  • cargo test -p buzz-relay collaboration_policy --lib: passed with
    cmov 0.5.4
  • desktop typecheck, changed-file Biome checks, release/canary source
    contracts, dependency lock contract, and git diff --check: passed

Proof boundary

This is an Electric-only release-integration and source-security staging PR.
It does not claim merge, signing, notarization, artifact publication,
deployment, relay/dashboard/VM state, runtime canary, or customer proof.

Eva and others added 13 commits July 24, 2026 19:45
(cherry picked from commit a3984c1)
Co-authored-by: benclink <111811630+benclink@users.noreply.github.com>
Signed-off-by: Eva <eva@100yen.org>
(cherry picked from commit 1fde7c4)
@coderabbitai

coderabbitai Bot commented Jul 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: c25d7f6f-baa9-46f2-8cdf-f94ca5034ebc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch security/9-dependency-alert-dispositions

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​fs2@​0.4.310010090100100

View full report

@100yenadmin

Copy link
Copy Markdown
Member Author

This pre-reset staging PR is closed as superseded by merged upstream-first reset PR #37 and the current thin-adapter tracker #1/#36.

No code is being deleted. The branch and review history remain available. Retained behavior was replayed narrowly in #37; dropped managed brokers, blanket guards, duplicate UI, and control-signed routine collaboration must not be revived from this PR.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant