fix(build): remediate CVEs, enforce equality pinning, repair Dependabot config#391
Merged
Merged
Conversation
…ot config - fix lodash prototype pollution CVE via overrides in root, frontend, docusaurus - add qs override to resolve CVE in docusaurus express dependency chain - pin all 6 pyproject.toml files to == equality versions - pin all 3 package.json files to exact resolved versions - regenerate all lockfiles (3 uv.lock, 3 package-lock.json) - repair dependabot.yml from 7 broken entries to 14 valid ecosystem entries - fix scanner dot-source guard to use return instead of exit 1 for Pester compat - add pip fixture files for pinned/unpinned pyproject.toml and requirements.txt 🔒 - Generated by Copilot
Contributor
Dependency ReviewThe following issues were found:
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #391 +/- ##
==========================================
+ Coverage 50.27% 50.48% +0.20%
==========================================
Files 267 267
Lines 18099 18188 +89
Branches 1903 1855 -48
==========================================
+ Hits 9100 9182 +82
- Misses 8709 8716 +7
Partials 290 290
*This pull request uses carry forward flags. Click here to find out more.
🚀 New features to boost your workflow:
|
added 4 commits
April 5, 2026 09:55
- add 3 lodash@4.17.21 GHSAs to dependency-review allow list (no upstream fix) - pin evaluation Docker requirements to exact == versions - skip self-referencing package entries in pyproject.toml scanner 🔒 - Generated by Copilot
- upgrade mlflow from 3.1.1 to 3.9.0 in Docker eval requirements - fixes 3 critical and 2 high severity mlflow vulnerabilities - 3.9.0 is latest compatible with azureml-mlflow 1.62.0.post2 🔒 - Generated by Copilot
- bump requests from 2.31.0 to 2.32.3 in all 4 Pester test fixtures - resolves GHSA-9wx4-h78v-vm56, GHSA-9hjg-9r4m-mvj7, GHSA-gc5v-m9x4-r6x2 🔒 - Generated by Copilot
- bump requests from 2.32.3 to 2.33.1 in all four pip fixture files - resolves GHSA-9hjg-9r4m-mvj7 (.netrc credentials leak) - resolves GHSA-gc5v-m9x4-r6x2 (insecure temp file reuse) 🔒 - Generated by Copilot
agreaves-ms
approved these changes
Apr 6, 2026
…support - replace grouped comments with per-GHSA inline comments including CVE IDs - add [dependency-groups] section detection to Test-DependencyPinning.ps1 - add pip fixture files and Pester tests for dependency-groups pinning 🔒 - Generated by Copilot
7ecf5e3 to
2d1698b
Compare
- keep equality-pinned versions over Dependabot range operators from #394 🔀 - Generated by Copilot
…on for pinning scan - add GHSA-7qhf-v65m-g5f3 (mlflow unauthenticated job endpoints) to dependency-review allow-list - add exclude-paths input to dependency-pinning-scan.yml wired to ExcludePaths parameter - exclude test fixture paths in pr-validation.yml and main.yml callers 🔒 - Generated by Copilot
…ependabot-config # Conflicts: # data-management/viewer/frontend/package-lock.json # data-management/viewer/frontend/package.json
WilliamBerryiii
pushed a commit
that referenced
this pull request
Apr 8, 2026
🤖 I have created a release *beep* *boop* --- ## [0.6.0](v0.5.0...v0.6.0) (2026-04-08) ### ✨ Features * **build:** add terraform-docs generation pipeline ([#378](#378)) ([78e90d0](78e90d0)) * **infrastructure:** enable optional AML diagnostic logs ([#400](#400)) ([58dd8db](58dd8db)) * **scripts:** consolidate scripts library paths and enhance dataviewer ([#383](#383)) ([176d9c9](176d9c9)) ### 🐛 Bug Fixes * **build:** remediate CVEs, enforce equality pinning, repair Dependabot config ([#391](#391)) ([0c29148](0c29148)) * **infrastructure:** add Storage File Data Privileged Contributor role for ML identity ([#380](#380)) ([378f7ed](378f7ed)) * **infrastructure:** replace hardcoded NAT Gateway availability zones with variable ([#356](#356)) ([a1397bd](a1397bd)) * **infrastructure:** resolve TFLint violations and enable hard-fail ([#376](#376)) ([dfb55cd](dfb55cd)) * **scripts:** add dot-source guard to Invoke-MsDateFreshnessCheck.ps1 ([#397](#397)) ([f6f22c3](f6f22c3)) * **training:** validate AzureML and OSMO RL submissions end to end ([#372](#372)) ([49904d3](49904d3)) ### 📚 Documentation * **infrastructure:** add terraform-docs tooling and improve developer experience ([#365](#365)) ([a0fb03a](a0fb03a)) * **reference:** centralize workflow template docs and convert workflow READMEs to pointer index ([#379](#379)) ([68097e4](68097e4)) ### 🔧 Miscellaneous * **deps-dev:** bump the npm_and_yarn group across 1 directory with 2 updates ([#374](#374)) ([d848c8b](d848c8b)) * **deps-dev:** bump vite from 6.4.1 to 6.4.2 in /data-management/viewer/frontend in the npm_and_yarn group across 1 directory ([#395](#395)) ([6ec7f19](6ec7f19)) * **deps:** bump the github-actions group across 1 directory with 7 updates ([#370](#370)) ([4d1b951](4d1b951)) * **deps:** bump the uv group across 2 directories with 1 update ([#373](#373)) ([ba66ed9](ba66ed9)) ### 🔒 Security * **deps-dev:** bump brace-expansion from 1.1.12 to 1.1.13 in /docs/docusaurus in the npm_and_yarn group across 1 directory ([#389](#389)) ([27129d9](27129d9)) * **deps-dev:** bump the npm_and_yarn group across 2 directories with 2 updates ([#363](#363)) ([aeae624](aeae624)) * **deps-dev:** bump the python-dependencies group with 5 updates ([#403](#403)) ([bb85560](bb85560)) * **deps:** bump cryptography from 46.0.5 to 46.0.6 in /training/rl ([#367](#367)) ([a82dd68](a82dd68)) * **deps:** bump the inference-dependencies group in /evaluation with 2 updates ([#401](#401)) ([c88d253](c88d253)) * **deps:** bump the pip group across 4 directories with 2 updates ([#411](#411)) ([1230fe0](1230fe0)) * **deps:** bump the training-dependencies group across 1 directory with 67 updates ([#375](#375)) ([8e05172](8e05172)) * **deps:** bump the uv group across 2 directories with 1 update ([#382](#382)) ([b6c7aea](b6c7aea)) * **deps:** update marshmallow requirement from <4.3.0,>=3.5 to >=3.5,<4.4.0 in /evaluation in the inference-dependencies group ([#393](#393)) ([599c7eb](599c7eb)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: physical-ai-toolchain-release[bot] <267194360+physical-ai-toolchain-release[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Resolved 5 open CVEs, enforced strict equality (
==) pinning across all 6 Python workspaces and exact semver pinning across all 3 npm workspaces, and repaired the Dependabot configuration to reflect current repository structure. Hardened the dependency pinning CI scanner to correctly validate pip ecosystems and fixed its dot-source guard that prevented standalone execution.Closes #390
Type of Change
Component(s) Affected
infrastructure/terraform/prerequisites/- Azure subscription setupinfrastructure/terraform/- Terraform infrastructureinfrastructure/setup/- OSMO control plane / Helmworkflows/- Training and evaluation workflowstraining/- Training pipelines and scriptsdocs/- DocumentationChanges
CVE Remediation
Addressed 5 CVEs across Python and npm ecosystems:
==2.4.xand azure-identity to==1.23.0+across affected pyproject.toml filesEquality Pinning Enforcement
Converted all dependency version specifiers to strict equality:
>=,~=, and range operators with==across 28+ dependencies in data-management/viewer/backend/pyproject.toml alone, plus evaluation/, training/il/lerobot/, training/rl/, root, and data-management/viewer/^and~range operators in data-management/viewer/frontend/, docs/docusaurus/, and rootDependabot Configuration Repair
Rewrote .github/dependabot.yml from 12 entries (several invalid) to 14 valid entries:
pipecosystem references withuvfor all Python workspacesCI Scanner Hardening
Updated shared/ci/security/Test-DependencyPinning.ps1 with 4 fixes:
Write-Error+exit 1toreturn, which prevented the script from being sourced by PesterGet-PipDependencyViolationsfunction for validating pip equality pinning in pyproject.toml and requirements.txt filesTest-SHAPinningto apply ecosystem-specific validation patternsAdded 4 new test fixtures in shared/ci/tests/Fixtures/Pip/ and updated the dot-source guard expectation in the Pester test file.
Workflow Update
Expanded the default
dependency_typesin .github/workflows/dependency-pinning-scan.yml to includegithub-actions,npm,pip,shell-downloads.Testing Performed
planreviewed (no unexpected changes)applytested in dev environmentsmoke_test_azure.py)Additional testing performed:
npm audit(root): 0 vulnerabilitiesnpm audit(frontend): 0 vulnerabilitiesnpm audit(docusaurus): 25 remaining — all lodash transitive dependencies with no upstream fix availableuv lock --checkacross all 3 Python workspaces: locked and consistentDocumentation Impact
Bug Fix Checklist
Checklist
Additional Notes