Skip to content

fix(security): patch Cuabot dependencies - #2718

Closed
0xjohnnydev wants to merge 3 commits into
mainfrom
agent/security-cuabot-tar-20260731
Closed

fix(security): patch Cuabot dependencies#2718
0xjohnnydev wants to merge 3 commits into
mainfrom
agent/security-cuabot-tar-20260731

Conversation

@0xjohnnydev

@0xjohnnydev 0xjohnnydev commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

What users see

Cuabot's lockfile can still install several vulnerable JavaScript packages. These alerts share one Cuabot override and lockfile, so they belong in one review.

What changed

Definition of Done

  • Cuabot's tar alerts resolve to 7.5.21.
  • Cuabot's brace-expansion alerts resolve to 5.0.8, which is newer than the reported fixed version 2.1.4.
  • Cuabot's fast-uri, hono, and ip-address alerts resolve to their reported fixed versions.
  • The shared package manifest and lockfile agree.
  • A maintainer reviews the Node 20 runtime floor for brace-expansion 5.0.8 and advances this draft; automation will not mark it ready or merge it.
  • GitHub closes the alerts after the reviewed fix reaches the default branch.

Validation

  • pnpm@10.11.0 install --lockfile-only --ignore-scripts
  • git diff --check
  • Confirmed the lockfile resolves tar 7.5.21, brace-expansion 5.0.8, fast-uri 3.1.5, hono 4.12.34, and ip-address 10.3.1.

Impact

This changes only Cuabot's dependency overrides and lockfile. Human review should focus on the Node 20 requirement and the existing direct Dependabot overlap.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Publishable packages changed

This comment is status-only. Editing it or adding task-list checkboxes cannot authorize a release.
Only owner-applied release:<service> labels can do that.

  • ⏸️ npm/cuabot — no owner-authorized release label

Ask the release owner to apply release:<service> labels to auto-release on merge (+ optional bump:minor or bump:major, default is patch).
Or add no-release to skip.

@0xjohnnydev
0xjohnnydev force-pushed the agent/security-cuabot-tar-20260731 branch from b35b069 to d332f3c Compare August 4, 2026 17:57
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

📦 Publishable packages changed

This comment is status-only. Editing it or adding task-list checkboxes cannot authorize a release.
Only owner-applied release:<service> labels can do that.

  • ⏸️ npm/cuabot — no owner-authorized release label

Ask the release owner to apply release:<service> labels to auto-release on merge (+ optional bump:minor or bump:major, default is patch).
Or add no-release to skip.

@0xjohnnydev 0xjohnnydev changed the title fix(security): patch Cuabot tar dependency fix(security): patch Cuabot dependencies Aug 4, 2026
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

📦 Publishable packages changed

This comment is status-only. Editing it or adding task-list checkboxes cannot authorize a release.
Only owner-applied release:<service> labels can do that.

  • ⏸️ npm/cuabot — no owner-authorized release label

Ask the release owner to apply release:<service> labels to auto-release on merge (+ optional bump:minor or bump:major, default is patch).
Or add no-release to skip.

@0xjohnnydev

Copy link
Copy Markdown
Contributor Author

This dependency graph is now included in draft #2719. That draft keeps each graph independently validated while giving reviewers one dependency-only change instead of several overlapping drafts. Nothing was merged or marked ready, and this branch is preserved.

@0xjohnnydev 0xjohnnydev closed this Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant