Skip to content

fix: bump anyio, js-yaml, multer, sharp, smol-toml, hono, morgan, react-router and vitest for security advisories - #757

Open
devin-ai-integration[bot] wants to merge 6 commits into
mainfrom
devin/1788786531-security-deps
Open

devin-ai-integration[bot] wants to merge 6 commits into
mainfrom
devin/1788786531-security-deps

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Summary

Dependency-only security remediation from the automated Wiz + Dependabot reconciliation run (2026-09-21), continuing the 2026-09-07/09-14 runs on this branch.

  • Critical: anyio 4.9.0 → 4.14.2 in all three Poetry locks (e2e/python, sdk/@launchdarkly/observability-python, sdk/highlight-py).
  • npm Highs via root resolutions: js-yaml 3.15.2 / 4.3.2, multer 2.4.0, sharp 0.35.4, smol-toml 1.8.0 (plus the earlier pacote, browserslist, fast-uri, @xmldom/xmldom, qs, fflate, @humanfs/node bumps).
  • npm Moderates: hono 4.13.7, morgan 1.12.1, react-router/react-router-dom 6.30.6, vitest + @vitest/mocker 4.1.11.
  • e2e/react-native has its own npm lockfile, so js-yaml is pinned there via overrides and the lock regenerated.
  • Minor/patch bumps only — manifests and lockfiles, no source edits; Go modules already on grpc 1.83.1 from the previous run.
Implementation details

Dependency vulnerability fixes (automated)

Generated by the dependency-vuln-remediation run on 2026-09-21.
Change type: Minor/patch version bumps only — manifest and lockfile changes, no source edits.

Findings addressed (this run)

Package Ecosystem Current → Target Severity Age Source(s) Advisory
anyio pip 4.9.0 → 4.14.2 Critical 2d (Critical: no hold) Dependabot, Wiz GHSA anyio < 4.14.2
js-yaml (3.x) npm 3.15.1 → 3.15.2 High 12d Dependabot, Wiz js-yaml >= 3.0.0, < 3.15.2
js-yaml (4.x) npm 4.3.1 → 4.3.2 High 12d Dependabot, Wiz js-yaml >= 4.0.0, < 4.3.2
multer npm 2.2.0 → 2.4.0 High 12d Dependabot, Wiz multer < 2.3.0
sharp npm 0.35.3 → 0.35.4 High 12d Dependabot sharp < 0.35.4
smol-toml npm 1.6.1 → 1.8.0 High 11d Dependabot smol-toml <= 1.7.0
hono npm 4.13.2 → 4.13.7 Moderate 12d Dependabot hono < 4.13.5
morgan npm 1.11.0 → 1.12.1 Moderate 12d Dependabot morgan < 1.12.0
react-router / react-router-dom npm 6.30.4 → 6.30.6 Moderate 13d Dependabot react-router-dom < 6.30.6
vitest / @vitest/mocker npm 4.1.8 → 4.1.11 Moderate 12d Dependabot @vitest/mocker >= 2.1.0, < 4.1.11

Carried from the previous runs on this branch: google.golang.org/grpc 1.83.1 across six Go modules, pacote 21.5.1, qs 6.16.0, fast-uri 3.1.7, @xmldom/xmldom 0.8.15, browserslist 4.28.9, fflate 0.4.9/0.6.11/0.8.3, @humanfs/node 0.16.8, Django 5.2.17 / 6.1.1.

Already satisfied on this branch (stale alerts, no change needed): baseline-browser-mapping (2.11.21 ≥ 2.11.0), vite in sdk/highlight-run (^6.4.3), uuid 11.1.1.

Not addressed here

Package Ecosystem Current → Required Reason
adm-zip npm 0.6.0 → 0.6.1 High first seen 2026-09-19 — inside the 7-day hold (eligible 2026-09-26). The older <= 0.6.0 Moderate has no fix.
devalue npm 5.8.1 → 5.9.2 Moderate first seen 2026-09-17 — inside the 7-day hold (eligible 2026-09-24).
OpenTelemetry.* (incl. Resources.Host) nuget 1.11.x → 1.15.3 / 1.16.0-beta.2 nuget.org blocked in this environment; Dependabot PRs #513/#509/#496 already cover e2e/dotnet4/cs/packages.config.
github.com/labstack/echo/v4 go 4.11.4 → 4.15.3 Covered by open Dependabot PR #748 — not duplicated here.
golang.org/x/crypto go 0.52.0 → 0.56.0 Wiz-only High. 0.x leading-component change counts as major per policy, and 0.56.0 declares go 1.26.0, which would rewrite every module's go directive and the CI toolchain.
pacote (20.x copy) npm 20.0.0 → 21.5.1 Major bump for the remaining 20.x descriptor (the 21.x copy is already patched).
decode-uri-component npm 0.2.2 → 0.5.0 0.x major per policy.
toml npm 3.0.0 → 4.1.2 Major.
vite (5.x copy) npm 5.4.21 → 6.4.3 Major for the 5.x descriptor.
nanoid (4.x copy) npm 4.0.2 → 5.x Major (ESM-only).
svelte npm 4.2.19 → 5.55.7 Major.
react-router (7.x advisory) npm 6.30.6 → 7.18.0 Major.
@nestjs/core npm 10.x → 11.1.18 Major.
@opentelemetry/core (1.x copies) npm 1.30.x → 2.8.0 Major (2.x descriptors already pinned to 2.10.0).
fast-xml-parser npm 4.5.5 → 5.7.0 Major.
markdown-it (12.x copy) npm 12.3.2 → 14.2.0 Major (14.x copy already patched).
file-type npm 20.4.1 → 21.3.2 Major.
ts-deepmerge npm 2.0.7 → 8.0.0 Major.
uuid (legacy copies) npm 3.4.0/7.0.3/8.3.2/9.0.1 → 11.1.1 Major.
pytest pip 8.x → 9.0.3 Major.
mail rubygems 2.9.0 → 2.9.1 rubygems.org is not on the network allowlist, so the two Gemfile.locks cannot be regenerated here.
@angular/*, image-size, extract-zip, apollo-server-core npm No fixed version published.
netty, jackson-databind, bcprov/bcutil/bcpkix-jdk18on, wire-runtime maven (Wiz) Gradle-toolchain transitives with no manifest entry in this repo; Maven Central is also blocked.

Verification

  • Install: ✅ PUPPETEER_SKIP_DOWNLOAD=1 YARN_NPM_REGISTRY_SERVER=https://registry.npmjs.org node .yarn/releases/yarn-4.13.0.cjs install (with --mode=skip-build; Playwright/Chrome CDN downloads for rrvideo/puppeteer are blocked in this environment — cosmetic, resolution and lockfile writing succeed)
  • Dedupe check: ✅ yarn dedupe --check
  • Build: ✅ yarn build:sdk 20/20 packages
  • Lint: ✅ yarn lint 49/49 packages
  • Tests: not run — the known angular.io-example#build failure in this environment is caused by fonts.googleapis.com being blocked, unrelated to these bumps
  • Poetry: ✅ lock-only updates, lock-version unchanged (2.1); only anyio and typing-extensions moved. e2e/python poetry check --lock reports a pre-existing missing README.md.
  • Go: no changes this run (grpc already at 1.83.1 on this branch)

Note: the Require additional human oversight on bot PRs check is action_required by design on bot-authored PRs in this repo and needs a human approval; the long-running iOS build (legacy arch, RN 0.78) job routinely exceeds 90 minutes.

Link to Devin session: https://app.devin.ai/sessions/e51e4f8c5e3a47a494306ec7418b4ae2
Open in Devin Desktop: https://app.devin.ai/desktop/session/e51e4f8c5e3a47a494306ec7418b4ae2?variant=devin

…visories

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration
devin-ai-integration Bot requested a review from a team as a code owner September 7, 2026 13:14
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration devin-ai-integration Bot added automated-security-deps Automated dependency security remediation devin-pr exempt labels Sep 7, 2026
@devin-ai-integration
devin-ai-integration Bot requested a review from a team September 7, 2026 13:14
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

☂️ Python Coverage

current status: ✅

Overall Coverage

Lines Covered Coverage Threshold Status
628 551 88% 0% 🟢

New Files

No new covered files...

Modified Files

No covered modified files...

updated for commit: 87693fc by action🐍

…manfs/node for security advisories

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: bump pacote and django for security advisories fix: bump grpc, pacote, qs, browserslist, fflate and django for security advisories Sep 14, 2026
@devin-ai-integration
devin-ai-integration Bot requested a review from a team September 14, 2026 13:26
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: bump grpc, pacote, qs, browserslist, fflate and django for security advisories fix: bump anyio, js-yaml, multer, sharp, smol-toml, hono, morgan, react-router and vitest for security advisories Sep 21, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated-security-deps Automated dependency security remediation devin-pr exempt

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant