Repository navigation
deps: clear 14 pnpm advisories and land the weekly dep groups - #490
Conversation
Folds the three open Dependabot PRs into one change and closes #486. pnpm 11.1.3 -> 11.21.0 across all six files that declare it, eight lines in total (the issue listed four sites; development.md's verify snippet, README.md and AGENTS.md were missed). 11.1.3 sat below the first_patched_version of fourteen advisories in the 11.x line, floor 11.8.0. 11.21.0 over the newer 11.22.0 because the repo's own minimumReleaseAge: 10080 encodes a 7-day cooldown and 11.22.0 is three days old; both clear every advisory. lockfileVersion stays at 9.0. Dependabot's `directory: /` for github-actions reaches .github/workflows/ and does not descend into .github/actions/*/action.yml, so the setup-env composite action -- which owns every cache in CI -- went untracked, so its pins went stale against upstream and diverged from publish-npm.yml, a workflow Dependabot DOES track and which does not call setup-env (actions/setup-node v7.0.0 there vs v6.4.0 here; pnpm/action-setup v6.0.9 vs v6.0.8). actions/cache was uniformly v5.0.5 everywhere, simply a major behind upstream. The config moves to `directories: [/, /.github/actions/setup-env]` and the action is brought up to the versions #480 proposed for the workflows. Groups landed: actions-deps (#480) verbatim, go-deps (#481) verbatim, and four of the five npm-deps bumps (#482). typescript 6 -> 7 is held: tsup 8.5.1 vendors rollup-plugin-dts 6.1.1, which reaches for TS 5-era compiler internals and throws on `dts: true` inside clients/ts's prepare script -- i.e. inside pnpm install, taking every Node job down at once. rollup-plugin-dts >= 6.5.0 declares TS 7 support, so the unblock is a tsup release that vendors it; dependabot.yml ignores the typescript major until then. Also makes housekeeping.yml's documented "labeling failures are non-fatal" contract true -- the labeler step never carried continue-on-error, which is why a transient GitHub 500 reddened #481. Closes #486. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YEwX2gCkH2BSzEfX6bUvDV
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (16)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (3)
🧰 Additional context used📓 Path-based instructions (4)**/*📄 CodeRabbit inference engine (AGENTS.md)
Files:
.github/workflows/*.yml📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.md📄 CodeRabbit inference engine (AGENTS.md)
Files:
docs/src/content/docs/**/*.md📄 CodeRabbit inference engine (AGENTS.md)
Files:
🧠 Learnings (5)📚 Learning: 2026-08-11T11:20:19.556ZApplied to files:
📚 Learning: 2026-06-10T15:01:09.027ZApplied to files:
📚 Learning: 2026-08-18T19:25:33.501ZApplied to files:
📚 Learning: 2026-06-10T15:01:59.729ZApplied to files:
📚 Learning: 2026-08-11T12:41:05.990ZApplied to files:
🪛 LanguageTooldocs/src/content/docs/development.md[uncategorized] ~559-~559: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~559-~559: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~564-~564: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~564-~564: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~566-~566: The official name of this software platform is spelled with a capital “H”. (GITHUB) CHANGELOG.md[uncategorized] ~32-~32: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~32-~32: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~32-~32: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~32-~32: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~32-~32: The official name of this software platform is spelled with a capital “H”. (GITHUB) [typographical] ~32-~32: In American English, use a period after an abbreviation. (MISSING_PERIOD_AFTER_ABBREVIATION) [typographical] ~32-~32: In American English, use a period after an abbreviation. (MISSING_PERIOD_AFTER_ABBREVIATION) [style] ~32-~32: Since ownership is already implied, this phrasing may be redundant. (PRP_OWN) [uncategorized] ~32-~32: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~60-~60: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~60-~60: The official name of this software platform is spelled with a capital “H”. (GITHUB) 🪛 OSV Scanner (2.4.0)go.mod[LOW] 196-196: golang.org/x/crypto 0.55.0: The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues (GO-2026-5932) [LOW] 198-198: golang.org/x/image 0.41.0: Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image (GO-2026-4961) [LOW] 198-198: golang.org/x/image 0.41.0: Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image (GO-2026-5061) [LOW] 198-198: golang.org/x/image 0.41.0: Lack of limit on tile sizes in x/image/tiff in golang.org/x/image (GO-2026-5062) [LOW] 198-198: golang.org/x/image 0.41.0: Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image (GO-2026-5066) [LOW] 198-198: golang.org/x/image 0.41.0: Excessive memory allocation during VP8L decoding in golang.org/x/image (GO-2026-6222) [LOW] 199-199: golang.org/x/mod 0.38.0: Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog (GO-2026-6179) [LOW] 199-199: golang.org/x/mod 0.38.0: Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb (GO-2026-6180) 🪛 zizmor (1.29.0).github/workflows/publish-dev.yml[error] 77-77: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default (cache-poisoning) 🔇 Additional comments (17)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe PR updates pnpm to 11.21.0, refreshes Go and npm dependencies, updates Dependabot coverage, and upgrades pinned GitHub Actions across CI, publishing, and release workflows. ChangesDependency and workflow maintenance
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This dependency update is merge-ready after normal checks and review; no actionable merge-blocking risk remains. Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
📚 Docs preview is live → https://332cab50-wavehouse-docs.wave-rf.workers.dev
|
#490 landed a better fix for the Dependabot composite-action gap than mine, so main's version wins on every shared file: - .github/dependabot.yml: taken wholesale. My two `updates:` entries are two independent Dependabot jobs and a group is scoped to its own job, so they would emit two actions-deps PRs every Monday -- the noise the group comment exists to prevent. main's `directories: [/, ...]` is one job, one PR. main's comment also carries the accuracy fix: actions/cache was uniformly v5.0.5 at every site, a major behind upstream rather than behind a caller. - .github/actions/setup-env/action.yml: taken wholesale. My bumps were a strict subset and stale (cache still v5.0.5, pnpm 11.1.3). - development.md Dependabot section: taken wholesale. My "four update configs" auto-merged silently and is wrong under the directories form -- it is three. main's also documents the typescript major hold (#487). - My CHANGELOG entry describing the two-entry mechanism is dropped; #490's entry on main is the accurate record of the same fix. Kept mine, reconciled by hand: - README's `--signer-workflow` fix -- #490 deliberately avoided it. - persist-credentials: false across the four release workflows. - clients/ts/README.md and sdk/index.mdx: #470 changed streaming from EventSource to fetch. Took its wording, kept my `latest`-is-a-dev- snapshot caveat and the corrected anchor -- main still links #releasing-the-sdk, a section this branch renamed. - CHANGELOG resolved with the same script as the #479 merge: main's entry text into this branch's structure. Verified 331 main entries + 29 branch entries, none lost, none invented, no duplicates. All action pins now match main exactly; no stale pnpm strings remain. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015bVwHtNakQgmnBhMcfW8pe
Both stale against what actually ships, found by the pre-push gate. - "Aligned setup-env's action pins" recorded pnpm/action-setup v6.0.8 -> v6.0.9. The merge took main's setup-env wholesale, so the file is now byte-identical to origin/main and carries v6.0.10 -- my entry recorded a state no commit in this release ever produced, and #490's entry immediately below it already covers the same file's same pins with the numbers that shipped. Same reasoning the merge gave for dropping its sibling. - "The SDK release checkout persisted git credentials" was subsumed by the sweep entry two lines above, which even narrates its origin. It still ended "matching ci.yml" -- verbatim the implication f29dd54 was written to remove, and contradicted by the sweep entry now naming housekeeping.yml as also already compliant. A reader also counted two credential incidents where there was one. Its two unique details (the npm-lifecycle threat model, the CodeRabbit attribution) are folded up. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015bVwHtNakQgmnBhMcfW8pe
## Summary Replaces Dependabot's #571 (`astro` 7.1.6 → 7.2.8), whose generated lockfile cannot be installed under this repo's supply-chain policy. Bumps to **astro 7.2.10** with a lockfile resolved by pnpm itself, so it satisfies `minimumReleaseAge`. Supersedes #571 — once `main` carries astro 7.2.10, Dependabot closes that PR itself (its 7.2.8 target is already satisfied). No manual close needed. ## Why #571 could not be rebased `pnpm install --frozen-lockfile` — the install every Node-touching CI job runs — rejected #571's lockfile outright: ``` ✗ Lockfile failed supply-chain policy check (1126 entries in 2.1s) [ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION] 21 lockfile entries failed verification: @clack/core@1.5.0 was published at 2026-09-07T20:12:19.000Z, within the minimumReleaseAge cutoff rolldown@1.2.7 ... postcss@8.5.28 ... tinyexec@1.3.1 ... undici@8.10.2 ... ``` That one `pnpm-install` target — reached via `make verify` (Lint), `make build-docs` → check-docs (Docs build), `make test-ts` (Unit tests), `make test-e2e` → build-ts (E2E tests), and invoked directly by the workflow (Coverage) — failed all five at once, printing no reason for any of them (#578). Integration tests, the one suite that never installs, stayed green on the same lockfile. `@dependabot rebase` / `recreate` cannot fix it: Dependabot resolves with a resolver that does not read `minimumReleaseAge` from `pnpm-workspace.yaml`, so it regenerates the same violating tree. This is #441. Note `astro@7.2.8` itself was **not** the problem — published 2026-08-26, 14 days old and well past the 7-day cooldown. All 21 violations were transitive: `rolldown@1.2.7` plus its 15 platform bindings (09-02), `postcss@8.5.28` / `tinyexec@1.3.1` (09-03), `undici@8.10.2` (09-04), `@clack/core` + `@clack/prompts` (09-07). A Dependabot `cooldown:` setting would not have prevented it, since that gates only the direct dependency. ## What this does instead Bump the manifest and let pnpm resolve. Its resolver *does* honor `minimumReleaseAge`, so it backs off to age-eligible versions on its own: ``` docs/package.json: "astro": "^7.1.1" -> "^7.2.10" pnpm install ``` Resolves `astro@7.2.10` (published 2026-08-31, already past cooldown) with `rolldown@1.2.2`, `postcss@8.5.25`, `undici@8.10.1`, `vite@8.2.0`. One further manifest change rides along, surfaced by pre-push review: - **Declare `@astrojs/markdown-remark` `^7.3.0`.** astro 7.1.6 pinned it to exactly 7.2.2 (an *optional* peer even then, so an unmet one is dropped silently rather than erroring); 7.2.10 widens the range to `^7.3.0`, which the tree's 7.2.2 — a hard dep of `@astrojs/mdx` — doesn't satisfy, so pnpm dropped it from astro's peer set. That's load-bearing: `docs/astro.config.mjs` sets `markdown.remarkPlugins`/`rehypePlugins`, and astro's `coerceLegacyMarkdownPlugins()` does `await import("@astrojs/markdown-remark")` and **throws** if it can't resolve. It only worked via pnpm's hoisted fallback copy — an undeclared edge a narrower `hoist-pattern`, or a starlight/mdx bump dropping that dependency, would break. A `sharp` bump to `^0.35.4` was also part of this branch originally (astro 7.2.8 raised its own optional sharp floor, and the stale 0.35.3 pin had stopped sharing a copy with astro). That change reached `main` first via #574, so it no longer appears in this diff — and #572, the dedicated sharp PR, was superseded by #574 and is already closed. ## Synced with main `origin/main` advanced while this was in review (#570 go-deps, #573 actions-deps, #574 npm-deps all merged). `origin/main` is merged in here — never rebased, per §Branch Maintenance. `pnpm-lock.yaml` conflicted. Resolved by taking main's post-#574 lockfile (`git checkout --theirs pnpm-lock.yaml`) and re-running a targeted `pnpm install` against the merged manifests, rather than hand-merging conflicting YAML. That is deliberate: a lockfile's peer-suffixed keys encode a whole resolution graph, and hand-merging them yields a tree that installs but matches neither side's actual resolution. Re-resolving lets pnpm rebuild the graph under policy. The result keeps both sides intact — #574's catalog `@types/node@26.4.1` and `tsx@4.23.13` are preserved, alongside this branch's `astro@7.2.10` and `@astrojs/markdown-remark@7.3.0`. Net diff vs `main` is now `docs/package.json` (2 lines) plus 281+/136− in `pnpm-lock.yaml`, with zero downgrades. One package drops out entirely — `@rollup/pluginutils@5.4.0`, correct because astro 7.2.x drops its `rollup` optional peer. ## Verification - `pnpm install --frozen-lockfile` — clean, no policy violation (this is what #571 failed), and leaves the lockfile byte-identical. Every entry in the resulting tree is past the 7-day cooldown; the newest is `@types/node@26.4.1` at 7d 17h. - `make build-docs` — 22 pages, all internal links valid, mermaid patched, 68 diagram PNGs rendered. - `make ci` — green on the merged tree. ## Related - #571 — the Dependabot PR this replaces. - #441 — the underlying Dependabot/pnpm cooldown mismatch. [Commented there](#441 (comment)) with the updated failure mode: the repo pinned pnpm 11.1.3 until #490 moved it to 11.21.0, which *does* enforce the policy under `--frozen-lockfile` — so this now fails loudly in CI rather than merging silently as #441 originally described. - #578 — filed from this PR's review: `pnpm-install`'s `--reporter=silent` swallowed the diagnostic entirely, which is why five red jobs stated no reason. - #572 — superseded by #574 (identical sharp bump); closed. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01CbyVditEujZabgu3R11VAm Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Folds the three open Dependabot PRs into one reviewable change, fixes the
pnpm advisories from #486, and repairs the Dependabot config gap that let the
setup-envcomposite action drift out of sync in the first place.Closes #486. Supersedes #480, #481, #482.
Why one PR instead of merging the three
They are not independent:
publish-npm.ymland.github/actions/setup-env/action.yml; ci: bump the actions-deps group with 7 updates #480 bumpsaction SHAs in the same two files. Sequencing them costs a rebase either way.
.github/workflows/— see below — so ci: bump the actions-deps group with 7 updates #480 moves the workflows toactions/cachev6.1.0 whilesetup-env, which owns every cache in CI,stays on v5.0.5. Only a hand-written commit can close that.
blocked upstream, permanently for now — see below.
go.mod/go.sum, all patch/minor).One CI run, one review, no interleaving.
1. pnpm 11.1.3 → 11.21.0 (#486)
Eight declaration lines across six files, not the four sites the issue listed:
package.jsonpackageManager.github/workflows/publish-npm.yml.github/actions/setup-env/action.ymldocs/src/content/docs/development.mdcorepack prepareline, prerequisites table, and the "verify your setup" snippetREADME.mdpnpm 11+floor in Local DevelopmentAGENTS.mdpnpm (≥ 11.1)floor in the toolchain listThe issue's advisory table is off by four. #486 lists ten; the actual
count affecting 11.1.3 is fourteen — 8 high, 6 medium. Its table
includes GHSA-v23m-ccfg-pq9h,
whose range is
>= 11.3.0, < 11.5.3and so does not cover 11.1.3, andomits five that do: GHSA-hwx4-2j3j-g496 (high), GHSA-cjhr-43r9-cfmw,
GHSA-p4xf-rf54-rj3x, GHSA-q6j5-fjx5-2mc3 and GHSA-54hh-g5mx-jqcp. "Eight
high" happens to survive only because the wrongly-included high and the
omitted high cancel out. All five were published 2026-06-26, so this was a
counting slip when the issue was written, not new information.
The remediation is unchanged — the highest
first_patched_versionis still11.8.0, and 11.21.0 clears all fourteen. Worth correcting the table on
#486 so the issue and this PR agree.
Why 11.21.0 and not 11.22.0 (latest). 11.22.0 shipped 2026-08-15, three
days ago.
pnpm-workspace.yamlsetsminimumReleaseAge: 10080— adeliberate 7-day cooldown against compromised releases. That knob governs
dependency resolution, not the
packageManagerpin, but the reasoningapplies harder here: pnpm runs postinstall scripts under
allowBuilds:inevery CI job, and in
publish-npm.yml, which holdsid-token: writefornpm trusted publishing. 11.21.0 is 9 days old and equally clear of every
advisory. Say the word and I'll move it to 11.22.0.
lockfileVersionis unchanged at9.0. The issue flagged a possiblebump; 11.21.0 reads and writes the existing format, and
pnpm install --frozen-lockfilepassed against the pre-existing lockfilebefore it was regenerated.
2. Dependabot never scanned the composite action
directory: /forpackage-ecosystem: github-actionsreaches.github/workflows/and stops. It does not descend into.github/actions/*/action.yml.setup-envhas been invisible to Dependabotsince it was created. Its only caller is
ci.yml, which pins none of theseactions itself — they all live inside
setup-env— so the staleness showsup against upstream, and against
publish-npm.yml, a workflow Dependabotdoes track and which does not call
setup-env:setup-envonmainmainactions/setup-nodepublish-npm.ymlpnpm/action-setuppublish-npm.ymlactions/cache(×6)The
setup-noderow is the tell: that major landed inpublish-npm.ymlinan earlier Dependabot PR and
setup-env, being invisible, never followed.(#480 would then have introduced a cache skew, bumping
publish-dev.ymlto v6.1.0 while
setup-envstayed on v5.0.5.)This PR aligns all three to the versions the workflows already use — no
version is introduced here that Dependabot has not already proposed and CI
has not already run — and switches the config to
directories: [/, /.github/actions/setup-env]so the group covers it from now on.
3. actions-deps (#480), verbatim
upload-code-coverage1.4.1→1.4.2 ·labeler6.2.0→7.0.0 ·cache+cache/restore5.0.5→6.1.0 ·docker/login-action4.4.0→4.6.0 ·
attest-build-provenance4.1.1→4.2.2 ·pnpm/action-setup6.0.9→6.0.10.
Both majors are ESM migrations with no config surface change, and #480's own
CI run was fully green on them.
4. go-deps (#481), verbatim
nats-server2.14.4→2.14.5 ·nats.go1.52.0→1.53.1 ·testify1.11.1→1.12.0 ·
testcontainers-go0.43.0→0.44.0, plus indirects. Allpatch/minor. #481's only red check was
PR housekeepingfailing on atransient GitHub API 500 inside
actions/labeler— not a code problem, andnow not a red check either (see below).
5. npm-deps (#482), minus TypeScript 7
Taken:
tsx4.23.5→4.23.12 ·@astrojs/starlight0.41.6→0.41.7 ·katex0.18.1→0.18.4 ·
@types/nodecatalog ^26.1.2→^26.2.0.Held:
typescript^6.0.3 → ^7.0.2. This is why every Node job on #482went red. Reproduced locally:
tsup8.5.1 — the current release — vendorsrollup-plugin-dts6.1.1into its own bundle, so it is not overridable from our side. 6.1.1 reaches
for TS 5-era compiler internals and dies the moment
dts: trueruns. Thatis
clients/ts'spreparescript, so the crash happens insidepnpm installand takes down Lint, Unit, E2E, Coverage and Docs build atonce.
rollup-plugin-dts6.5.0 is the first release declaringtypescript: "^4.5 || ^5 || ^6 || ^7"(6.4.0 stops at^6.0); we need atsuprelease that vendors ≥ 6.5.0.No rebase of #482 can fix this, and left alone Dependabot re-proposes it
every Monday — so
.github/dependabot.ymlnow ignoresversion-update:semver-majorfortypescript, with the reason and theremoval condition written next to it.
The regenerated lockfile changes exactly four resolved packages and adds
or drops none:
6. One-line fix: labeling really is non-fatal now
housekeeping.yml's header has always claimed:It wasn't true — the
Apply file-path labelsstep has never carriedcontinue-on-error, in any revision. So when the labeler hit a transient500 on #481:
the job aborted before the title mirror it exists to protect, and the check
went red. Adding
continue-on-error: truemakes the documented contract real.In scope because it is the direct cause of one of the three red PRs this
change set is meant to clear.
PR housekeepingis not a required check — theCIaggregator is — so this was noise rather than a merge blocker, but it'snoise that costs a re-run every time GitHub hiccups.
What this PR's CI does not prove
Worth stating rather than implying green means everything:
actions/labeler6.2.0 → 7.0.0 is not exercised here.housekeeping.ymlruns on
pull_request_target, so GitHub loads that workflow file frommain, not from the PR head. ThePR housekeepingcheck on this PR — andon ci: bump the actions-deps group with 7 updates #480 — runs labeler v6.2.0 regardless. v7.0.0 first executes on the
PR after this merges. Mitigating: v7.0.0 is an ESM-migration-only release,
.github/labeler.ymlalready uses the v5+changed-filesschema, and thelabeling step is deliberately
continue-on-errorso a bad labeler cannotblock a PR.
publish-npm.yml,publish-dev.ymlandrelease.ymlare tag/releasetriggered, so their action bumps (and the new pnpm pin in the publish
jobs) first run on the next release, not here.
actions/cache5.0.5 → 6.1.0 is covered —ci.ymlruns onpull_request, so every cache insetup-envexercises v6.1.0 on this PR.Verification
make cigreen locally with Docker up, running on pnpm 11.21.0 — allstatic checks, unit, integration, E2E and every coverage gate.
pnpm install --frozen-lockfileclean against the regenerated lockfile;tsupDTS build succeeds..github/any more (was:
cache,setup-node,pnpm/action-setup).actionlint,shellcheck,biomeandmarkdownlintall pass over theworkflow, config and CHANGELOG edits.
CHANGELOG.mdupdated under[Unreleased]— a Security entry for the pnpmbump and a Changed entry for the groups + Dependabot config.
gh api "/advisories?ecosystem=npm&affects=pnpm" --paginatewith range matching against 11.1.3, not copied from the issue.Note that #480/#481/#482 are superseded rather than closed by me — Dependabot
should retire them on its next run once these versions are on
main.