Repository navigation
deps: periodic dependency and security updates - #6287
Conversation
There was a problem hiding this comment.
Arcjet Review — 🟡 Medium Risk
Decision: Needs Review
Rationale: This PR is composed entirely of dependency, override, and toolchain pin changes across many workspace package.json files, including removal of numerous root overrides and restoration of scoped minimum-version overrides. The dependency-changes escalation trigger fires. I did not find hardcoded secrets, auth changes, injection risks, or direct application-code security issues in the diff. However, because the changes alter supply-chain controls broadly and no lockfile changes are visible in the provided files changed list, human review should verify the effective dependency graph and confirm the intended security advisory remediation is actually reflected in install resolution.
Summary of Changes
Updates npm from 12.0.1 to 12.0.2 in the pinned action and root packageManager, bumps many devDependencies such as tsdown, framework/tooling packages, and turbo, removes many broad root overrides, and replaces some overrides with scoped minimum-version overrides for cookie, undici, and sharp.
Escalation Triggers
- Dependency Changes: The PR changes many package.json files, including root devDependencies, workspace devDependencies, packageManager, and npm overrides.
Review Focus Areas
- Verify that removing the previous root overrides does not reintroduce vulnerable transitive versions of packages such as svgo, sharp, postcss, nanoid, adm-zip, fast-uri, uuid, @bufbuild/protobuf, or @anthropic-ai/sdk in the effective dependency tree.
Root overrides are a supply-chain security control; removing them is safe only if direct or transitive dependency constraints now resolve to fixed versions. - Confirm that the scoped override ranges using ">=" for sharp, cookie, and undici resolve deterministically to reviewed versions in the lockfile/install output.
Minimum-version override ranges may allow newer unreviewed versions during future installs unless the lockfile and package manager behavior keep resolution deterministic. - Check whether the repository has a package-lock.json or equivalent lockfile and whether it was intentionally unchanged or excluded from the provided diff.
Dependency version changes without a corresponding lockfile update can mean installs will not use the versions shown here, or that reviewers cannot verify the actual resolved dependency graph. - Verify the npm 12.0.2 bump is compatible with the repository's install and workspace tooling in CI.
Changing the package manager version can affect lockfile format, override resolution, and install behavior.
Notes
Path filtering: 1 file excluded by ignore paths. 38 of 39 files included in review.
Review: 4583a932 | Model: openai/gpt-5.5 | Powered by Arcjet Review
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Every entry in the root overrides block already resolves to the pinned version on its own — removing the block produces a byte-identical package-lock.json. adm-zip, fast-uri, nanoid, postcss, sharp, svgo, and uuid all already satisfy their pin naturally; @nosecone/sveltekit's nested @sveltejs/kit/cookie pin and miniflare's nested undici pin are likewise already met without forcing; rolldown-plugin-dts's typescript pin is unneeded; rollup: npm:@rollup/wasm-node was vestigial, since rollup isn't in the tree at all anymore, aliased or not; and @anthropic-ai/sdk / @bufbuild/protobuf both already match what @arcjet/guard, transport, protocol, and arcjet request directly in their own manifests. That last pair is worth watching: they exist to route around optional-peer version collisions between @arcjet/guard's bundled AI framework integrations (@strands-agents/sdk wants openai ^6.x while @openai/agents wants ^7.x; @google/adk's transitive opentelemetry-exporter range collides with genkit's), both pre-existing and independent of any version bump. They're redundant only because nothing on this branch has moved those two versions yet — a future bump of either without updating (or dropping) a same-named override would silently re-pin the old version underneath it, which is exactly what happened upstream before this cleanup. Revisit deliberately when that bump happens, rather than re-adding the override reflexively. Verified: lint, format, and typecheck are clean; tests pass for every package except @arcjet/transport and its dependents, which hit a pre-existing, unrelated hang in that package's own test suite (already being fixed separately). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Safe subset of the periodic dependency update: tsdown 0.22.14 -> 0.23.0 across all 36 packages, turbo 2.10.10 -> 2.10.12, npm 12.0.1 -> 12.0.2 (and .github/actions/pin-npm/action.yml synced to match, which otherwise hardcodes the version separately and would desync CI), and framework-adjacent devDependencies: astro, bun-types, undici-types, fastify, @nestjs/common, next (arcjet-next and nosecone-next), react-router, @sveltejs/kit/svelte/vite (nosecone-sveltekit), rolldown (arcjet), and @tanstack/intent (arcjet-guard and arcjet-skills). Deliberately excludes @arcjet/guard's bundled AI framework devDependencies (@strands-agents/sdk, @openai/agents, @mastra/core, @langchain/langgraph, @tanstack/ai, ai, eve, genkit, @google/adk, @anthropic-ai/sdk, @anthropic-ai/claude-agent-sdk, @ai-sdk/provider-utils) — those carry the optional-peer collisions the removed root overrides were papering over, and need their own pass. Also excludes @bufbuild/protobuf and @connectrpc/* (bumped alongside the transport HTTP/2 test fix) and oxlint/oxfmt/oxlint-tsgolint (bumped alongside the lint config unification). Verified: build, lint, and format are clean; typecheck passes for all 55 typecheck targets; tests pass for every package except @arcjet/transport and its dependents, which hit the pre-existing, unrelated hang in that package's own test suite (fixed separately). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…523-8j87) Transitive via astro's own ^4.0.1 range, which already permitted 4.1.0 — it was just never re-resolved after the root override pinning it to 4.0.2 was removed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
GHSA-pxg6-pf52-xh8x (cookie), GHSA-8xcm-r25x-g524 / GHSA-4cwx-7wf7-3272 / GHSA-m8rv-5g2x-5cg5 / GHSA-jr45-8vmc-qm54 / GHSA-v3r7-h72x-cjcm (undici), GHSA-f88m-g3jw-g9cj / GHSA-rgj7-g3m4-5g8c (sharp) All three were among the overrides removed as redundant earlier in this branch — correctly so at the time, since nothing had bumped their consumers yet. They're live again: `@sveltejs/kit@2.70.3` hard-caps cookie at `^0.6.0` (vulnerable), `miniflare@4.20260730.0` exact-pins `undici@7.28.0` (vulnerable) and `sharp@0.35.2` (vulnerable), and `@huggingface/transformers@4.2.0` caret-pins `sharp@^0.34.5` (also vulnerable) — none of the three can clear their own advisory without forcing past a range their parent declares. Scoped rather than blanket: each override targets only the specific parent that actually needs forcing (`@huggingface/transformers` and `miniflare` for sharp, `@nosecone/sveltekit` → `@sveltejs/kit` for cookie), not every package in the tree. astro and next already resolve sharp to 0.35.4 on their own and are left alone. Floor ranges (`>=x`) rather than exact pins, so a dedup that already lands on something newer/safer elsewhere in the tree isn't flagged as a mismatch by `npm ls`. Landing this needed more than editing package.json: `npm install` alone doesn't retroactively re-resolve nested lockfile entries that predate an override change, so the three affected nested entries (miniflare's sharp and undici, @huggingface/transformers's sharp and its per-platform binaries, nosecone-sveltekit's cookie) had to be deleted from package-lock.json's `packages` map directly before `npm install` would honor the new ranges there. `npm audit`: 65 -> 57 (low 2 -> 0, high 13 -> 6). `npm ls` is clean (exit 0, no invalid/extraneous entries) for all three packages. Verified: lint and typecheck clean; sensitive-info-rampart (the @huggingface/transformers consumer) 41/41; full suite 21/21 excluding @arcjet/transport and its dependents, which hit the pre-existing, unrelated hang fixed separately. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
8ec6fe7 to
1555bc5
Compare
Update dependencies, audit "overrides", and patch resolvable security notices.
#6286 & #6285 were split out