Skip to content

chore(deps): carry dependabot's npm security bumps onto Dev_new_gui (hono 4.13.7 and transitive; supersedes #16171) - #16408

Merged
mrveiss merged 3 commits into
mainfrom
issue-16171-mcp-npm-security
Sep 13, 2026
Merged

mrveiss merged 3 commits into
mainfrom
issue-16171-mcp-npm-security

Conversation

@mrveiss

@mrveiss mrveiss commented Sep 11, 2026 •

Copy link
Copy Markdown
Owner

Refs #16171 (dependabot's original npm security bump, superseded by this PR and closed).

Supersedes #16171 (dependabot's security update, which targets main; PRs here target Dev_new_gui).

Single-issue rationale: this carries one dependabot security update onto the branch PRs actually target. Its scope is exactly that update's lockfiles.

Thinking Path

Dependabot security updates always target the default branch (main), whatever target-branch says, so #16171 couldn't ride the Dev_new_gui trains. Each package dependabot bumped was compared with Dev_new_gui's lockfile, and only those still behind were brought up.

What Changed

  • .mcp: hono 4.13.0 → 4.13.7 (GHSA-hxh3-vqpv-xpqv, GHSA-crvj-82cr-hjcx, GHSA-gqvv-2mrq-wpjv, GHSA-g6gw-c38x-mqfc). fast-uri and qs were already fixed on Dev_new_gui.
  • The MCP tools mcp-structured-thinking and mcp-autobot-tracker get hono 4.13.0 → 4.13.7, plus dependabot's transitive bumps (browserslist, electron-to-chromium, node-releases and baseline-browser-mapping).
  • autobot-frontend gets joi 18.2.3 → 18.2.8, @redocly/openapi-core 1.34.18 → 1.34.20, and the same transitive bumps.
  • libs/autobot-sdk-ts gets the same transitive bumps.
  • autobot-slm-frontend was already at target, so it's unchanged.
  • Every version, resolved URL and integrity hash comes verbatim from dependabot's commit 7dc04e3a3. Nothing was hand-computed or installed.

Verification

  • A per-package table compares Dev_new_gui, dependabot, and applied or skipped; it's in the implementation report.
  • No npm install was run locally, and CI's npm ci plus the audit gates are the real check.
  • .github/workflows/security.yml is untouched: chore(deps): bump the npm_and_yarn group across 6 directories with 7 updates #16171's allowance edit belonged to main.
  • A review is checking each bumped node against dependabot's full node, not just the three fields.

Model Used

Claude Opus 5 as coordinator; devops-engineer subagents on Sonnet.

🤖 Generated with Claude Code

…-chromium, hono, joi, node-releases, @redocly/openapi-core in autobot-frontend, mcp-structured-thinking, mcp-autobot-tracker, libs/autobot-sdk-ts (supersedes #16171)

Applies the subset of dependabot commit 7dc04e3 that
was still behind origin/Dev_new_gui, per lockfile node (version/resolved/integrity only):

- autobot-frontend: @redocly/openapi-core 1.34.18->1.34.20, baseline-browser-mapping
  2.11.20->2.11.21, browserslist 4.28.7->4.28.9, electron-to-chromium 1.5.419->1.5.426,
  joi 18.2.3->18.2.8, node-releases 2.0.54->2.0.55
- mcp-structured-thinking: baseline-browser-mapping 2.11.20->2.11.21, browserslist
  4.28.8->4.28.9, electron-to-chromium 1.5.420->1.5.426, hono 4.13.0->4.13.7,
  node-releases 2.0.54->2.0.55
- mcp-autobot-tracker: hono 4.13.0->4.13.7
- libs/autobot-sdk-ts: baseline-browser-mapping 2.11.20->2.11.21, browserslist
  4.28.7->4.28.9, electron-to-chromium 1.5.419->1.5.426, node-releases 2.0.54->2.0.55

autobot-slm-frontend already had fast-uri 3.1.7 (dependabot's target); no change.
fast-uri, qs, js-yaml, caniuse-lite, es-object-atoms, hasown, side-channel(-list),
update-browserslist-db were already at or above dependabot's target in every directory
and were skipped. package.json overrides (js-yaml, qs) were already at the bumped
constraint in every directory that has one.
@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a3e8b4c1-261a-4d32-9a3f-212ea6fe4f56


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Notice: 29 open PRs — past the runaway threshold (25)

There is no PR queue limit, and this is not a request to defer this PR. Work proceeds one issue at a time without a cap on open PRs; review capacity is the constraint.

This notice only means the count is high enough to be worth a glance for a runaway — something opening PRs in a loop, or a merge pipeline that has stalled so nothing is draining.

Currently open:

If the queue is draining normally, ignore this. Otherwise:

  1. Check whether CI is dispatching at all — see the ci-dispatch-watchdog status on these PRs
  2. Merge the ones whose CI has finished and review has passed: gh pr merge <number> --squash --delete-branch
  3. Look for a loop opening near-identical PRs

Warn-only runaway detector — .github/workflows/pr-queue-gate.yml. It never blocks a merge.

@mrveiss

mrveiss commented Sep 11, 2026

Copy link
Copy Markdown
Owner Author

CI red: Check PR links to its issue fails because the branch name implies a link this PR's body doesn't state in the recognised form. The branch is issue-16171-mcp-npm-security, so the check expects Closes #16171 or Refs #16171 somewhere in the body. The body says "Supersedes #16171" — not a keyword the check recognises, even though #16171 is itself a PR (now closed), not an issue.

Fix: add a line the check accepts, e.g.:

Refs #16171 (superseded by this PR; #16171 targeted main and is closed)

That satisfies the linkage textually without implying #16171 needed fixing as an issue.

mrveiss added a commit that referenced this pull request Sep 12, 2026
@mrveiss mrveiss added this to the v0.9.0 milestone Sep 12, 2026
@mrveiss

mrveiss commented Sep 12, 2026

Copy link
Copy Markdown
Owner Author

Content review: approve. Pure lockfile bump (hono 4.13.0→4.13.7 + transitive deps across 4 package-lock.json files), no source changes. closingIssuesReferences=[] matches body (Refs #16171 only, no Closes). Ready.

@mrveiss
mrveiss merged commit 15d9775 into main Sep 13, 2026
75 of 78 checks passed
@mrveiss
mrveiss deleted the issue-16171-mcp-npm-security branch September 13, 2026 00:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant