Repository navigation
fix(ci): time-box braces audit exception - #2547
Conversation
|
Claude Security Review: no high-confidence findings. (run) |
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
Reasonable approach to an awkward situation. GHSA-vfj7-8cjw-p6xm (braces stack-exhaustion DoS) currently has first_patched_version: null upstream, so there's nothing to upgrade to; suppressing it in CI and pairing that with a self-destructing techDebtTest to force a re-review on 2026-10-13 is a sensible pattern.
A few small observations, none blocking:
src/testing/techDebt.ts: when the deadline passes, every CI run onmainwill fail until someone updates the lockfile or extends the exception. That is the point of the test, but worth being aware of — the breakage happens on a date, not a code change. Consider also writing theconsole.errormessage to stdout/stderr viaprocess.stderr.writeor leaving theexpect(...).toBeLessThan(...)message richer, since bun's default failure output may truncate the console log in CI. Not required.package.jsonaudit script:bun audit --ignore GHSA-vfj7-8cjw-p6xmis the correct flag per the bun docs, andbun run auditinverify.ymlwill forward extra CLI args, so this doesn't regress ad-hoc usage.bun.lockalso bumpsshell-quoteandsource-map-jsas side-effects of a reinstall. Unrelated to this PR but harmless.- Test location:
src/techDebt.test.tsis a repo-wide debt tracker rather than a unit test for a module, so top-level placement is defensible. If you add more of these, a dedicatedsrc/techDebt/directory may read better.
No telemetry or mocking concerns — this is CI/test infra only.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## refactor #2547 +/- ##
============================================
- Coverage 97.40% 97.39% -0.01%
============================================
Files 642 642
Lines 46865 46910 +45
============================================
+ Hits 45647 45689 +42
- Misses 1218 1221 +3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Thanks for the report, @codecov-commenter — feedback like this is exactly Would you mind opening a new issue so we can track it properly? If this is a security issue, please report it privately via |
Summary
Temporarily ignore GHSA-vfj7-8cjw-p6xm through the shared
bun run auditscript while no patchedbracesrelease is available. Add a reusable expiry-test helper and one-week follow-up test; update two other vulnerable dependencies to fixed versions.Related: #2528 (remove the exception when
bracesis patched).Validation
Local audit, frozen install, 3,976 tests, typecheck, lint, format, secrets check, build, and Linux binary compile passed.