Skip to content

fix(ci): time-box braces audit exception - #2547

Merged
Hweinstock merged 3 commits into
aws:refactorfrom
Hweinstock:fix/ci-braces-audit-expiry
Oct 6, 2026
Merged

Hweinstock merged 3 commits into
aws:refactorfrom
Hweinstock:fix/ci-braces-audit-expiry

Conversation

@Hweinstock

Copy link
Copy Markdown
Contributor

Summary

Temporarily ignore GHSA-vfj7-8cjw-p6xm through the shared bun run audit script while no patched braces release is available. Add a reusable expiry-test helper and one-week follow-up test; update two other vulnerable dependencies to fixed versions.

Related: #2528 (remove the exception when braces is patched).

Validation

Local audit, frozen install, 3,976 tests, typecheck, lint, format, secrets check, build, and Linux binary compile passed.

@github-actions github-actions Bot added the size/s PR size: S label Oct 6, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Oct 6, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed claude-security-reviewing Claude Code /security-review in progress agentcore-harness-reviewing AgentCore Harness review in progress labels Oct 6, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Reasonable approach to an awkward situation. GHSA-vfj7-8cjw-p6xm (braces stack-exhaustion DoS) currently has first_patched_version: null upstream, so there's nothing to upgrade to; suppressing it in CI and pairing that with a self-destructing techDebtTest to force a re-review on 2026-10-13 is a sensible pattern.

A few small observations, none blocking:

  • src/testing/techDebt.ts: when the deadline passes, every CI run on main will fail until someone updates the lockfile or extends the exception. That is the point of the test, but worth being aware of — the breakage happens on a date, not a code change. Consider also writing the console.error message to stdout/stderr via process.stderr.write or leaving the expect(...).toBeLessThan(...) message richer, since bun's default failure output may truncate the console log in CI. Not required.
  • package.json audit script: bun audit --ignore GHSA-vfj7-8cjw-p6xm is the correct flag per the bun docs, and bun run audit in verify.yml will forward extra CLI args, so this doesn't regress ad-hoc usage.
  • bun.lock also bumps shell-quote and source-map-js as side-effects of a reinstall. Unrelated to this PR but harmless.
  • Test location: src/techDebt.test.ts is a repo-wide debt tracker rather than a unit test for a module, so top-level placement is defensible. If you add more of these, a dedicated src/techDebt/ directory may read better.

No telemetry or mocking concerns — this is CI/test infra only.

@Hweinstock
Hweinstock marked this pull request as ready for review October 6, 2026 21:42

@notgitika notgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice idea! LGTM

@Hweinstock
Hweinstock merged commit 0dfabec into aws:refactor Oct 6, 2026
22 of 23 checks passed
@Hweinstock
Hweinstock deleted the fix/ci-braces-audit-expiry branch October 6, 2026 22:03
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.39%. Comparing base (f0943aa) to head (b195eab).
⚠️ Report is 5 commits behind head on refactor.

Additional details and impacted files
@@             Coverage Diff              @@
##           refactor    #2547      +/-   ##
============================================
- Coverage     97.40%   97.39%   -0.01%     
============================================
  Files           642      642              
  Lines         46865    46910      +45     
============================================
+ Hits          45647    45689      +42     
- Misses         1218     1221       +3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thanks for the report, @codecov-commenter — feedback like this is exactly
how we catch the things we missed. Because this PR is already
closed, the team won't see follow-up comments here.

Would you mind opening a new issue so we can track it properly?
https://github.com/aws/agentcore-cli/issues/new/choose

If this is a security issue, please report it privately via
https://aws.amazon.com/security/vulnerability-reporting/ instead
of a public issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/s PR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants