Skip to content

chore: clear open Dependabot alerts (rustls + frontend) - #173

Merged
thedancingdeveloper merged 2 commits into
mainfrom
chore/dependabot-sweep
Oct 10, 2026
Merged

thedancingdeveloper merged 2 commits into
mainfrom
chore/dependabot-sweep

Conversation

@thedancingdeveloper

Copy link
Copy Markdown
Collaborator

Summary

Clears the open Dependabot alerts in one sweep: rustls bumped to 0.23.45 in all four lockfiles, and the frontend npm audit findings fixed with direct bumps plus overrides where a parent pins an old version. Angular stays on major 21.

npm audit fix (no --force) crashes on both npm 10.9.9 and the repo's declared npm 11.9.0 (Cannot read properties of null (reading 'edgesOut')), so the frontend bumps were applied directly and the lockfile regenerated with npm 11.9.0.

Alert → package → old → new

Alert Package Old New
#90 rustls (root) 0.23.43 0.23.45
#89 rustls (benchnzb) 0.23.37 0.23.45
#88 rustls (desktop) 0.23.41 0.23.45
#74 rustls (fuzz) 0.23.42 0.23.45
#87 @modelcontextprotocol/sdk 1.30.0 1.31.0
#86 source-map-js 1.2.1 1.2.2
#85 proxy-addr 2.0.7 2.0.8
#83 piscina 5.2.0 5.3.2
#82 hono 4.13.5 4.13.7
#80 ip-address 10.7.0 10.7.1
#78 brace-expansion 5.0.9 5.0.12
#76 undici (6.x, node-gyp) 6.28.0 6.28.1
#75, #59 fast-uri 3.1.6 3.1.8
#72 @angular/router 21.2.22 21.2.25
#70, #69, #68, #65, #64, #62 undici (7.x) 7.29.0 7.29.1
#58 vitest 4.1.10 4.1.11
#57 @vitest/mocker 4.1.10 4.1.11

fast-uri is taken to 3.1.8 rather than 3.1.7 because 3.1.7 is itself flagged (inconsistent host-case normalisation). The Angular framework line moves to 21.2.25 and CLI/build to 21.2.26 alongside the router bump, since 21.2.25 peers the whole framework at that exact version; material and CDK stay at 21.2.14, their newest 21 release. qs moves 6.15.3 → 6.16.0 as part of the same audit pass.

Remaining unfixable alert

Alert Package Status
#84 http-cache-semantics (≤ 4.2.0, no patched release) Resolved transitively: the lockfile now pulls 4.3.0, which is outside the vulnerable range. npm audit reports 0 vulnerabilities.

Verification

  • cargo build --locked and cargo test -p rustnzb pass at the repo root.
  • cargo metadata --locked passes for benchnzb/, desktop/src-tauri/ and fuzz/.
  • npm ci && npx ng build && npm test -- --watch=false: build succeeds, 152 tests pass.
  • npm audit: 0 vulnerabilities.

The fuzz lockfile also refreshes path-crate versions (nzb-core, nzb-decode, nzb-nntp) that had fallen behind the workspace, because cargo update -p rustls rewrites that graph.

thedancingdeveloper and others added 2 commits October 10, 2026 09:30
Clears Dependabot alerts #74 #88 #89 #90 (WI-1199).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…erts

Angular 21.2.x patch bumps, vitest 4.1.11, and overrides for transitive
packages with fixed releases. http-cache-semantics has no fix yet (WI-1199).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@thedancingdeveloper thedancingdeveloper left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review: no blockers (head 87ac3c7)

This reviews both commits on main e48e2c0. All 24 open Dependabot alerts are fixed at this head: I checked each alert's vulnerable range against every copy of that package in the PR's lockfiles (4× rustls, 20× npm). Nothing malicious or tampered was found.

5f5967e: rustls in all four Cargo lockfiles

  • Cargo.lock and desktop/src-tauri/Cargo.lock: only rustls → 0.23.45, rustls-webpki → 0.103.15, aws-lc-rs → 1.18.1 and aws-lc-sys → 0.45.0.
  • benchnzb/Cargo.lock: only rustls and rustls-webpki.
  • Registry checks: all four match crates.io checksums, aren't yanked, and come from their usual publishers (ctz, cpu, justsmth). There's one rustls in the workspace.
  • fuzz/Cargo.lock: the transitive churn comes from the lock being stale. It pinned old copies of our own path crates (nzb-core 0.2.16, nzb-nntp 0.2.22, nzb-decode 0.1.2). It now matches the workspace (0.2.19 / 0.2.26 / 0.1.5), so their current dependencies follow.
    • 29 of the 37 new registry versions already appear, with identical checksums, in the vetted workspace, desktop or bench locks. That includes the five crate names new to fuzz (md-5, const-oid, toml_parser, toml_writer, and hybrid-array at another version) and the small downgrades (mio, tokio-macros, zerocopy, windows-*).
    • The other 8 are cc 1.4.4, find-msvc-tools 0.1.11, futures-{core,sink,task,util} 0.3.34, hybrid-array 0.4.14 and portable-atomic 1.15.0. All match crates.io checksums, aren't yanked, and are 7–10 weeks old.
    • No non-crates.io sources, and no checksum changes for an unchanged version.
  • Lockfile consistency: all four lockfiles resolve with cargo metadata --locked.

87ac3c7: frontend

  • Direct dependencies: patch/minor bumps within existing majors only: Angular 21.2.25/21.2.26, CDK/Material 21.2.14, vitest and @vitest/coverage-v8 4.1.11.
  • Package inventory: 584 → 586 packages. One new name, @napi-rs/lzma-linux-x64-gnu 1.5.1. One removed, @parcel/watcher-win32-ia32.
    • Rollup 4.64.4 adds the lzma package as an optional dependency. I verified it's genuine: it's in rollup's own package.json at the v4.64.4 commit (9568144c54), and npm provenance ties the published tarball to rollup/rollup refs/tags/v4.64.4. Rollup has shipped it since 4.62.4.
    • The binary itself has provenance from Brooooooklyn/lzma (the napi-rs author), was published in July, has no install scripts, and its integrity matches.
    • Every entry resolves from registry.npmjs.org with an integrity hash. No integrity changes for an unchanged version, and no package newly gains an install script.
  • Overrides (correctness): I resolved every copy of each overridden package and checked its dependents' declared ranges with npm's semver. All are satisfied:
    • brace-expansion 5.0.12 has a single dependent, minimatch ^5.0.8.
    • undici 7.29.1 applies everywhere except node-gyp, which gets 6.28.1 through the nested override.
    • All ten overridden packages are dev-only, so none ships in the app bundle.
  • Local run (npm ci --ignore-scripts, as a precaution): ng build --configuration production passes, with only the pre-existing 128-byte queue-view style budget warning. ng test passes 152/152 tests in 20 files. npm audit, including dev dependencies, reports 0 vulnerabilities.
  • CSP: the built index.html still has 0 inline scripts, 0 on*= handlers and a plain stylesheet link, so it stays compatible with the strict CSP from #170.

CI at this head

All 11 checks are green: the required policy, rust, Analyze (rust) and Analyze (javascript-typescript), plus desktop, frontend, e2e, container-smoke, CodeQL, dependency-review and runner-policy. There are no code-scanning alerts on the PR.

Should-fix (non-blocking)

  1. Very fresh releases came in with the lock refresh. Of 133 new npm versions, 70 are under 14 days old and 28 were published today, hours before the commit:

    • rollup 4.64.4 and all 26 of its platform binaries, 06:07–06:11Z;
    • prettier 3.9.10, 08:35Z, with the commit at 09:30Z.

    None of these is needed for the alerts; the fixing versions are all 9+ days old.

    • Provenance: for the versions under 2 days old, rollup, express 5.3.0, @hono/node-server 2.1.4, electron-to-chromium, baseline-browser-mapping and node-releases all have provenance from their expected repos.
    • No provenance: prettier 3.9.10 and p-map 7.1.0 have none, but that matches every recent release of each (prettier publishes from GitHub Actions without attestations; p-map is published manually by sindresorhus). Neither has lifecycle scripts.

    I found no sign of compromise. Still, dev tooling runs in CI and on developer machines with credentials. Recommendation: re-lock with a short cooldown (e.g. npm install --before=<3 days ago>), and add a release-age policy for future sweeps (a Dependabot cooldown, or Renovate's minimumReleaseAge). There's none in the repo today.

  2. Make the overrides floors, not exact pins. An exact override freezes that transitive package. A later security patch, e.g. undici 7.29.2, won't install until someone edits package.json, and Dependabot can't move a version pinned by an override, so future alerts would stay open.

    • Prefer ^ ranges with the patched floor ("proxy-addr": "^2.0.8", "undici": "^7.29.1", and so on), keeping the nested node-gyp → undici ^6.28.1.
    • Several are already redundant and could be dropped: @angular/cli pins @modelcontextprotocol/sdk 1.31.0 exactly, @angular/build pins piscina 5.3.2 and undici 7.29.1 exactly, and express already requires qs ^6.16.0.
    • Review the list periodically and remove entries once parents ship fixed ranges.

Not merged. This verdict covers only this head SHA.

@thedancingdeveloper
thedancingdeveloper merged commit 71fea38 into main Oct 10, 2026
11 checks passed
@thedancingdeveloper
thedancingdeveloper deleted the chore/dependabot-sweep branch October 10, 2026 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant