Repository navigation
chore: clear open Dependabot alerts (rustls + frontend) - #173
Conversation
…erts Angular 21.2.x patch bumps, vitest 4.1.11, and overrides for transitive packages with fixed releases. http-cache-semantics has no fix yet (WI-1199). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
thedancingdeveloper
left a comment
There was a problem hiding this comment.
Security review: no blockers (head 87ac3c7)
This reviews both commits on main e48e2c0. All 24 open Dependabot alerts are fixed at this head: I checked each alert's vulnerable range against every copy of that package in the PR's lockfiles (4× rustls, 20× npm). Nothing malicious or tampered was found.
5f5967e: rustls in all four Cargo lockfiles
Cargo.lockanddesktop/src-tauri/Cargo.lock: onlyrustls→ 0.23.45,rustls-webpki→ 0.103.15,aws-lc-rs→ 1.18.1 andaws-lc-sys→ 0.45.0.benchnzb/Cargo.lock: onlyrustlsandrustls-webpki.- Registry checks: all four match crates.io checksums, aren't yanked, and come from their usual publishers (
ctz,cpu,justsmth). There's onerustlsin the workspace. fuzz/Cargo.lock: the transitive churn comes from the lock being stale. It pinned old copies of our own path crates (nzb-core0.2.16,nzb-nntp0.2.22,nzb-decode0.1.2). It now matches the workspace (0.2.19 / 0.2.26 / 0.1.5), so their current dependencies follow.- 29 of the 37 new registry versions already appear, with identical checksums, in the vetted workspace, desktop or bench locks. That includes the five crate names new to fuzz (
md-5,const-oid,toml_parser,toml_writer, andhybrid-arrayat another version) and the small downgrades (mio,tokio-macros,zerocopy,windows-*). - The other 8 are
cc1.4.4,find-msvc-tools0.1.11,futures-{core,sink,task,util}0.3.34,hybrid-array0.4.14 andportable-atomic1.15.0. All match crates.io checksums, aren't yanked, and are 7–10 weeks old. - No non-crates.io sources, and no checksum changes for an unchanged version.
- 29 of the 37 new registry versions already appear, with identical checksums, in the vetted workspace, desktop or bench locks. That includes the five crate names new to fuzz (
- Lockfile consistency: all four lockfiles resolve with
cargo metadata --locked.
87ac3c7: frontend
- Direct dependencies: patch/minor bumps within existing majors only: Angular 21.2.25/21.2.26, CDK/Material 21.2.14, vitest and
@vitest/coverage-v84.1.11. - Package inventory: 584 → 586 packages. One new name,
@napi-rs/lzma-linux-x64-gnu1.5.1. One removed,@parcel/watcher-win32-ia32.- Rollup 4.64.4 adds the lzma package as an optional dependency. I verified it's genuine: it's in rollup's own
package.jsonat the v4.64.4 commit (9568144c54), and npm provenance ties the published tarball torollup/rolluprefs/tags/v4.64.4. Rollup has shipped it since 4.62.4. - The binary itself has provenance from
Brooooooklyn/lzma(the napi-rs author), was published in July, has no install scripts, and its integrity matches. - Every entry resolves from
registry.npmjs.orgwith an integrity hash. No integrity changes for an unchanged version, and no package newly gains an install script.
- Rollup 4.64.4 adds the lzma package as an optional dependency. I verified it's genuine: it's in rollup's own
- Overrides (correctness): I resolved every copy of each overridden package and checked its dependents' declared ranges with npm's
semver. All are satisfied:brace-expansion5.0.12 has a single dependent,minimatch ^5.0.8.undici7.29.1 applies everywhere exceptnode-gyp, which gets 6.28.1 through the nested override.- All ten overridden packages are dev-only, so none ships in the app bundle.
- Local run (
npm ci --ignore-scripts, as a precaution):ng build --configuration productionpasses, with only the pre-existing 128-byte queue-view style budget warning.ng testpasses 152/152 tests in 20 files.npm audit, including dev dependencies, reports 0 vulnerabilities. - CSP: the built
index.htmlstill has 0 inline scripts, 0on*=handlers and a plain stylesheet link, so it stays compatible with the strict CSP from #170.
CI at this head
All 11 checks are green: the required policy, rust, Analyze (rust) and Analyze (javascript-typescript), plus desktop, frontend, e2e, container-smoke, CodeQL, dependency-review and runner-policy. There are no code-scanning alerts on the PR.
Should-fix (non-blocking)
-
Very fresh releases came in with the lock refresh. Of 133 new npm versions, 70 are under 14 days old and 28 were published today, hours before the commit:
rollup4.64.4 and all 26 of its platform binaries, 06:07–06:11Z;prettier3.9.10, 08:35Z, with the commit at 09:30Z.
None of these is needed for the alerts; the fixing versions are all 9+ days old.
- Provenance: for the versions under 2 days old, rollup,
express5.3.0,@hono/node-server2.1.4,electron-to-chromium,baseline-browser-mappingandnode-releasesall have provenance from their expected repos. - No provenance:
prettier3.9.10 andp-map7.1.0 have none, but that matches every recent release of each (prettier publishes from GitHub Actions without attestations; p-map is published manually bysindresorhus). Neither has lifecycle scripts.
I found no sign of compromise. Still, dev tooling runs in CI and on developer machines with credentials. Recommendation: re-lock with a short cooldown (e.g.
npm install --before=<3 days ago>), and add a release-age policy for future sweeps (a Dependabotcooldown, or Renovate'sminimumReleaseAge). There's none in the repo today. -
Make the overrides floors, not exact pins. An exact override freezes that transitive package. A later security patch, e.g.
undici7.29.2, won't install until someone editspackage.json, and Dependabot can't move a version pinned by an override, so future alerts would stay open.- Prefer
^ranges with the patched floor ("proxy-addr": "^2.0.8","undici": "^7.29.1", and so on), keeping the nestednode-gyp→undici^6.28.1. - Several are already redundant and could be dropped:
@angular/clipins@modelcontextprotocol/sdk1.31.0 exactly,@angular/buildpinspiscina5.3.2 andundici7.29.1 exactly, andexpressalready requiresqs ^6.16.0. - Review the list periodically and remove entries once parents ship fixed ranges.
- Prefer
Not merged. This verdict covers only this head SHA.
Summary
Clears the open Dependabot alerts in one sweep: rustls bumped to 0.23.45 in all four lockfiles, and the frontend npm audit findings fixed with direct bumps plus
overrideswhere a parent pins an old version. Angular stays on major 21.npm audit fix(no--force) crashes on both npm 10.9.9 and the repo's declared npm 11.9.0 (Cannot read properties of null (reading 'edgesOut')), so the frontend bumps were applied directly and the lockfile regenerated with npm 11.9.0.Alert → package → old → new
fast-uri is taken to 3.1.8 rather than 3.1.7 because 3.1.7 is itself flagged (inconsistent host-case normalisation). The Angular framework line moves to 21.2.25 and CLI/build to 21.2.26 alongside the router bump, since 21.2.25 peers the whole framework at that exact version; material and CDK stay at 21.2.14, their newest 21 release.
qsmoves 6.15.3 → 6.16.0 as part of the same audit pass.Remaining unfixable alert
npm auditreports 0 vulnerabilities.Verification
cargo build --lockedandcargo test -p rustnzbpass at the repo root.cargo metadata --lockedpasses forbenchnzb/,desktop/src-tauri/andfuzz/.npm ci && npx ng build && npm test -- --watch=false: build succeeds, 152 tests pass.npm audit: 0 vulnerabilities.The fuzz lockfile also refreshes path-crate versions (nzb-core, nzb-decode, nzb-nntp) that had fallen behind the workspace, because
cargo update -p rustlsrewrites that graph.