build(deps): fix 13 security advisories (tar, brace-expansion, js-yaml, hono, fast-uri, body-parser) - #465
Conversation
…-parser for security advisories - tar ^7.5.3 -> ^7.5.19 (locked 7.5.21): fixes GHSA-23hp-3jrh-7fpw (critical), GHSA-8x88-c5mf-7j5w (high), GHSA-w8wr-v893-vjvp / GHSA-gvwx-54wh-qm9j (moderate) - brace-expansion -> 1.1.16 / 5.0.7 via overrides: fixes GHSA-3jxr-9vmj-r5cp (high) - js-yaml 4.x -> 4.3.0 via override: fixes GHSA-52cp-r559-cp3m (high) - hono -> 4.12.27 via override: fixes GHSA-xgm2-5f3f-mvvc, GHSA-hvrm-45r6-mjfj, GHSA-w62v-xxxg-mg59 (moderate, dev-only) - fast-uri -> 3.1.4 via override: fixes GHSA-v2hh-gcrm-f6hx, GHSA-4c8g-83qw-93j6 (high, dev-only) - body-parser 2.x -> 2.3.0 via override: fixes GHSA-v422-hmwv-36x6 (low, dev-only) Not fixed: elliptic GHSA-848j-6mx2-7j84 (no patched release published) and @hono/node-server GHSA-frvp-7c67-39w9 (fix requires breaking 1.x -> 2.x bump that violates @modelcontextprotocol/sdk's ^1.19.9 range; dev-only, Windows-only). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
❌ Missing Changeset Please add a changeset describing your changes: pnpm changesetIf your changes do not need a version bump (docs, CI, refactoring), For dependency updates, use the |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
📝 WalkthroughSummary by CodeRabbit
WalkthroughUpdates the ChangesDependency security updates
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 Checkov (3.3.8)package.jsonTraceback (most recent call last): pnpm-workspace.yamlTraceback (most recent call last): Comment |
* fix(status): enable Terminal RPC module and TCP streaming for devnet (#463) (#464) * fix(status): enable Terminal RPC module and TCP streaming for devnet ckb-tui panels were always empty on devnet because the bundled devnet ckb.toml did not meet ckb-tui's two data requirements: - the Terminal RPC module (provides get_overview system metrics), which upstream CKB now enables by default, was missing from rpc.modules, so the overview dashboards showed N/A - rpc.tcp_listen_address was commented out and the status command never passed -t, so the mempool (new/rejected transactions) and logs dashboards had no subscription stream to read from Enable both in the devnet config template and have the status command read tcp_listen_address from the running node's ckb.toml and pass it to ckb-tui via -t (wildcard binds are dialed as localhost). Testnet and mainnet keep HTTP-only behavior since their proxied public RPCs expose no TCP stream. * chore: add patch changeset for status devnet fix * fix(devnet): bind RPC to loopback instead of 0.0.0.0 Address CodeRabbit review on PR #463: with the Terminal module enabled, binding the unauthenticated JSON-RPC to 0.0.0.0 exposes host system metrics (and the rest of the RPC surface) to any host on the network. Bind to 127.0.0.1 by default; all offckb-internal consumers (proxy, ckb-tui, miner, forks) already talk to 127.0.0.1:8114. Users who need remote access can edit rpc.listen_address via the config editor. * fix(devnet): align embedded reference template with devnet ckb.toml Add Terminal to rpc.modules and enable tcp_listen_address in the config editor's embedded template so configurations based on it also provide the metrics stream that offckb status needs. --------- Co-authored-by: claude-bear <noreply@anthropic.com> * build(deps): bump tar, brace-expansion, js-yaml, hono, fast-uri, body-parser for security advisories (#465) - tar ^7.5.3 -> ^7.5.19 (locked 7.5.21): fixes GHSA-23hp-3jrh-7fpw (critical), GHSA-8x88-c5mf-7j5w (high), GHSA-w8wr-v893-vjvp / GHSA-gvwx-54wh-qm9j (moderate) - brace-expansion -> 1.1.16 / 5.0.7 via overrides: fixes GHSA-3jxr-9vmj-r5cp (high) - js-yaml 4.x -> 4.3.0 via override: fixes GHSA-52cp-r559-cp3m (high) - hono -> 4.12.27 via override: fixes GHSA-xgm2-5f3f-mvvc, GHSA-hvrm-45r6-mjfj, GHSA-w62v-xxxg-mg59 (moderate, dev-only) - fast-uri -> 3.1.4 via override: fixes GHSA-v2hh-gcrm-f6hx, GHSA-4c8g-83qw-93j6 (high, dev-only) - body-parser 2.x -> 2.3.0 via override: fixes GHSA-v422-hmwv-36x6 (low, dev-only) Not fixed: elliptic GHSA-848j-6mx2-7j84 (no patched release published) and @hono/node-server GHSA-frvp-7c67-39w9 (fix requires breaking 1.x -> 2.x bump that violates @modelcontextprotocol/sdk's ^1.19.9 range; dev-only, Windows-only). Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix: rename mainnet-fork override flag and apply leftover 0.4.9 review fixes (#466) * fix: rename mainnet-fork override flag and apply leftover 0.4.9 review fixes - Rename --allow-mainnet-replay-risk to --allow-external-key-on-mainnet-fork (#460) - Enforce the Mainnet-fork replay guard in transfer-all, udt issue/destroy, and deploy, threading the fork boundary into input selection (#462) - Validate --tx-hash before it is used in debug cache paths - Only read the fork boundary after the spawned process binds the RPC port - Reject symlinked entries when copying fork source chain data - Accept extended xUDT type args (owner hash + flags/extension) - Per-kind UDT scan budgets, deep-cloned settings fallbacks, accurate config-set errors, preserved devnet-config error, execFile process lookup, aligned ckb-tui download timeouts, EXDEV-safe install, README TOC entry Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: address PR #466 review comments - Keep --allow-mainnet-replay-risk as a hidden deprecated alias folded into --allow-external-key-on-mainnet-fork (with a deprecation warning) so 0.4.9 scripts keep working under a patch release - Treat lsof probe failures with stderr output as indeterminate (null) instead of "not listening"; only an empty-stderr exit is a genuine no-match, so permission errors fall back to the weaker genesis signal - Reject a symlinked data root before enumerating source chain data - Stage cross-device ckb-tui installs inside binDir and publish with an atomic rename, so concurrent installs never see a truncated binary Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: bound the lsof port probe with a timeout A hung lsof would block execFileSync (and with it daemon startup) indefinitely, and its empty-stderr timeout error would be misread as a genuine no-match. Cap the probe at 5s and classify ETIMEDOUT as indeterminate (null) so the genesis fallback proceeds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test: make lsof probe tests platform-independent isProcessListeningOnPort short-circuits to null on win32, so the lsof outcome-mapping tests failed on the Windows CI runner (mock never called). Force a unix platform for the lsof-probing cases, cover the win32 short-circuit explicitly, and pin the probe timeout to exactly 5000 ms per review feedback. --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * Merge pull request #468 from ckb-devrel/agent/claude-bear/6b0ed58e fix(devnet): offer Terminal module in config editor and migrate legacy ckb.toml * chore: version packages for 0.4.10 release (#469) * fix: default devnet log filter to info,ckb-script=debug (#471) A healthy devnet emits almost no warn-level logs, so with the previous default filter (warn,ckb-script=debug) the `offckb status` Logs panel stayed permanently empty and looked broken. Switch the devnet ckb.toml and ckb-miner.toml templates (and the config editor's embedded reference templates) to info,ckb-script=debug so the per-block log stream is visible while script debug output is preserved. Existing chains keep their current filter; edit [logger] filter in the devnet ckb.toml to opt in. Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * chore: add new change log (#472) --------- Co-authored-by: humble-little-bear <retric@ckba.build> Co-authored-by: claude-bear <noreply@anthropic.com>
Summary
Security dependency bumps clearing 13 of the 15 advisories currently reported for
pnpm-lock.yaml(8 open Dependabot alerts + additional ones found viapnpm audit). All changes are patch/minor-level, applied via the existingpnpm-workspace.yamloverride pattern plus one direct-dependency floor bump.Fixed
limitdisables size enforcementminimumReleaseAgeExcludewas extended for the freshly published versions, matching the existing convention.Not auto-fixed
>=6.6.2fix version does not exist). Transitive via@ckb-ccc/core→@joyid/ckb→@nervosnetwork/ckb-sdk-utils. Needs an upstream fix.@modelcontextprotocol/sdk@1.27.1's declared^1.19.9range, so forcing it via override could silently break the (dev-only, Windows-only)eslint --mcpstatic-serving path. Left for a deliberate upgrade.Verification
pnpm install— lockfile regenerated cleanlypnpm audit— 15 → 2 advisories remaining (the two listed above); 0 critical / 0 high leftpnpm build✅pnpm test— 24/24 suites, 181 passed ✅pnpm typecheck✅ /pnpm lint✅ (0 errors)