build(deps): remediate npm alerts and refresh safe dependencies - #3370
Merged
Merged
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remediate all nine open npm alerts, update compatible Go and UI dependencies, refresh pinned Actions and the Go image, and backport the Cosign verification fix. Add weekly npm updates and regenerate third-party notices. Raise the minimum supported Go version to 1.26.8 for the latest x/net dependency and align CI linting with that toolchain. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Auto-generated by license-check workflow
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It spans security-sensitive dependency, CI, container, and signing changes, while Docker builds and release signing were not exercised.
Review effort: Balanced
Findings: None
What changed in this PR
Remediates npm security alerts while refreshing compatible Go, UI, container, and CI dependencies without changing MCP schemas.
Changes:
- Updates vulnerable npm packages and adds weekly UI dependency updates.
- Raises the Go minimum to 1.26.8 and adapts GraphQL pointer types.
- Refreshes CI actions, container images, Cosign, and license reports.
| File | Description |
|---|---|
ui/package.json |
Updates compatible UI dependencies. |
ui/package-lock.json |
Locks refreshed and security-fixed npm packages. |
go.mod |
Raises Go minimum and updates modules. |
go.sum |
Records updated module checksums. |
pkg/github/pullrequests.go |
Adapts the GraphQL path pointer type. |
pkg/github/pullrequests_test.go |
Updates mutation fixtures. |
pkg/github/granular_tools_test.go |
Updates granular-tool fixture. |
pkg/http/oauth/oauth_test.go |
Corrects existing formatting. |
.golangci.yml |
Excludes the newexpr modernization. |
CONTRIBUTING.md |
Documents toolchain requirements. |
Dockerfile |
Refreshes the Go image digest. |
.github/dependabot.yml |
Adds weekly npm updates. |
.github/actions/build-ui/action.yml |
Updates cache and Node setup actions. |
.github/workflows/lint.yml |
Reads the Go version from go.mod. |
.github/workflows/code-scanning.yml |
Updates CodeQL actions. |
.github/workflows/docker-publish.yml |
Updates Cosign and Docker actions. |
third-party-licenses.darwin.md |
Refreshes Darwin dependency licenses. |
third-party-licenses.linux.md |
Refreshes Linux dependency licenses. |
third-party-licenses.windows.md |
Refreshes Windows dependency licenses. |
Files not reviewed (1)
- ui/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Auto-generated by license-check workflow
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix all nine open Dependabot alerts, refresh compatible Go/UI dependencies and GitHub Actions, and add weekly npm version updates. Keep MCP tool schemas and existing signing compatibility intact.
Why
The nine medium-severity alerts affect
ui/package-lock.json:Alerts remain open on
mainuntil a reviewed update merges and Dependabot rescans.Dependabot PRs merged before this change: none. All eight open PRs require approving reviews and are behind main. No rulesets, protections, reviews or checks were bypassed. Their updates are included here; the original PRs remain open for maintainers to review or supersede:
What changed
go mod tidy.go.modinstead of pinning Go 1.25.AddPullRequestReviewThreadInput.Pathand existing mutation fixtures without changing the serialized path or tool contract.npmcoverage for/ui; gomod, github-actions and docker are already covered.newexprstyle migration to preserve established pointer helpers rather than rewriting the library for Go 1.26. Security lint rules remain enabled.Deferred upgrades:
Other direct Go dependencies are current in their compatible module paths. Libraries without stable tags use their latest published revisions; go-github's existing revision is not downgraded to the older v89.0.0 tag.
MCP impact
Prompts tested (tool changes only)
Security / limits
Tool renaming
deprecated_tool_aliases.goNote: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.
Lint & tests
./script/lint—GOTOOLCHAIN=go1.26.8 TMPDIR="$PWD/bin/lint-tmp" script/lint: passed, 0 issues. Isolated TMPDIR avoids another session's shared linter lock../script/test—GOTOOLCHAIN=go1.26.8 script/test: passed full race suite and unchanged toolsnaps.Additional commands/results:
go test -race ./...on Go 1.27.1: passed.GOTOOLCHAIN=go1.26.8 go build ./cmd/github-mcp-server ./cmd/mcpcurl: passed.GOTOOLCHAIN=go1.26.8 script/generate-docs: passed; generated docs unchanged.go mod tidy -diff: passed; no differences.cd ui && npm ci --no-fund && npm run typecheck && npm run build && npm audit: passed; 0 vulnerabilities.GOTOOLCHAIN=go1.26.8 go run golang.org/x/vuln/cmd/govulncheck@latest ./...: passed; no vulnerabilities found.go run golang.org/x/vuln/cmd/govulncheck@latest -scan package ./...on Go 1.27.1: passed; no vulnerabilities found, including imported but unreachable dependencies.check_dependency_vulnerabilities: passed; 0 vulnerable of 8 selected versions, including fixed npm packages and Cosign 2.6.5.script/licensesandscript/licenses-check: passed for all platforms; reports regenerated and reproducible.actionlint -oneline -ignore 'property "code_scanning_.*" is not defined' -ignore 'label "ubuntu-latest-xl" is unknown': passed. Unfiltered actionlint reports only existing organization-injected CodeQL inputs/custom runner labels, not changes here.git diff origin/main --check: passed.Live PAT-based e2e tests, Docker builds and release signing were not run (no credentials/container runtime available). Hosted checks must pass before merge.
Docs