Skip to content

build(deps): remediate npm alerts and refresh safe dependencies - #3370

Merged
SamMorrowDrums merged 5 commits into
mainfrom
sammorrowdrums-dependency-updates
Oct 2, 2026
Merged

SamMorrowDrums merged 5 commits into
mainfrom
sammorrowdrums-dependency-updates

Conversation

@SamMorrowDrums

Copy link
Copy Markdown
Collaborator

Summary

Fix all nine open Dependabot alerts, refresh compatible Go/UI dependencies and GitHub Actions, and add weekly npm version updates. Keep MCP tool schemas and existing signing compatibility intact.

Why

The nine medium-severity alerts affect ui/package-lock.json:

Package Alerts Fixed version Advisories
hono 83, 84, 85, 91 4.13.12 GHSA-crvj-82cr-hjcx, GHSA-g6gw-c38x-mqfc, GHSA-gqvv-2mrq-wpjv, GHSA-hxh3-vqpv-xpqv
fast-uri 90 3.1.8 GHSA-hrr3-gc8f-f4qj
ip-address 86, 87, 88, 89 10.7.3 GHSA-2vr4-cq9g-pvrc, GHSA-rpw4-54j3-4h4q, GHSA-h3mg-xc3c-68pw, GHSA-j6r3-76f7-8jcv

Alerts remain open on main until a reviewed update merges and Dependabot rescans.

Dependabot PRs merged before this change: none. All eight open PRs require approving reviews and are behind main. No rulesets, protections, reviews or checks were bypassed. Their updates are included here; the original PRs remain open for maintainers to review or supersede:

Awaiting review Update CI at inventory
#3343 CodeQL Action 4.38.2 Successful
#3342 Go Docker digest Successful
#3319 setup-buildx-action 4.4.1 Successful
#3318 build-push-action 7.4.0 Successful
#3277 x/oauth2 0.37.0 No checks reported
#3276 MCP Go SDK 1.8.0 No checks reported
#3257 hono security update Successful
#3240 x/net update (this PR uses 0.59.0) Successful

What changed

  • Upgrade MCP Go SDK to stable 1.8.0, GraphQL clients to latest published revisions, x/net to 0.59.0, and x/oauth2 to 0.37.0. Refresh indirect x/sync, x/sys and x/text through go mod tidy.
  • Raise the minimum Go version to 1.26.8: latest x/net requires Go 1.26; 1.26.8 is the current maintenance patch. Lint CI now reads go.mod instead of pinning Go 1.25.
  • Adapt the new pointer type of AddPullRequestReviewThreadInput.Path and existing mutation fixtures without changing the serialized path or tool contract.
  • Update compatible UI versions and lockfile, including all fixed transitive packages above. No overrides or forced major upgrades.
  • Update CodeQL Action references to 4.38.2, SHA-pinned Docker setup-buildx/build-push to 4.4.1/7.4.0, and the Go Docker image digest. Align the UI composite action with cache v6 / setup-node v7 already used elsewhere.
  • Upgrade Cosign to 2.6.5, the maintained v2 backport for GHSA-fx35-mq7g-6g98, without changing signature bundle defaults.
  • Add weekly Dependabot npm coverage for /ui; gomod, github-actions and docker are already covered.
  • Regenerate all platform license reports. License texts, tool snapshots and generated docs remain unchanged. Required gofmt corrects one existing indentation issue.
  • Disable only modernize's newexpr style migration to preserve established pointer helpers rather than rewriting the library for Go 1.26. Security lint rules remain enabled.

Deferred upgrades:

Dependency Latest stable Reason
go-github v92.0.0 v90–v92 require widespread import-path and request-type migrations; retain v89's existing post-release revision with needed API work. No advisory found.
@modelcontextprotocol/ext-apps 2.0.3 SDK 2 split peers and breaking TypeScript/handler APIs require a dedicated migration. Use latest compatible 1.7.5.
@primer/react 38.40.1 Two major component/API migrations require visual review. Use latest compatible 36.27.0.
react / react-dom 19.3.0 Coordinated runtime major migration needs UI behavior review. Retain latest React 18.3.1.
@types/react / @types/react-dom 19.3.0 Keep types aligned with React 18; update to 18.3.31 / 18.3.7.
@types/node 26.6.4 Defer typing major until runtime policy is unified (CI Node 22, Docker Node 26). Update existing v25 line to 25.9.9.
typescript 7.0.2 Compiler major migration needs separate compatibility review. Use latest v5, 5.9.3.
golangci-lint 2.14.0 Trial introduced gosec/staticcheck/modernize findings in unchanged code; resolving/suppressing them needs separate review. Retain pinned 2.9.0 on Go 1.26.8 and document its Go 1.27 export-data limitation.
cosign 3.1.3 v3 changes default signature bundle format. Use security-fixed 2.6.5 backport to preserve published signature compatibility.

Other direct Go dependencies are current in their compatible module paths. Libraries without stable tags use their latest published revisions; go-github's existing revision is not downgraded to the older v89.0.0 tag.

MCP impact

  • No tool or API changes — tool names, schemas and outputs remain unchanged; existing snapshots pass. MCP SDK 1.8.0 supplies upstream transport/OAuth hardening without changing the supported protocol set.
  • Tool schema or behavior changed
  • New tool added

Prompts tested (tool changes only)

  • N/A: no tool definition changes. Existing pending-review mutation tests cover the GraphQL adaptation.

Security / limits

  • No security or limits impact
  • Auth / permissions considered — preserve auth/signing flows and fix Cosign verification; no protections or reviews bypassed.
  • Data exposure, filtering, or token/size limits considered — upstream MCP transport bounds are retained, with no new configuration overrides. npm audit, govulncheck and the advisory database check found no known vulnerabilities in their checked dependency sets.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR — all names remain unchanged.

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint — GOTOOLCHAIN=go1.26.8 TMPDIR="$PWD/bin/lint-tmp" script/lint: passed, 0 issues. Isolated TMPDIR avoids another session's shared linter lock.
  • Tested locally with ./script/test — GOTOOLCHAIN=go1.26.8 script/test: passed full race suite and unchanged toolsnaps.

Additional commands/results:

  • go test -race ./... on Go 1.27.1: passed.
  • GOTOOLCHAIN=go1.26.8 go build ./cmd/github-mcp-server ./cmd/mcpcurl: passed.
  • GOTOOLCHAIN=go1.26.8 script/generate-docs: passed; generated docs unchanged.
  • go mod tidy -diff: passed; no differences.
  • cd ui && npm ci --no-fund && npm run typecheck && npm run build && npm audit: passed; 0 vulnerabilities.
  • GOTOOLCHAIN=go1.26.8 go run golang.org/x/vuln/cmd/govulncheck@latest ./...: passed; no vulnerabilities found.
  • go run golang.org/x/vuln/cmd/govulncheck@latest -scan package ./... on Go 1.27.1: passed; no vulnerabilities found, including imported but unreachable dependencies.
  • GitHub check_dependency_vulnerabilities: passed; 0 vulnerable of 8 selected versions, including fixed npm packages and Cosign 2.6.5.
  • script/licenses and script/licenses-check: passed for all platforms; reports regenerated and reproducible.
  • actionlint -oneline -ignore 'property "code_scanning_.*" is not defined' -ignore 'label "ubuntu-latest-xl" is unknown': passed. Unfiltered actionlint reports only existing organization-injected CodeQL inputs/custom runner labels, not changes here.
  • git diff origin/main --check: passed.

Live PAT-based e2e tests, Docker builds and release signing were not run (no credentials/container runtime available). Hosted checks must pass before merge.

Docs

  • Not needed
  • Updated (README / docs / examples) — CONTRIBUTING documents the new Go minimum and pinned-linter toolchain; generated tool docs remain unchanged.

SamMorrowDrums and others added 3 commits October 2, 2026 10:45
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remediate all nine open npm alerts, update compatible Go and UI dependencies, refresh pinned Actions and the Go image, and backport the Cosign verification fix. Add weekly npm updates and regenerate third-party notices.

Raise the minimum supported Go version to 1.26.8 for the latest x/net dependency and align CI linting with that toolchain.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner October 2, 2026 08:49
Copilot AI balanced review requested due to automatic review settings October 2, 2026 08:49
Auto-generated by license-check workflow

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It spans security-sensitive dependency, CI, container, and signing changes, while Docker builds and release signing were not exercised.

Review effort: Balanced
Findings: None

What changed in this PR

Remediates npm security alerts while refreshing compatible Go, UI, container, and CI dependencies without changing MCP schemas.

Changes:

  • Updates vulnerable npm packages and adds weekly UI dependency updates.
  • Raises the Go minimum to 1.26.8 and adapts GraphQL pointer types.
  • Refreshes CI actions, container images, Cosign, and license reports.
File Description
ui/​package.json Updates compatible UI dependencies.
ui/​package-lock.json Locks refreshed and security-fixed npm packages.
go.mod Raises Go minimum and updates modules.
go.sum Records updated module checksums.
pkg/​github/​pullrequests.go Adapts the GraphQL path pointer type.
pkg/​github/​pullrequests_test.go Updates mutation fixtures.
pkg/​github/​granular_tools_test.go Updates granular-tool fixture.
pkg/​http/​oauth/​oauth_test.go Corrects existing formatting.
.golangci.yml Excludes the newexpr modernization.
CONTRIBUTING.md Documents toolchain requirements.
Dockerfile Refreshes the Go image digest.
.github/​dependabot.yml Adds weekly npm updates.
.github/​actions/​build-ui/​action.yml Updates cache and Node setup actions.
.github/​workflows/​lint.yml Reads the Go version from go.mod.
.github/​workflows/​code-scanning.yml Updates CodeQL actions.
.github/​workflows/​docker-publish.yml Updates Cosign and Docker actions.
third-party-licenses.darwin.md Refreshes Darwin dependency licenses.
third-party-licenses.linux.md Refreshes Linux dependency licenses.
third-party-licenses.windows.md Refreshes Windows dependency licenses.
Files not reviewed (1)
  • ui/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Auto-generated by license-check workflow
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants