chore(deps): mitigate security findings with verified upgrades - #456
Merged
Merged
Conversation
JWThewes
marked this pull request as ready for review
September 11, 2026 10:59
JWThewes
requested review from
eipasteur,
jeromevdl,
leandrodamascena and
svozza
as code owners
September 11, 2026 10:59
jeromevdl
reviewed
Sep 11, 2026
Collaborator
There was a problem hiding this comment.
do we want to keep that in the repo?
jeromevdl
reviewed
Sep 11, 2026
Collaborator
There was a problem hiding this comment.
do we need to keep this too ?
jeromevdl
reviewed
Sep 11, 2026
jeromevdl
left a comment
Collaborator
There was a problem hiding this comment.
clean, but there are 2 files I'm not sure we should keep?!
Contributor
Author
|
I'll remove them |
- Deleted `scripts/test/dependency-security.test.mjs` as part of cleanup. - Removed outdated dependency security review notes from `docs/development/dependency-security-review-2026-09-11.md`.
Contributor
Author
|
Both files deleted |
jeromevdl
approved these changes
Sep 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolve the 14 open Dependabot findings reviewed on September 11, plus both open CodeQL findings. Also patch the Nano ID issue found by a fresh npm audit. Each dependency was checked separately before the next upgrade; the backend and frontend Vitest sets were tested separately with their internal versions aligned.
AgentCore installs from a separate manifest. Pin the affected packages there too, so its image source hash and Docker dependency layer change when this is deployed. Remove the SSM parameter path from the realtime-secret error and isolate the release test helper from its fixed shell probe, with regression tests for both CodeQL findings.
Dependency risk
The full compatibility and risk report lists every changed package, including each internal Vitest dependency, all alert IDs, upstream evidence, and residual risks. Other lockfile versions are unchanged. AgentCore's other existing ranges still float: medium residual rebuild risk, checked with a separate production installation, audit, and HTTP/MCP smoke test.
Dependabot PR review
Validation
No live AWS deployment or full container image build was performed. Default-branch security alerts remain open until merge and rescanning. GitHub validation also passed for commit
ee7b6419b6ae26300541e0af38deef6d3f428d36.GitHub validation — passed
refs/pull/456/head.The linked branch validation runs all used the PR head commit above. All PR-triggered checks also passed, including backend tests on Node 22 and 24, frontend build, lint, and CodeQL.