Skip to content

chore(deps): mitigate security findings with verified upgrades - #456

Merged
jeromevdl merged 2 commits into
mainfrom
chore/dep-upgrades
Sep 11, 2026
Merged

jeromevdl merged 2 commits into
mainfrom
chore/dep-upgrades

Conversation

@JWThewes

@JWThewes JWThewes commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Resolve the 14 open Dependabot findings reviewed on September 11, plus both open CodeQL findings. Also patch the Nano ID issue found by a fresh npm audit. Each dependency was checked separately before the next upgrade; the backend and frontend Vitest sets were tested separately with their internal versions aligned.

AgentCore installs from a separate manifest. Pin the affected packages there too, so its image source hash and Docker dependency layer change when this is deployed. Remove the SSM parameter path from the realtime-secret error and isolate the release test helper from its fixed shell probe, with regression tests for both CodeQL findings.

Dependency risk

Upgrade Regression risk Individual compatibility evidence
js-yaml 4.3.1 → 4.3.2 Medium: new 100-source YAML merge limit 71 parsing/seeding tests; normal aliases and empty-merge budget regression
brace-expansion 2.1.2 → 2.1.4 Low: extreme expansions are bounded CommonJS API, padded ranges, character budget, ZIP export
brace-expansion 5.0.7 → 5.0.9 Low: drops Node 18; project uses 22/24 Named API and separate expansion/ZIP checks
Hono 4.13.0 → 4.13.5 Low: stricter query/form handling 82 MCP tests, normal/adversarial queries and forms
qs 6.15.3 → 6.16.0 Low: strict comma-array limit behavior Both advisory regressions, nested round trips, real MCP Express HTTP form request
Nano ID 3.3.16 → 3.3.18, root and frontend Low ESM, CommonJS, browser and async browser checks in each tree; frontend build
Backend Vitest + coverage 4.1.10 → 4.1.11 Low: filesystem allowlist/concurrency backport 1,516 tests with coverage; exact peers validated
Frontend Vitest 4.1.9 → 4.1.11 Low 540 tests and production build

The full compatibility and risk report lists every changed package, including each internal Vitest dependency, all alert IDs, upstream evidence, and residual risks. Other lockfile versions are unchanged. AgentCore's other existing ranges still float: medium residual rebuild risk, checked with a separate production installation, audit, and HTTP/MCP smoke test.

Dependabot PR review

Validation

  • Full backend on Node 22.22.2: 158 files / 2,837 tests passed, including integration tests.
  • Shared/agent runtime coverage on Node 24.18.0: 94 files / 1,516 tests passed.
  • Frontend on Node 24.18.0: 77 files / 540 tests passed; production build passed.
  • Release tooling and security regression suite: 63 tests passed.
  • All Lambda workspace builds passed; 37 ESM bundle entry points imported in fresh Node 24 processes.
  • Standalone AgentCore: exact security pins verified; HTTP health, YAML parsing, MCP initialization and 20-tool discovery passed.
  • Full npm audits, including dev dependencies: 0 vulnerabilities in root, frontend, Yjs, and Cognito lockfiles; standalone AgentCore production audit also 0.
  • Clean installs, complete dependency-tree checks, formatter, lint, changed-file secretlint, and AWS SDK alignment passed. Existing lint/Smithy and frontend chunk-size warnings remain.

No live AWS deployment or full container image build was performed. Default-branch security alerts remain open until merge and rescanning. GitHub validation also passed for commit ee7b6419b6ae26300541e0af38deef6d3f428d36.

GitHub validation — passed

The linked branch validation runs all used the PR head commit above. All PR-triggered checks also passed, including backend tests on Node 22 and 24, frontend build, lint, and CodeQL.

@JWThewes
JWThewes marked this pull request as ready for review September 11, 2026 10:59

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we want to keep that in the repo?

@jeromevdl jeromevdl Sep 11, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we need to keep this too ?

@jeromevdl jeromevdl left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clean, but there are 2 files I'm not sure we should keep?!

@JWThewes

Copy link
Copy Markdown
Contributor Author

I'll remove them

- Deleted `scripts/test/dependency-security.test.mjs` as part of cleanup.
- Removed outdated dependency security review notes from `docs/development/dependency-security-review-2026-09-11.md`.
@JWThewes

Copy link
Copy Markdown
Contributor Author

Both files deleted

@JWThewes
JWThewes requested a review from jeromevdl September 11, 2026 12:40
@jeromevdl
jeromevdl merged commit bcd94d3 into main Sep 11, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants