Skip to content

fix(security): bump vulnerable deps flagged by Dependabot - #33008

Queued
harsh-vador wants to merge 2 commits into
mainfrom
fix/dependabot-dep-bumps
Queued

fix(security): bump vulnerable deps flagged by Dependabot#33008
harsh-vador wants to merge 2 commits into
mainfrom
fix/dependabot-dep-bumps

Conversation

@harsh-vador

Copy link
Copy Markdown
Contributor

Summary

Fixes 6 open Dependabot alerts:

Alert Package Change Advisory
#715 stream-json 1.7.5 → 3.5.0 (root, via resolutions) GHSA-528h-pc64-c93x — O(depth²) DoS
#720 js-yaml 3.15.1 → 3.15.2 (tooling/antd-codemods) GHSA-2883-xcg3-v3hh
#718/#719 svgo 3.3.4 → 3.3.5 (ui-core-components) GHSA-w27v-7q3p-w38r, GHSA-4vpr-x523-8j87
#716/#717 vitest + @vitest/mocker 3.2.7 → 4.1.11 (ui-core-components) GHSA-82fw-gwwq-j7x9 — path traversal via mocker redirect

stream-json compatibility

quicktype@20.0.27 pins stream-json@1.7.5 exactly; 3.5.0 is ESM-only, so the bump needs the resolutions override. This repo only invokes quicktype in schema mode (json2ts.sh, json2ts-generate-all.sh, and the typescript-type-generation workflow), which works with 3.5.0 (verified codegen). quicktype's JSON-sample input mode breaks under 3.5.0, but nothing here uses it. Same change already merged in Collate (open-metadata/openmetadata-collate#6455) with byte-identical regenerated output there.

vitest 4 notes (ui-core-components)

  • Dev-only test runner; first patched version is 4.1.11 (no 3.x backport).
  • Suite parity with main: 88 passed, 1 failure in table.test.tsx ("can omit the selection cell for a full-width synthetic row") that fails identically on pristine main — pre-existing, unrelated.
  • yarn build green.
  • Added vite: 7.3.5 resolution: vitest 4 moves vite to a peer dependency, and the duplicate vite lock entries (7.3.5/7.3.6) trip yarn 1's peer linker ("could not find a copy of vite to link"). Pinning collapses them to the single version the package already uses.

Not addressed (no patched release exists / not a dep bump)

🤖 Generated with Claude Code

- stream-json 1.7.5 -> 3.5.0 via root resolutions (GHSA-528h-pc64-c93x,
  DoS). quicktype@20 pins 1.7.5; the repo only uses `quicktype -s schema`
  (json2ts.sh / json2ts-generate-all.sh), verified working with 3.5.0.
- js-yaml 3.15.1 -> 3.15.2 in tooling/antd-codemods (GHSA-2883-xcg3-v3hh)
- svgo 3.3.4 -> 3.3.5 in ui-core-components (GHSA-w27v-7q3p-w38r,
  GHSA-4vpr-x523-8j87)
- vitest 3.2.7 -> 4.1.11 in ui-core-components (GHSA-82fw-gwwq-j7x9,
  @vitest/mocker path traversal). Dev-only; suite parity with main
  (88 passed, 1 pre-existing failure in table.test.tsx) and
  `yarn build` green. Added `vite: 7.3.5` resolution to collapse the
  duplicate vite lock entries that trip yarn 1's peer linker under
  vitest 4 ("could not find a copy of vite to link").

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

❌ PR checklist incomplete

This PR cannot be merged until the following are addressed on its linked issue:

  • No GitHub issue is linked. Link an issue in the Development section of the PR (or add Fixes #12345 to the description). For a same-org cross-repo issue, add Fixes open-metadata/<repo>#123 to the description.

The fields live on the linked issue in the Shipping project (open the issue → right sidebar → Projects). After you set them, re-run this check (or push a commit) — issue/project changes do not re-trigger it automatically.

Maintainers can bypass this check by adding the skip-pr-checks label.

@github-actions github-actions Bot added the UI UI specific issues label Sep 9, 2026
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Hi there 👋 Thanks for your contribution!

The OpenMetadata team will review the PR shortly! Once it has been labeled as safe to test, the CI workflows
will start executing and we'll be able to make sure everything is working as expected.

Let us know if you need any help!

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

✅ Playwright Results — workflow succeeded

Validated commit 929025e38b1ccda20586f5fc832516fb294d96fe in Playwright run 34317000955, attempt 1.

✅ 574 passed · ❌ 0 failed · 🟡 2 flaky · ⏭️ 0 skipped · 🧰 0 lifecycle flaky

Performance

Blocking targets: ✅ met · Optimization targets: 🟡 in progress

Shard-job maxima below are not the full workflow wall time; the linked run includes build, fixture, planning, and reporting.

🕒 Full workflow signal wall (to summary) 53m 9s

⏱️ Max setup 4m 17s · max shard execution 16m 33s · max shard-job elapsed before upload 19m 42s · reporting 6s

🌐 235.37 requests/attempt · 2.82 app boots/UI scenario · 19.84% common-shard skew

Optimization targets still in progress:

  • Common shard skew was 19.84% (convergence target: at most 15%).
  • Browser traffic was 235.37 requests per attempt (convergence target: fewer than 200).
  • Application boot ratio was 2.82 per UI scenario (1689 boots / 599 scenarios; convergence target: at most 1).
Shard Passed Failed Flaky Skipped Lifecycle failed Lifecycle flaky
🟡 Shard chromium-01 108 0 1 0 0 0
🟡 Shard chromium-02 104 0 1 0 0 0
✅ Shard chromium-03 98 0 0 0 0 0
✅ Shard chromium-04 106 0 0 0 0 0
✅ Shard data-asset-rules-01 65 0 0 0 0 0
✅ Shard domain-isolation-01 16 0 0 0 0 0
✅ Shard global-state-01 34 0 0 0 0 0
✅ Shard ingestion-01 1 0 0 0 0 0
✅ Shard reindex-01 2 0 0 0 0 0
✅ Shard search-01 11 0 0 0 0 0
✅ Shard search-rbac-01 29 0 0 0 0 0
🟡 2 flaky test(s) (passed on retry)
  • Pages/Entity.spec.tsTag Add, Update and Remove for child entities (shard chromium-01, 1 retry)
  • Pages/Entity.spec.tsTier Add, Update and Remove (shard chromium-02, 1 retry)

📦 Download artifacts

How to debug locally
# Download playwright-test-results-<shard> artifact and unzip
npx playwright show-trace path/to/trace.zip    # view trace

@harsh-vador harsh-vador self-assigned this Sep 9, 2026
@harsh-vador harsh-vador added the safe to test Add this label to run secure Github workflows on PRs label Sep 9, 2026
@gitar-bot

gitar-bot Bot commented Sep 9, 2026

Copy link
Copy Markdown
Code Review ✅ Approved

Bumps 6 vulnerable dependencies flagged by Dependabot: stream-json, js-yaml, svgo, vitest, and @vitest/mocker. stream-json 3.5.0 is pinned via resolutions to override quicktype's constraint (verified compatible with schema codegen); vitest 4 moves vite to peer dependency, so vite 7.3.5 is pinned to resolve duplicate lock entries. Test suite passes with one pre-existing failure unrelated to these changes. No issues found.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source

@harsh-vador
harsh-vador added this pull request to the merge queue Sep 9, 2026
Any commits made after this event will not be merged.
harsh-vador added a commit that referenced this pull request Sep 9, 2026
…33018)

* fix(security): bump stream-json 1.7.5 -> 3.5.0 (backport 2.0)

GHSA-528h-pc64-c93x (DoS). quicktype@20 pins 1.7.5; the repo only uses
`quicktype -s schema` (json2ts.sh / json2ts-generate-all.sh), verified
working with 3.5.0. Backport of the stream-json part of #33008; the
js-yaml (tooling/antd-codemods) and vitest/svgo (ui-core-components)
parts don't apply — those deps don't exist on 2.0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: document why the stream-json resolution override is safe

Review feedback on #33018: the override jumps two majors past
quicktype's exact pin, so record the verified-safe usage (schema mode
only) and the re-verification duty on future quicktype upgrades.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

safe to test Add this label to run secure Github workflows on PRs UI UI specific issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants