Repository navigation
fix(deps): resolve joi 18.2.9 for the wait-on dev tool (GHSA-6h2x-m376-mqjq) - #909
Conversation
…6-mqjq) The tag-triggered CI/CD run for v1.29.0 failed its enforced OSV scan on joi 18.2.5 (CVE-2026-92599, high, fixed in 18.2.6), reached only through the root devDependency wait-on 9.1.0. Lockfile-only refresh inside the existing ^18.2.3 range: both joi copies now resolve 18.2.9. No manifest, override or scanner-config change.
🤖 CodeAnt AI — Review Status
|
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis lockfile-only dependency refresh resolves both Joi copies to 18.2.9, removing the reported OSV vulnerability from the CI/E2E wait-on dependency graph without changing package manifests, scanner configuration, or adding an ignore; reviewers should also confirm the immutable-tag and v1.29.1 release disposition. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 11 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 92 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThe changelog records the development dependency update from ChangesDependency update record
Priority: ⬇️ Low Merge Risk: 🔵 Low · up to Update the stale security-table entry before merging so reviewers see the current dependency versions. Automated scans use the lockfile, so the mismatch does not invalidate them. Comment |
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
Release-truth correction before merge: The remediation itself is correct and the exact-head Security Audit already passes, including the OSV scan. However, the PR body's release-disposition sentence “so nothing was published” is too broad. Before the Tauri cancellation, Docker run
to digest: The accurate statement is: no GitHub/Desktop Release was published; GHCR container tags were already published and must be reconciled by the v1.29.1 successor release. Please fold this into the single correction wave with any other validated review findings. No scanner ignore/gate weakening is needed; the lockfile fix itself is already proven by the exact-head OSV gate. |
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to GitHub limitations.
🟡 Minor · Update the Known Overrides Table to match the lockfile. · pnpm-lock.yaml:7610-7618
pnpm-lock.yaml:7610-7618
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winUpdate the Known Overrides Table to match the lockfile.
AUDIT.mdpresents this table as current security guidance, but the row listsjoi@18.2.1andwait-on@9.0.10. The lockfile now resolvesjoi@18.2.9forwait-on@7.2.0andwait-on@9.1.0. This mismatch can mislead a human security review.Suggested fix
-| joi (transitive via `wait-on` ← `@storybook/test-runner` → `jest-process-manager`) | ^18.2.1 | transitive hardening (dev-only) | `wait-on@7.2.0` originally pulled an older `joi`; lockfile pins `joi@18.2.1` for both `wait-on@7.2.0` and `wait-on@9.0.10`. Dev/test toolchain only, never shipped. | +| joi (transitive via `wait-on` ← `@storybook/test-runner` → `jest-process-manager`) | ^18.2.1 | transitive hardening (dev-only) | `wait-on@7.2.0` originally pulled an older `joi`; the lockfile resolves `joi@18.2.9` for both `wait-on@7.2.0` and `wait-on@9.1.0`. Dev/test toolchain only, never shipped. |
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
Review profile: CHILL
Plan: Essentials
Run ID: 327b3cdf-d0b4-4bcd-bcbc-ad7a5e4cf98f
📒 Files selected for processing (1)
CHANGELOG.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
|
Confirmed and folded in. The Docker run 36618279810 log shows manifests pushed for |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
#909) The workspace override still admitted the affected joi 18.2.5 (>=18.2.5 <19); raise it to >=18.2.6 <19 so a later re-resolution cannot fall back to a GHSA-6h2x-m376-mqjq version. AUDIT.md's accepted-risk note and Known Overrides row named a stale ^18.2.1 range and old resolutions (joi 18.2.1, wait-on 9.0.10); both now match the override and lockfile.
|
@coderabbitai Outside-diff finding (AUDIT.md Known Overrides row): valid, fixed in I fixed the root cause as well. The actual workspace override was Both AUDIT.md statements were stale:
Both now name |
|
@CodeAnt-AI review |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf 'HEAD: '; git rev-parse --short HEAD
printf '\nReferenced files:\n'
fd -i '^(AUDIT\.md|CHANGELOG\.md|package\.json|pnpm-lock\.yaml|package-lock\.json|yarn\.lock)$' .
printf '\nOverride and documentation references:\n'
rg -n -C 3 'Known Overrides|accepted.risk|joi@18\.2\.9|wait-on@|>=18\.2\.(5|6) <19|\^18\.2\.1|raised floor' --glob 'AUDIT.md' --glob 'CHANGELOG.md' --glob 'package.json' --glob 'pnpm-lock.yaml' --glob 'package-lock.json' --glob 'yarn.lock' . | head -220Length of output: 15893 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf 'Workspace file:\n'; fd -i '^pnpm-workspace\.yaml$' .
printf '\nWorkspace override:\n'; rg -n -C 5 'joi:|overrides:' pnpm-workspace.yaml | head -90
printf '\nChangelog current entry:\n'; sed -n '1,65p' CHANGELOG.md
printf '\nAudit accepted-risk note:\n'; sed -n '140,145p' AUDIT.md
printf '\nAudit override row:\n'; sed -n '1855,1861p;1881,1886p' AUDIT.md
printf '\nLockfile header and dependency resolutions:\n'; sed -n '1,15p;15614,15633p' pnpm-lock.yamlLength of output: 13589
✏️ Learnings added
You are interacting with an AI system. |
CodeAnt Nitpicks1 code suggestion1. The new row contradicts the earlier accepted-risk note, which still documents
|
…on paths (PR #909) The accepted-risk note sits in the dated v1.24.0 section, so it returns to its original wording; the current joi state lives in the Known Overrides table, which now names both paths: the root devDependency wait-on@9.1.0 and wait-on@7.2.0 via jest-process-manager and @storybook/test-runner.
|
CodeAnt nitpicks on
@CodeAnt-AI review |
|
Question: codeant nitpicks on
review Answer:
No further issues are apparent from these questions. |
There was a problem hiding this comment.
No application code in the PR — skipped Code Health checks.
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
|
@CodeAnt-AI review |
|
CodeAnt nitpick on This contradicts the previous nitpick on
That is a P3 doc-consistency edit with no effect on the fix. It goes into the v1.29.1 release-prep PR, which edits AUDIT.md anyway, so the full CI matrix is not restarted here. The authoritative current state ( |
#909) The workspace override still admitted the affected joi 18.2.5 (>=18.2.5 <19); raise it to >=18.2.6 <19 so a later re-resolution cannot fall back to a GHSA-6h2x-m376-mqjq version. AUDIT.md's accepted-risk note and Known Overrides row named a stale ^18.2.1 range and old resolutions (joi 18.2.1, wait-on 9.0.10); both now match the override and lockfile.
…on paths (PR #909) The accepted-risk note sits in the dated v1.24.0 section, so it returns to its original wording; the current joi state lives in the Known Overrides table, which now names both paths: the root devDependency wait-on@9.1.0 and wait-on@7.2.0 via jest-process-manager and @storybook/test-runner.
fix(deps): resolve joi 18.2.9 for the wait-on dev tool (GHSA-6h2x-m376-mqjq)
v1.29.1 succeeds the signed v1.29.0 tag, whose tag-triggered CI/CD failed the enforced OSV scan on the development-only joi 18.2.5 (fixed by #909); its desktop release was cancelled before publication and the tag stays immutable. Version 1.29.1 in all five sync authorities; CHANGELOG 1.29.1 section with a candidate marker and a never-published note on 1.29.0; README/AUDIT/TODO truth; v1.29.0 outcome recorded and docs/RELEASE-V1.29.1-EVIDENCE.md added.
User description
User description
Part of #872.
Why
The tag-triggered CI/CD run 36618279795 for
v1.29.0failed its enforced Security Audit OSV scan:GHSA-6h2x-m376-mqjq/ CVE-2026-92599 (high):joi18.2.5, fixed in 18.2.6.wait-on9.1.0 →joi18.2.5. A second copy, 18.2.8 viawait-on7.2.0, was not affected.Reachability (evidence, not a waiver)
wait-onis only a CI/E2E tool that waits for a local server (ci.ymllines 948 and 1075,storybook-debug.yml). The three shipped v1.29.0 CycloneDX SBOMs, generated from the production dependency graph of the exact candidate, contain 0joiand 0wait-oncomponents.reactis present, which confirms the check itself works. So there is no shipped runtime exposure.The gate is still deterministic and enforced, so the fix does not add an ignore entry or change the scanner config.
Change
pnpm update joi --lockfile-only). Bothjoicopies now resolve to 18.2.9, which has no OSV record.joi: ">=18.2.5 <19"still admitted the affected 18.2.5. It is raised to">=18.2.6 <19", so a later re-resolution cannot fall back to an affected version.^18.2.1,joi18.2.1 andwait-on9.0.10. This was raised by CodeRabbit as an outside-diff comment.package.jsonandosv-scanner.toml. There is no ignore entry.Release disposition
The
v1.29.0tag (e0739537oncf72dc6d) is kept and not moved.GitHub Releasejob.ghcr.io/qnbs/worldscript-studio:1.29.0,:1.29and:latestto digestsha256:1f463bc6ba1e2544b9d8c2191814c3eff50c9add81cd81d3d3927be736b3fe2d, with OCI revisioncf72dc6d.nginxplus the staticdist/only (Dockerfile lines 22–28).joiexists only in the discarded builder stage.:1.29and:latestwill move to the v1.29.1 image, and:1.29.0stays as the record of the unpublished tag.Under the immutable-tag policy (the v1.28.5 → v1.28.6 precedent), the release continues as v1.29.1 after this fix and its resulting-main epoch.
Summary by Sourcery
Eliminate the vulnerable development-only
joiresolution while preserving enforced security scanning without adding an ignore.Bug Fixes:
joidependency used by CI and development tooling by updating both dependency paths tojoi18.2.9.Enhancements:
joioverride floor to 18.2.6 to prevent reintroduction of the affected version.Documentation:
joiversion, advisory information, and current dependency mappings.CodeAnt-AI Description
Update the CI dependency to a security-fixed Joi release
What Changed
joito 18.2.9 instead of affected older versions.wait-ondependency paths and the corrected versions.Impact
✅ OSV security scans pass for the wait-on dependency✅ Fewer vulnerable development-tool installations✅ Clearer dependency security records💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.