Repository navigation
deps: batch low-risk CVE bumps (smol-toml, @grpc/grpc-js, brace-expansion, tinypool) - #135
Conversation
|
I'll fix CI failures and address comments from users with write access that start with 'Devin'.
Original prompt from Alex
|
There was a problem hiding this comment.
Approving maintainer App lacks
pull_requests:writeon OpenRouterTeam, so this verdict is posted as a COMMENT downgrade — the review itself found no changes needed (✅ Approve-equivalent).
Perry's Review
Verdict: ✅ Approve-equivalent (posted as COMMENT — see note above) — clean, well-scoped security-bump PR clearing 8 of 10 bun audit findings with no API changes.
Risk: 🟢 Low
Risk assessment:
| Dimension | Severity | Risk | Reasoning |
|---|---|---|---|
| Implementation risk | 🟩 | Low | Patch-level bumps at the advisories' patched versions; CI green including 1643 tests and format check. |
| Premise risk | 🟩 | Low | Premise (CVE Watch backlog, fix must land in this repo before the vendored copy picks it up) is consistent with this repo's role as the upstream source. |
| Estimated impact | 🟩 | Low | If wrong, the worst case is a benchmark-tooling regression caught by CI — revert is a single lockfile commit. |
| Risk Factor | Severity | Risk | Reasoning |
|---|---|---|---|
| Reversibility | 🟩 | Low | Reverting a lockfile bump is trivial. |
| Detectability | 🟩 | Low | Regressions surface immediately in CI (format, typecheck, tests). |
| Blast radius | 🟩 | Low | Dev/tooling deps plus one direct dep used only by benchmark dataset loaders. |
| Data integrity | — | None | No persisted state touched. |
| Financial exposure | — | None | No billing path. |
| Security and privacy exposure | 🟩 | Low | The change itself reduces exposure; the tinypool RCE GHSAs are dev-tooling-reachable here. |
| Propagation | 🟨🟨 | Medium | Vendored into openrouter-web — the PR correctly sequences landing here first, but the vendored copy stays stale until the subtree pull runs. |
| Availability | — | None | No serving path. |
| Recovery cost | 🟩 | Low | Single revert commit. |
| Time to correct | 🟩 | Low | Any regression is caught by CI pre-merge. |
Verification detail
- All four target versions match the advisories' patched releases.
smol-toml@1.9.0is the first patched version for GHSA-r4xh-jqrq-34v2 (quadratic-timeparse()on key lines — this repo parses benchmark TOML datasets through the directsmol-tomldependency, so it's a real consumption path, not just a lockfile entry).@grpc/grpc-js@1.14.5≥ 1.13.6 (GHSA-m9gg-hp2v-232j, high: unauthorized certs accepted as authorized).brace-expansion@5.0.12≥ 5.0.11 (three recursion/quadratic-time DoS GHSAs; dev-only viaultracite > glob > minimatch).tinypool@2.1.2≥ 2.1.1 (two critical prototype-pollution-to-RCE GHSAs; dev/tooling-only viaoxfmt, no direct usage in source). - The
overrides.tinypoolentry is correct and minimal.oxfmt@0.62.0pinstinypool@2.1.0exactly (confirmed in the lockfile), so the override is the only way to get 2.1.2 without bumping the formatter. Removing it afteroxfmt≥ 0.68.0 is the right follow-up. - Diff is exactly the described change. 2 files,
package.jsonandbun.lockin lockstep; no unrelated lockfile churn;smol-tomlbump correctly dedupesmodal's^1.3.3range onto 1.9.0. - CI: all four checks pass (validate, CodeQL, both Analyze runs). No existing review threads.
No findings to raise — nothing asked of the author beyond the follow-up the PR already tracks (SEC-543, drop the override once oxfmt ≥ 0.68.0). The excluded majors (csv-parse 5→7, nested uuid) are correctly deferred to their own tickets, with the vendoring follow-up noted on the downstream side once this lands.
What these risk factors mean
Each factor rates the potential consequence if anything about the change is wrong, from None to Critical between these two ends:
- Reversibility — None: the previous state can be fully restored; Critical: what was lost or altered cannot be restored by any later action
- Detectability — None: any problem is caught immediately by tests, alerts, or plain observation; Critical: a problem produces no signal and is found only after harm accumulates
- Blast radius — None: a single contained component; Critical: every user, organization, or dependent system is affected
- Data integrity — None: no persisted state is touched; Critical: persisted data is corrupted, lost, or made untrustworthy
- Financial exposure — None: no billing/payment/accounting effect; Critical: incorrect charges, missed revenue, or unrecoverable spend
- Security and privacy exposure — None: nothing sensitive is reachable from the change; Critical: credentials, personal data, or tenant isolation are compromised
- Propagation — None: nothing else reads or builds on the affected output; Critical: downstream systems, records, or decisions absorb an error and carry it forward
- Availability — None: cannot affect whether anything serves; Critical: a relied-on path stops serving
- Recovery cost — None: rollback completes recovery; Critical: correction requires manual reconciliation, backfill, or customer remediation
- Time to correct — None: corrected as soon as noticed; Critical: stays in effect through long investigation, coordination, or deployment cycles
TL;DR
One PR for four patch/minor CVE Watch bumps. It clears 8 of the 10
bun auditfindings without any major upgrades.What changed?
smol-toml1.8.0→1.9.0(direct dep;modal's copy dedupes onto it) – GHSA-r4xh-jqrq-34v2 – SEC-535@grpc/grpc-js1.14.4→1.14.5(lockfile only, viamodal > nice-grpc) – GHSA-m9gg-hp2v-232j, GHSA-f596-whhp-79r4 – SEC-491brace-expansion5.0.9→5.0.12(lockfile only, dev viaultracite > glob > minimatch) – GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr – SEC-476tinypool2.1.0→2.1.2through a newoverridesentry.oxfmt@0.62.0pinstinypoolexactly, so this avoids bumping the formatter. – GHSA-5gmw-xhrv-c9v3, GHSA-85c8-ppgw-ccpr – SEC-543No other lockfile entries changed. I generated the lockfile with the pinned
bun@1.3.14, so it stays atlockfileVersion: 1. Every target version is more than 3 days old.Not in this PR (major bumps, tracked on their own tickets):
csv-parse5.6.0→7.0.2(SEC-415) anduuid(nested in@google-cloud/storage/modal).Why?
The CVE Watch backlog is growing. These findings are vendored into openrouter-web under
packages/bench-harness, so the fix has to land here first. After merge, runscripts/subtree-pull-bench-harness.shin openrouter-web to close the vendored tickets.How to test
bun install --frozen-lockfilepassesbun auditshows onlycsv-parseanduuidbun run format:check && bun run check && bun run typecheck && bun test && bun run buildall pass locally (1643 tests).format:checkrunning cleanly also confirmsoxfmtworks withtinypool@2.1.2.Reviewer focus
tinypooloverride. It can be removed afteroxfmtmoves to>=0.68.0, which pinstinypool@2.1.2.Checklist
Link to Devin session: https://openrouter.devinenterprise.com/sessions/72ed622a8d294e3482813aa7183ddd6f
Open in Devin Desktop: https://openrouter.devinenterprise.com/desktop/session/72ed622a8d294e3482813aa7183ddd6f?variant=devin
Requested by: @alexb-openrouter