Skip to content

deps: batch low-risk CVE bumps (smol-toml, @grpc/grpc-js, brace-expansion, tinypool) - #135

Merged
alexb-openrouter merged 1 commit into
mainfrom
devin/cve-batch-2026-10-06
Oct 6, 2026
Merged

alexb-openrouter merged 1 commit into
mainfrom
devin/cve-batch-2026-10-06

Conversation

@alexb-openrouter

Copy link
Copy Markdown
Contributor

TL;DR

One PR for four patch/minor CVE Watch bumps. It clears 8 of the 10 bun audit findings without any major upgrades.

What changed?

No other lockfile entries changed. I generated the lockfile with the pinned bun@1.3.14, so it stays at lockfileVersion: 1. Every target version is more than 3 days old.

Not in this PR (major bumps, tracked on their own tickets): csv-parse 5.6.0 → 7.0.2 (SEC-415) and uuid (nested in @google-cloud/storage / modal).

Why?

The CVE Watch backlog is growing. These findings are vendored into openrouter-web under packages/bench-harness, so the fix has to land here first. After merge, run scripts/subtree-pull-bench-harness.sh in openrouter-web to close the vendored tickets.

How to test

  • bun install --frozen-lockfile passes
  • bun audit shows only csv-parse and uuid
  • bun run format:check && bun run check && bun run typecheck && bun test && bun run build all pass locally (1643 tests). format:check running cleanly also confirms oxfmt works with tinypool@2.1.2.

Reviewer focus

  • The tinypool override. It can be removed after oxfmt moves to >=0.68.0, which pins tinypool@2.1.2.

Checklist

  • Tests cover changed behavior
  • Public API or configuration changes are backward compatible, or the break is documented
  • Benchmark changes document dataset provenance and licensing
  • No credentials, private results, or restricted dataset contents are included
  • Documentation is updated where needed

Link to Devin session: https://openrouter.devinenterprise.com/sessions/72ed622a8d294e3482813aa7183ddd6f
Open in Devin Desktop: https://openrouter.devinenterprise.com/desktop/session/72ed622a8d294e3482813aa7183ddd6f?variant=devin
Requested by: @alexb-openrouter

@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access that start with 'Devin'.

  • Disable automatic comment, CI, and merge conflict monitoring

Original prompt from Alex

SYSTEM:
<latest_message>
Alex Bujduveanu (U0BFFJD2XR8) [ts=1791305311.088319]: @Devin the CVE watch backlog is growing. any way we can batch together some of the low risk benchmark related minor version bumps into one PR?
</latest_message>

=== BEGIN THREAD HISTORY (in #agents-platform) ===
Alex Bujduveanu (U0BFFJD2XR8) [ts=1791305311.088319]: @Devin the CVE watch backlog is growing. any way we can batch together some of the low risk benchmark related minor version bumps into one PR?
=== END THREAD HISTORY ===
Channel ID: C0BRLAQLVSA
Thread URL: https://openrouter.slack.com/archives/C0BRLAQLVSA/p1791305311088319?thread_ts=1791305311.088319&amp;cid=C0BRLAQLVSA

The <latest_message> is the message that you should use to guide your goals + task for this session, and you should use the rest of the slack thread as context.
A [ts=...] marker on a Slack message is that message's timestamp. To act on a specific message with the slack tool (e.g. adding an emoji reaction via the reaction command), pass that value as timestamp along with the Channel ID — no extra lookup call is needed.

@perry-the-pr-reviewer perry-the-pr-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving maintainer App lacks pull_requests:write on OpenRouterTeam, so this verdict is posted as a COMMENT downgrade — the review itself found no changes needed (✅ Approve-equivalent).

Perry's Review

Verdict: ✅ Approve-equivalent (posted as COMMENT — see note above) — clean, well-scoped security-bump PR clearing 8 of 10 bun audit findings with no API changes.

Risk: 🟢 Low

Risk assessment:

Dimension Severity Risk Reasoning
Implementation risk 🟩 Low Patch-level bumps at the advisories' patched versions; CI green including 1643 tests and format check.
Premise risk 🟩 Low Premise (CVE Watch backlog, fix must land in this repo before the vendored copy picks it up) is consistent with this repo's role as the upstream source.
Estimated impact 🟩 Low If wrong, the worst case is a benchmark-tooling regression caught by CI — revert is a single lockfile commit.
Risk Factor Severity Risk Reasoning
Reversibility 🟩 Low Reverting a lockfile bump is trivial.
Detectability 🟩 Low Regressions surface immediately in CI (format, typecheck, tests).
Blast radius 🟩 Low Dev/tooling deps plus one direct dep used only by benchmark dataset loaders.
Data integrity — None No persisted state touched.
Financial exposure — None No billing path.
Security and privacy exposure 🟩 Low The change itself reduces exposure; the tinypool RCE GHSAs are dev-tooling-reachable here.
Propagation 🟨🟨 Medium Vendored into openrouter-web — the PR correctly sequences landing here first, but the vendored copy stays stale until the subtree pull runs.
Availability — None No serving path.
Recovery cost 🟩 Low Single revert commit.
Time to correct 🟩 Low Any regression is caught by CI pre-merge.
Verification detail
  • All four target versions match the advisories' patched releases. smol-toml@1.9.0 is the first patched version for GHSA-r4xh-jqrq-34v2 (quadratic-time parse() on key lines — this repo parses benchmark TOML datasets through the direct smol-toml dependency, so it's a real consumption path, not just a lockfile entry). @grpc/grpc-js@1.14.5 ≥ 1.13.6 (GHSA-m9gg-hp2v-232j, high: unauthorized certs accepted as authorized). brace-expansion@5.0.12 ≥ 5.0.11 (three recursion/quadratic-time DoS GHSAs; dev-only via ultracite > glob > minimatch). tinypool@2.1.2 ≥ 2.1.1 (two critical prototype-pollution-to-RCE GHSAs; dev/tooling-only via oxfmt, no direct usage in source).
  • The overrides.tinypool entry is correct and minimal. oxfmt@0.62.0 pins tinypool@2.1.0 exactly (confirmed in the lockfile), so the override is the only way to get 2.1.2 without bumping the formatter. Removing it after oxfmt ≥ 0.68.0 is the right follow-up.
  • Diff is exactly the described change. 2 files, package.json and bun.lock in lockstep; no unrelated lockfile churn; smol-toml bump correctly dedupes modal's ^1.3.3 range onto 1.9.0.
  • CI: all four checks pass (validate, CodeQL, both Analyze runs). No existing review threads.

No findings to raise — nothing asked of the author beyond the follow-up the PR already tracks (SEC-543, drop the override once oxfmt ≥ 0.68.0). The excluded majors (csv-parse 5→7, nested uuid) are correctly deferred to their own tickets, with the vendoring follow-up noted on the downstream side once this lands.

What these risk factors mean

Each factor rates the potential consequence if anything about the change is wrong, from None to Critical between these two ends:

  • Reversibility — None: the previous state can be fully restored; Critical: what was lost or altered cannot be restored by any later action
  • Detectability — None: any problem is caught immediately by tests, alerts, or plain observation; Critical: a problem produces no signal and is found only after harm accumulates
  • Blast radius — None: a single contained component; Critical: every user, organization, or dependent system is affected
  • Data integrity — None: no persisted state is touched; Critical: persisted data is corrupted, lost, or made untrustworthy
  • Financial exposure — None: no billing/payment/accounting effect; Critical: incorrect charges, missed revenue, or unrecoverable spend
  • Security and privacy exposure — None: nothing sensitive is reachable from the change; Critical: credentials, personal data, or tenant isolation are compromised
  • Propagation — None: nothing else reads or builds on the affected output; Critical: downstream systems, records, or decisions absorb an error and carry it forward
  • Availability — None: cannot affect whether anything serves; Critical: a relied-on path stops serving
  • Recovery cost — None: rollback completes recovery; Critical: correction requires manual reconciliation, backfill, or customer remediation
  • Time to correct — None: corrected as soon as noticed; Critical: stays in effect through long investigation, coordination, or deployment cycles

@alexb-openrouter
alexb-openrouter merged commit e20970c into main Oct 6, 2026
4 checks passed
@alexb-openrouter
alexb-openrouter deleted the devin/cve-batch-2026-10-06 branch October 6, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants