Skip to content

chore(deps): npm audit fix for transitive vulnerabilities#1113

Merged
bert-e merged 1 commit into
development/1.0from
improvement/npm-audit-fixes
May 21, 2026
Merged

chore(deps): npm audit fix for transitive vulnerabilities#1113
bert-e merged 1 commit into
development/1.0from
improvement/npm-audit-fixes

Conversation

@JeanMarcMilletScality

Copy link
Copy Markdown
Contributor

Summary

Runs npm audit fix against the latest development/1.0 (which already includes the merged uuid v14 bump from #1092). Only package-lock.json is touched — no direct dependencies in package.json changed.

Resolves 4 vulnerabilities → 0:

Package Severity Advisory
@babel/plugin-transform-modules-systemjs high GHSA-fv7c-fp4j-7gwp
fast-uri high GHSA-q3j6-qgpj-74h6, GHSA-v39h-62p7-jpjc
brace-expansion moderate GHSA-jxxr-4gwj-5jf2
ws moderate GHSA-58qx-3vcg-4xpx

This supersedes #1105 (fast-uri) and #1106 (@babel/plugin-transform-modules-systemjs).

Why the Dependabot PRs failed the claude-review check

Both #1105 and #1106 had passing tests, CodeQL, and dependency-review — only the review / claude-review job failed with:

Secret GCP_WORKLOAD_IDENTITY_PROVIDER is required, but not provided while calling.
Secret GCP_SERVICE_ACCOUNT is required, but not provided while calling.
Secret ANTHROPIC_VERTEX_PROJECT_ID is required, but not provided while calling.
Secret CLOUD_ML_REGION is required, but not provided while calling.

Root cause: GitHub runs Dependabot-triggered workflows in a restricted security context. GITHUB_TOKEN is read-only, and regular Actions secrets are not exposed, even when the workflow uses secrets: inherit (as .github/workflows/review.yml does). The reusable workflow scality/workflows/.github/workflows/claude-code-review.yml@v2 requires those four GCP/Vertex secrets, so it errors out before running. Because the job fails at the workflow-evaluation stage, branch protection treats the PR as failing even though the actual CI is green.

Potential fixes

  1. Mirror the secrets into the Dependabot scope (recommended). In Settings → Secrets and variables → Dependabot (a separate scope from Actions), add the same four secrets. Dependabot-triggered runs will then have access.
  2. Skip the review job for Dependabot PRs. In .github/workflows/review.yml, add if: github.actor != 'dependabot[bot]' on the review job so it is simply not invoked for Dependabot PRs (it will not show as failed either).
  3. Make claude-review non-blocking in branch protection. Remove it from required checks so a failure does not block merging; manual review still happens via comments.
  4. Trigger review via pull_request_target instead of pull_request. This runs in the base-repo context with access to secrets, but it carries supply-chain risks for untrusted PRs and is not recommended unless tightly scoped.

Option 1 is the cleanest if the goal is to keep the Claude review running on Dependabot PRs. Option 2 is the quickest if it isn't needed there.

Test plan

  • npm install clean
  • npm audit reports 0 vulnerabilities
  • npm run build succeeds
  • npm test — 436/436 tests pass across 35 suites
  • CI green on this PR

🤖 Generated with Claude Code

Resolves 4 advisories via package-lock.json bumps only:
- @babel/plugin-transform-modules-systemjs (GHSA-fv7c-fp4j-7gwp, high)
- fast-uri (GHSA-q3j6-qgpj-74h6, GHSA-v39h-62p7-jpjc, high)
- brace-expansion (GHSA-jxxr-4gwj-5jf2, moderate)
- ws (GHSA-58qx-3vcg-4xpx, moderate)

Supersedes dependabot PRs #1105 and #1106 which were blocked by the
claude-review check (Dependabot PRs cannot access Actions secrets).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@bert-e

bert-e commented May 21, 2026

Copy link
Copy Markdown
Contributor

Hello jeanmarcmilletscality,

My role is to assist you with the merge of this
pull request. Please type @bert-e help to get information
on this process, or consult the user documentation.

Available options
name description privileged authored
/after_pull_request Wait for the given pull request id to be merged before continuing with the current one.
/bypass_author_approval Bypass the pull request author's approval
/bypass_build_status Bypass the build and test status
/bypass_commit_size Bypass the check on the size of the changeset TBA
/bypass_incompatible_branch Bypass the check on the source branch prefix
/bypass_jira_check Bypass the Jira issue check
/bypass_peer_approval Bypass the pull request peers' approval
/bypass_leader_approval Bypass the pull request leaders' approval
/approve Instruct Bert-E that the author has approved the pull request. ✍️
/create_pull_requests Allow the creation of integration pull requests.
/create_integration_branches Allow the creation of integration branches.
/no_octopus Prevent Wall-E from doing any octopus merge and use multiple consecutive merge instead
/unanimity Change review acceptance criteria from one reviewer at least to all reviewers
/wait Instruct Bert-E not to run until further notice.
Available commands
name description privileged
/help Print Bert-E's manual in the pull request.
/status Print Bert-E's current status in the pull request TBA
/clear Remove all comments from Bert-E from the history TBA
/retry Re-start a fresh build TBA
/build Re-start a fresh build TBA
/force_reset Delete integration branches & pull requests, and restart merge process from the beginning.
/reset Try to remove integration branches unless there are commits on them which do not appear on the source branch.

Status report is not available.

@bert-e

bert-e commented May 21, 2026

Copy link
Copy Markdown
Contributor

Waiting for approval

The following approvals are needed before I can proceed with the merge:

  • the author

  • one peer

Peer approvals must include at least 1 approval from the following list:

@JeanMarcMilletScality

Copy link
Copy Markdown
Contributor Author

/approve

@bert-e

bert-e commented May 21, 2026

Copy link
Copy Markdown
Contributor

Waiting for approval

The following approvals are needed before I can proceed with the merge:

  • the author

  • one peer

Peer approvals must include at least 1 approval from the following list:

The following options are set: approve

@bert-e

bert-e commented May 21, 2026

Copy link
Copy Markdown
Contributor

In the queue

The changeset has received all authorizations and has been added to the
relevant queue(s). The queue(s) will be merged in the target development
branch(es) as soon as builds have passed.

The changeset will be merged in:

  • ✔️ development/1.0

There is no action required on your side. You will be notified here once
the changeset has been merged. In the unlikely event that the changeset
fails permanently on the queue, a member of the admin team will
contact you to help resolve the matter.

IMPORTANT

Please do not attempt to modify this pull request.

  • Any commit you add on the source branch will trigger a new cycle after the
    current queue is merged.
  • Any commit you add on one of the integration branches will be lost.

If you need this pull request to be removed from the queue, please contact a
member of the admin team now.

The following options are set: approve

@bert-e

bert-e commented May 21, 2026

Copy link
Copy Markdown
Contributor

I have successfully merged the changeset of this pull request
into targetted development branches:

  • ✔️ development/1.0

Please check the status of the associated issue None.

Goodbye jeanmarcmilletscality.

@bert-e bert-e merged commit ee25c54 into development/1.0 May 21, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants