Skip to content

chore: sync main into main-convert + fold in the dependency advisory work - #426

Open
abbaseya wants to merge 14 commits into
main-convertfrom
sync/merge-main-into-main-convert
Open

chore: sync main into main-convert + fold in the dependency advisory work#426
abbaseya wants to merge 14 commits into
main-convertfrom
sync/merge-main-into-main-convert

Conversation

@abbaseya

@abbaseya abbaseya commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

Brings main-convert fully up to date with main, and carries the dependency work that has
landed since.

What's in it

mainmain-convert sync everything on main as of now, including #424 (tar / shell-quote CVEs) and #421 (supply-chain minimum-release-age gate)
#427 (merged to main) the dependency upgrade — 236 advisories → 41, 0 critical
#429 (open against main) the follow-up resolutions — 41 → 28, and packages/*-reachable advisories to zero

After this merges, main-convert and main are level on dependencies, and main-convert has no
open advisories reachable from any published package.

The #429 commit (5cb9797) is included here by the same sha, so there is no duplication when
#429 merges to main separately.

No published package changes

peerDependencies are byte-identical to main in all 11 packages, and no dependencies move.
Only devDependencies, the root resolutions block, and the lockfile differ.

Every commit is chore(...) — deliberately no feat / fix prefix — so release-please does not
cut a release off this.

Verified at 5cb9797

  • yarn install --immutable — passes
  • yarn build at the repo root — 50 bundles, exit 0
  • yarn lint in packages/js-sdk — clean
  • yarn test:mocha across all 10 test packages — 546 passing, 0 failing
  • yarn test:browser in packages/js-sdk47 passed

Known, pre-existing, not fixed here

  • Repo-root yarn lint is red in packages/types (generated src/config/types.gen.ts). Present
    on main too; pass-qa only lints packages/js-sdk, so CI has never exercised it.
  • yarn build rewrites each package's source package.json (generate-rollup-config.mjs pins
    peerDependencies to sibling workspace versions), so any build leaves a dirty tree. That churn
    was stripped before committing.

🤖 Generated with Claude Code

Ahmed Abbas and others added 8 commits July 24, 2026 18:26
…e qa install

Supply-chain hardening (Asana 1216667157595351):
- .yarnrc.yml: npmMinimalAgeGate 4320 (3 days) + npmPreapprovedPackages
  @convertcom/* — Yarn refuses to install a dependency version younger than
  3 days (the smash-and-grab filter), exempting our internal scope.
- qa.yml: freeze the dependency install (yarn -> yarn install --immutable) so
  CI installs strictly from the committed lockfile.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
chore(ci): supply-chain minimum-release-age gate + Renovate onboarding
Adds two entries to the root `resolutions` block, matching the existing
pattern used for security force-bumps.

tar was pinned at 6.2.1 (via ^6.1.11 / ^6.1.2 from cacache and node-gyp)
and shell-quote at 1.8.1 (via browserify, launch-editor, outpipe and
react-dev-utils). Both are dev-time tooling only — neither appears in any
published package's runtime dependencies.

Resolves:
  - CVE-2026-59873 / GHSA-23hp-3jrh-7fpw  CRITICAL  tar          <= 7.5.18
  - CVE-2026-59874 / GHSA-8x88-c5mf-7j5w  HIGH      tar          <= 7.5.17
  - CVE-2026-13311 / GHSA-395f-4hp3-45gv  HIGH      shell-quote  <= 1.8.4

There is no patched tar 6.x — the vulnerable range covers all of 6.x, so
this is a forced 6 -> 7 major bump.

The floor is >=7.5.21 rather than 7.5.19 because GHSA-r292-9mhp-454m
(published 2026-07-24, vulnerable <= 7.5.20) is first patched in 7.5.21.
Yarn resolves tar 7.5.21 rather than the newer 7.5.22, which is still
inside the repo's npmMinimalAgeGate window; 7.5.21 clears all advisories.

Verified: yarn build, yarn test (546 passing / 0 failing),
packages/js-sdk lint, and yarn install --immutable all pass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…e-cve-fix

chore(deps): force tar >=7.5.21 and shell-quote >=1.9.0 to clear CVEs
Takes the repo from 236 open advisories (3 critical / 105 high) to 41
(0 critical / 11 high), measured with `yarn npm audit --all --recursive`.

No published package is affected either way: every packages/* manifest
declares an empty `dependencies` apart from js-sdk-utils -> murmurhash,
so the alerts all trace to the demo apps and dev tooling.

- lockfile re-resolution (`yarn up -R`) clears 151 advisories on its own,
  with no manifest edits
- next 16.0.1 -> 16.3.0 clears the last critical (React flight RCE)
- wrangler 3 -> 4, @nestjs/* -> 11.1.28, @remix-run/* -> 2.17.5,
  react-router-dom -> 7.18.2, nyc -> 18
- chai 4 -> 6 across every test package

chai >=5 exports a sealed ES module namespace, so `chai.use(spies)` can
no longer attach `.spy` in place. The event tests now capture what
`use()` returns instead. All 546 mocha tests pass.

The 41 remaining advisories sit behind parents that are already at their
latest published version: react-scripts@5.0.1 (14), @remix-run v2 (9),
the jsdoc/better-docs chain (8), wrangler -> miniflare -> undici (5),
mocha/nyc/browserify internals (5).

Known issue, not yet resolved: `yarn build` fails on packages/enums in
this state - rollup-plugin-typescript2 stops resolving relative imports
after the recursive lockfile refresh. Ruled out rollup, plugin-commonjs,
plugin-terser, glob, rollup-plugin-dts, dotenv, tslib, typescript, a
stale rpt2 cache and the @types auto-inclusion; the culprit is not yet
pinpointed. The test suite stays green through it, so tests alone do not
catch this.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The recursive lockfile refresh in the previous commit broke `yarn build`:
rollup-plugin-typescript2 silently stopped transforming and resolving,
so rollup fell back to parsing raw TypeScript as JavaScript. Symptoms
differed per package - `Could not resolve "./src/..."` in enums, and
`Expected ',', got ':'` in js-sdk - but both are the same plugin going
inert.

Bisected on a pristine clone with a single variable: `yarn up -R
picomatch` on its own takes the build from passing to failing.
picomatch 2.3.1 -> 2.3.2 is itself a required security bump (4 advisories),
so pinning it back is not an option.

rollup-plugin-typescript2 0.37.0 works with picomatch 2.3.2, so the fix
is to move the plugin forward rather than hold the transitive back.

Verified after the change:
- `yarn build` at the repo root: 50 bundles, exit 0
- `yarn lint` in packages/js-sdk: clean
- all 546 mocha tests across the 10 test packages: passing
- advisories unchanged at 41 (0 critical, 11 high), down from 236

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
abbaseya and others added 6 commits August 8, 2026 18:51
`yarn install --immutable` failed in CI (`pass-qa`) with YN0028: the
lockfile disagreed with the manifests.

Two defects, both mine:

1. The `yarn up` runs in the earlier commits rewrote `peerDependencies`
   across all 11 published packages as a side effect - tightening ranges
   like `@convertcom/js-sdk-types: ">=3.11.0"` to `">=4.0.0"` to match
   current workspace majors. That is a breaking change for consumers on
   older majors, and the exact opposite of what this branch claims: no
   published package should change at all here. All 47 peer ranges are
   restored to their `main-convert` values.

2. The lockfile was left internally inconsistent - yarn had rewritten the
   `packages/js-sdk` workspace entry's peer ranges but not the other ten,
   because it only rewrites entries it re-resolves. Resynced against the
   corrected manifests.

Only `devDependencies` differ from `main-convert` now, which is what the
advisory work actually needed.

Verified at this commit:
- `yarn install --immutable` - passes (the CI step that failed)
- `yarn build` at the repo root - 50 bundles, exit 0
- `yarn lint` in packages/js-sdk - clean
- 546 mocha tests across 10 packages - passing
- 47 browser tests - passing

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`pass-qa` still failed on `yarn install --immutable` (YN0028) after the
previous fix, because I had misdiagnosed the cause.

`generate-rollup-config.mjs` rewrites each package's **source**
`package.json` on every build, pinning `peerDependencies` to the current
sibling workspace versions:

    peerDependencies: {...info.peerDependencies, ...peerDependencies}
    writeFileSync(resolve(`${basePath}/package.json`), ...)

So `yarn build` - not `yarn up` - is what turned ranges like
`@convertcom/js-sdk-types: ">=3.11.0"` into `">=4.0.0"`. Running the
verification build and then `git add -A` swept that mutation into the
commit, while the lockfile still carried the ranges from before it. CI
installs before it builds, so a clean checkout disagrees with the
committed manifests every time.

All 47 peer ranges are back to their `main-convert` values and the
lockfile matches them. Only `devDependencies` differ from `main-convert`
now, which is all the advisory work needed - no published package
changes.

Note for whoever picks this up: the build mutating tracked source files
means any `yarn build` leaves a dirty tree. Worth separating the
generated `lib/package.json` from the source manifest, but that is out of
scope here.

Verified at this commit, with no build run afterwards:
- `yarn install --immutable` - passes (the failing CI step)
- peerDependencies byte-identical to origin/main-convert in all 11 packages

Build and test results from the same dependency state, before the
restore: 50 bundles, 546 mocha tests, 47 browser tests, lint clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
chore(deps): clear 195 of 236 dependency advisories (0 critical left)
Takes the repo from 41 open advisories (11 high) to 28 (6 high). More
usefully: advisories reachable from `packages/*` go from 8 to **zero**.
Everything still open is inside a `demo/*` app, which no CI job builds or
tests.

These were previously written off as needing the parent tool replaced.
That was wrong - the patched versions exist, they just fall outside the
range the parent declares, which is exactly what `resolutions` is for.
This repo already used it 14 times; this adds 7 more.

Four of them had no upstream fix at all, and are gone because the thing
that pulled them is gone:

- `jsdoc` ^4.0.5 - jsdoc 4 dropped `taffydb` (the only high in the SDK's
  own tree) and brings `markdown-it` 14 / `linkify-it` 5 with it
- `vue-docgen-api` ^4.79.2 - drops `vue-template-compiler` (Vue 2, EOL,
  no fix will ever ship)
- `browserify` + `watchify` removed from packages/js-sdk - no script in
  the repo references either, and they were the only path to `elliptic`
  (no upstream fix) and `bn.js`

The rest are straightforward forced bumps: `serialize-javascript` >=7.0.5,
`diff` >=8.0.3, `pug` / `pug-code-gen` >=3.0.3, `underscore` >=1.13.8.

Deliberately no `feat`/`fix` prefix - this is tooling only and must not
cut a release. No published package changes: `peerDependencies` are
byte-identical to `main` in all 11 packages, and no `dependencies` move.

Verified at this commit:
- `yarn install --immutable` - passes
- `yarn build` at the repo root - 50 bundles, exit 0
- `yarn lint` in packages/js-sdk - clean
- 546 mocha tests across 10 packages - passing
- 47 browser tests - passing

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@abbaseya abbaseya changed the title chore: merge main into main-convert chore: sync main into main-convert + fold in the dependency advisory work Aug 9, 2026
@sonarqubecloud

sonarqubecloud Bot commented Aug 9, 2026

Copy link
Copy Markdown

@abbaseya abbaseya self-assigned this Aug 9, 2026
@abbaseya
abbaseya requested review from a team and removed request for a team August 9, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants