Skip to content

[INFRA-1076] fix: clear the 2026-10-07 nightly npm Trivy findings - #9956

Merged
sriramveeraghanta merged 2 commits into
previewfrom
fix/infra-1076-trivy-nightly-2026-10-07
Oct 7, 2026
Merged

sriramveeraghanta merged 2 commits into
previewfrom
fix/infra-1076-trivy-nightly-2026-10-07

Conversation

@pratapalakshmi

@pratapalakshmi pratapalakshmi commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

New npm advisories published on 2026-10-05 and 2026-10-06 turned plane-live, plane-space and plane-aio-community red in the nightly scan. Every finding is in our own .pnpm tree.

  • Catalog: compression 1.8.1 → 1.8.2 and sharp ^0.35.4 → ^0.35.5.
  • The exact prosemirror-view override goes from 1.40.0 to 1.42.6 (CVE-2026-104847 is fixed in 1.42.3). prosemirror-model is pinned to 1.25.12 because 1.42.6 requires it, and this keeps the graph to one model copy.
  • New override floors:
  • compression: "catalog:" covers serve@14.2.5, which pins 1.8.1 exactly.
  • Lockfile: the only version moves are those packages plus the @img/sharp-* binaries.

Behaviour changes: the editor moves from prosemirror-view 1.40.0 to 1.42.6 and from prosemirror-model 1.25.3 to 1.25.12.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • Feature (non-breaking change which adds functionality)
  • Improvement (change that would cause existing functionality to not work as expected)
  • Code refactoring
  • Performance improvements
  • Documentation update

Screenshots and Media (if applicable)

N/A

Test Scenarios

Verified:

  • pnpm install --frozen-lockfile passes, and the supply-chain policy check passed on commit.
  • node_modules/.pnpm has exactly one copy of each fixed package at its fixed version.
  • turbo check:types --filter=live --filter=space --filter=@plane/editor passes (13/13 tasks).
  • live vitest passes. @plane/editor has no test script.
  • oxfmt --check is clean on live with tinypool 2.2.0.
  • sharp 0.35.5 loads natively.

Not verified:

  • Image rebuild and Trivy re-scan (no Docker locally).
  • trivy fs (trivy isn't installed).
  • Collaborative editing in a browser.

To clear the scan after merge:

  1. Run this repo's build-branch.yml so the preview tags are re-pushed.
  2. Re-run plane-ee's Nightly Docker Security Scan. Its Trivy log must show [vulndb] Need to update DB.

References

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated compatibility and maintenance settings. No user-facing feature changes are included in this update.

New advisories published 2026-10-05/06 turned plane-live, plane-space and
plane-aio-community red. Bump compression to 1.8.2 and sharp to ^0.35.5
in the catalog, bump the exact prosemirror-view override 1.40.0 -> 1.42.6
(with prosemirror-model 1.25.12 so the graph keeps one model copy), and
add override floors for proxy-addr 2.0.8, source-map-js 1.2.2 and
tinypool 2.1.2 (pinned to 2.1.0 by oxfmt 0.35.0). compression is forced
to the catalog because serve 14.2.5 pins 1.8.1 exactly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 06:50
@makeplane

makeplane Bot commented Oct 7, 2026

Copy link
Copy Markdown

Linked to Plane Work Item(s)

This comment was auto-generated by Plane

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b3090ed1-c841-482a-b064-64970a478c7e
📥 Commits

Reviewing files that changed from the base of the PR and between 3a72357 and 7906e39.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The workspace configuration updates the compression and sharp catalog versions, changes ProseMirror overrides, and adds overrides for compression, proxy-addr, source-map-js, and tinypool.

Changes

Workspace dependency updates

Layer / File(s) Summary
Update catalog pins and package overrides
pnpm-workspace.yaml
The catalog updates compression to 1.8.2 and sharp to ^0.35.5. Overrides update prosemirror-view to 1.42.6, pin prosemirror-model to 1.25.12, resolve compression through the catalog, and add bounded version ranges for proxy-addr, source-map-js, and tinypool.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: sriramveeraghanta

Merge Risk: ⚪ Minimal · up to 7906e

The checked-in dependency resolutions match the intended updates, and no actionable merge risk was identified.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the change as fixing npm Trivy findings from the October 7, 2026 nightly scan.
Description check ✅ Passed The description covers the dependency updates, reason for the changes, type of change, tests performed, unverified items, and references. It follows the repository template and clearly reports remaini…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The unverified collaborative-editor behavior and image-level Trivy scan warrant final human validation.

Review effort: Balanced
Findings: None

What changed in this PR

Updates vulnerable npm dependencies to clear nightly Trivy findings while preserving a single ProseMirror model instance.

Changes:

  • Upgrades compression, sharp, and ProseMirror packages.
  • Adds secure override floors for vulnerable transitive dependencies.
  • Regenerates the lockfile and Sharp platform binaries.
File Description
pnpm-workspace.yaml Updates catalog versions and security overrides.
pnpm-lock.yaml Resolves the dependency graph to patched versions.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Matches the pkg@major override convention and keeps a future tinypool 1.x
consumer off 2.x. Mirrors the review fix on makeplane/plane-ee#10123.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sriramveeraghanta
sriramveeraghanta merged commit d475cf4 into preview Oct 7, 2026
14 checks passed
@sriramveeraghanta
sriramveeraghanta deleted the fix/infra-1076-trivy-nightly-2026-10-07 branch October 7, 2026 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants