Repository navigation
[INFRA-1076] fix: clear the 2026-10-07 nightly npm Trivy findings - #9956
Conversation
New advisories published 2026-10-05/06 turned plane-live, plane-space and plane-aio-community red. Bump compression to 1.8.2 and sharp to ^0.35.5 in the catalog, bump the exact prosemirror-view override 1.40.0 -> 1.42.6 (with prosemirror-model 1.25.12 so the graph keeps one model copy), and add override floors for proxy-addr 2.0.8, source-map-js 1.2.2 and tinypool 2.1.2 (pinned to 2.1.0 by oxfmt 0.35.0). compression is forced to the catalog because serve 14.2.5 pins 1.8.1 exactly. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Linked to Plane Work Item(s) This comment was auto-generated by Plane |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe workspace configuration updates the ChangesWorkspace dependency updates
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The checked-in dependency resolutions match the intended updates, and no actionable merge risk was identified. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The unverified collaborative-editor behavior and image-level Trivy scan warrant final human validation.
Review effort: Balanced
Findings: None
What changed in this PR
Updates vulnerable npm dependencies to clear nightly Trivy findings while preserving a single ProseMirror model instance.
Changes:
- Upgrades
compression,sharp, and ProseMirror packages. - Adds secure override floors for vulnerable transitive dependencies.
- Regenerates the lockfile and Sharp platform binaries.
| File | Description |
|---|---|
pnpm-workspace.yaml |
Updates catalog versions and security overrides. |
pnpm-lock.yaml |
Resolves the dependency graph to patched versions. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Matches the pkg@major override convention and keeps a future tinypool 1.x consumer off 2.x. Mirrors the review fix on makeplane/plane-ee#10123. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Description
New npm advisories published on 2026-10-05 and 2026-10-06 turned
plane-live,plane-spaceandplane-aio-communityred in the nightly scan. Every finding is in our own.pnpmtree.compression1.8.1 → 1.8.2 andsharp^0.35.4 → ^0.35.5.prosemirror-viewoverride goes from 1.40.0 to 1.42.6 (CVE-2026-104847 is fixed in 1.42.3).prosemirror-modelis pinned to 1.25.12 because 1.42.6 requires it, and this keeps the graph to one model copy.proxy-addr>=2.0.8 (CVE-2026-90711, critical)source-map-js>=1.2.2 (CVE-2026-93749)tinypool>=2.1.2 (CVE-2026-104848/104849, critical). It is pinned to 2.1.0 byoxfmt@0.35.0.compression: "catalog:"coversserve@14.2.5, which pins 1.8.1 exactly.@img/sharp-*binaries.Behaviour changes: the editor moves from prosemirror-view 1.40.0 to 1.42.6 and from prosemirror-model 1.25.3 to 1.25.12.
Type of Change
Screenshots and Media (if applicable)
N/A
Test Scenarios
Verified:
pnpm install --frozen-lockfilepasses, and the supply-chain policy check passed on commit.node_modules/.pnpmhas exactly one copy of each fixed package at its fixed version.turbo check:types --filter=live --filter=space --filter=@plane/editorpasses (13/13 tasks).@plane/editorhas no test script.oxfmt --checkis clean on live with tinypool 2.2.0.Not verified:
trivy fs(trivy isn't installed).To clear the scan after merge:
build-branch.ymlso thepreviewtags are re-pushed.[vulndb] Need to update DB.References
🤖 Generated with Claude Code
Summary by CodeRabbit