Skip to content

fix(deps): repair Go and frontend security dependencies - #473

Open
cristim wants to merge 3 commits into
mainfrom
fix/otel-sdk-security-platform
Open

cristim wants to merge 3 commits into
mainfrom
fix/otel-sdk-security-platform

Conversation

@cristim

@cristim cristim commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Repair the Go and frontend dependency findings that independently blocked the security gate.

  • Update OpenTelemetry SDK 1.44.0 to 1.45.0 and its required module closure for GO-2026-6505. Preserve all published provider pins.
  • Preserve the brace-expansion, fast-uri and moment repairs, then remove every vulnerable braces/micromatch path by updating the four necessary Jest, environment, types and ts-loader dependencies.
  • Migrate tests to supported jsdom Location behavior. A shared reload boundary preserves the eight existing native reload calls; real Chromium logout and cross-tab tests verify actual document reloads.

No scanner suppression, audit-policy change, workflow change or forced dependency resolution. The advisory finding does not establish exploitation in this application. Related dependency-policy tracking remains #165; this repair does not close that broader work.

Verification

Independent Astra approved exact combined commit 0f339e52887aa76c1724530867ebd648e5f84b33, tree 32f33d84dba9cb0f5ca84f6a0653ff022e2f9c40. The thirteen-file diff is exactly the previously reviewed Go repair plus the two separately reviewed frontend commits, replayed as 85fca77 and 0f339e5. Source and lock bytes match their reviewed originals; normal hooks passed.

Native macOS verification on the combined source:

  • Node 24.19.0: fresh npm ci, npm audit with zero findings, production build, typecheck and lint passed. Lint retains 125 existing warnings and no errors.
  • Jest: 92 suites, 3,000 tests passed and one existing skip; coverage policy unchanged.
  • CI-mode Chromium: all 54 tests passed. Both new reload probes fail when the real reload implementation is temporarily replaced by a no-op, then pass after restoration. These verify the reload boundary, not a complete authentication-revocation audit.
  • Go 1.26.6: actual server build and uncached scheduler/purchase race tests passed. Binary metadata confirms OTEL 1.45.0 and unchanged provider pins.
  • Root, e2e-module and actual server-binary scans passed against the same frozen advisory database used for the failing baseline. There are zero reachable or imported-package vulnerability findings; the pre-existing module-only GO-2026-5932 in unused x/crypto/openpgp remains reported without suppression.
  • Independent review reproduced combined source equivalence, binary metadata and scans, and the two compiled reload scenarios. Prior independent full frontend-suite evidence applies to identical source bytes.

Linux CI, including the actual shipped-image scan, must pass for this new head before merge. Native scans are not a substitute for that image gate.

Summary by CodeRabbit

  • Chores
    • Updated supporting libraries and test tools.
    • Improved coverage for sign-out and page reload behavior across tabs. No user-facing behavior changes are included in this release.

Select the patched SDK and its required module closure while preserving
the published provider pins and existing security gates.

Native macOS source and server-binary scans pass against the same frozen
advisory data that reports the pre-fix finding. Short race tests pass.
@cristim cristim added urgency/this-sprint Within the current sprint impact/internal Team-internal only triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm effort/s Hours type/security Security finding labels Oct 3, 2026
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 6c440feb-0968-4df8-b614-d800f88cb4d7
📥 Commits

Reviewing files that changed from the base of the PR and between 5b30fbc and 0f339e5.

📒 Files selected for processing (11)
  • frontend/package-lock.json
  • frontend/package.json
  • frontend/src/__tests__/archera.test.ts
  • frontend/src/__tests__/auth-mfa-login.test.ts
  • frontend/src/__tests__/auth.test.ts
  • frontend/src/__tests__/crosstab-session.test.ts
  • frontend/src/__tests__/navigation.test.ts
  • frontend/src/api/client.ts
  • frontend/src/auth.ts
  • frontend/src/utils.ts
  • frontend/tests-e2e/deeplink.spec.ts

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

Authentication and cross-tab sign-out flows now use a shared page-reload utility. Tests cover reload calls, browser path handling, logout, and cross-tab sign-out. Go and frontend development dependencies are also updated.

Changes

Page reload handling

Layer / File(s) Summary
Centralize authentication reload calls
frontend/src/utils.ts, frontend/src/auth.ts, frontend/src/api/client.ts
Adds reloadPage() and uses it after authentication actions and cross-tab sign-out.
Test reload calls and browser paths
frontend/src/__tests__/auth-mfa-login.test.ts, frontend/src/__tests__/auth.test.ts, frontend/src/__tests__/crosstab-session.test.ts, frontend/src/__tests__/archera.test.ts, frontend/src/__tests__/navigation.test.ts
Authentication tests mock reloadPage and check when it is called. Deeplink and navigation tests set paths through browser history and restore URL state.
Verify authentication reloads end to end
frontend/tests-e2e/deeplink.spec.ts
Adds end-to-end tests for logout reloads and cross-tab sign-out, including storage cleanup and checks for storage changes that do not reload the page.

Dependency updates

Layer / File(s) Summary
Update dependency versions
go.mod, frontend/package.json
Updates github.com/go-logr/logr, OpenTelemetry modules, Jest packages, and ts-loader.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant Auth
  participant ReloadPage
  participant Browser
  User->>Auth: Complete logout
  Auth->>ReloadPage: Call reloadPage()
  ReloadPage->>Browser: Reload current page
Loading

Merge Risk: ⚪ Minimal · up to 0f339

The authentication reload changes have no identified merge-blocking issue. Normal checks can proceed.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 9 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the dependency updates for Go and the frontend, including their security purpose.
Full details: Docstring Coverage

Explanation

Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 9 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@cristim

cristim commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Already reviewed the last commit. Use @coderabbitai full review to rerun a review of the entire changeset.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Update brace-expansion, fast-uri and moment within existing dependency
ranges to their patched releases. Keep the full npm audit gate intact.
- Upgrade the four Jest and loader roots retaining micromatch.
- Preserve browser reload behavior through a testable shared boundary.
- Migrate Location test setup for supported jsdom behavior and verify
  actual logout and cross-tab document reloads in Chromium.
@cristim cristim changed the title fix(deps): update OpenTelemetry SDK for GO-2026-6505 fix(deps): repair Go and frontend security dependencies Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/internal Team-internal only priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant