Skip to content

fix: bump adm-zip, fast-uri, js-yaml, sharp, hono and csv-parse to patched versions - #173

Open
devin-ai-integration[bot] wants to merge 5 commits into
mainfrom
devin/dep-vulns/2026-09-14
Open

devin-ai-integration[bot] wants to merge 5 commits into
mainfrom
devin/dep-vulns/2026-09-14

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Dependency vulnerability fixes (automated)

Generated by the Devin Dependency Security Vuln Fix automation run on 2026-10-05.
Change type: Minor/patch version bumps — manifest and lockfile changes, no source edits.

Warning

We're not just looking for a review like a normal PR. Security can offer this fix as a recommendation, but doesn't have the tooling or domain knowledge to safely verify changes like this end-to-end for each repo. Please review, test, and own deployment before merging. For more information: https://launchdarkly.atlassian.net/wiki/spaces/SEC/pages/5360943572/Dependency+Vulnerability+Remediation+with+Devin.

Findings addressed

Package Ecosystem Bump type Current → Target Severity Age Source(s) Advisory
fast-uri npm Patch 3.1.5 → 3.1.7 High 32d Dependabot, Wiz GHSA-5jgf-p345-68v8, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp, GHSA-f65p-4m7j-42xc
sharp npm Patch 0.35.3 → 0.35.4 High 24d Dependabot, Wiz GHSA-rgj7-g3m4-5g8c
js-yaml npm Patch 4.3.1 → 4.3.2 High 22d Dependabot, Wiz GHSA-2883-xcg3-v3hh
adm-zip npm Patch 0.6.0 → 0.6.1 High 16d Dependabot, Wiz GHSA-7q85-xj36-vmfc (also clears GHSA-j5f4-cc29-5x44 High and GHSA-p634-w6r4-rjp2 Moderate, published 2026-10-04)
csv-parse npm Patch 7.0.1 → 7.0.2 Moderate 26d Dependabot, Wiz GHSA-8cw4-87c7-c6xx
hono npm Patch 4.13.2 → 4.13.8 Moderate 25d Dependabot, Wiz GHSA-gqvv-2mrq-wpjv, GHSA-crvj-82cr-hjcx

All findings are dev-only, in evals/ and tests/ (csv-parse only in evals/). Transitives of promptfoo are pinned via npm overrides; lockfiles regenerated with --legacy-peer-deps (matches CI). Branch merged with current main on 2026-10-05. Supersedes the Dependabot PRs for these packages (#166, #167, #169, #171, #172, #175, #176, #178, #180).

Deferred / excluded findings

Verification

  • Install: ✅ npm ci --legacy-peer-deps in evals/ and tests/ (Node 24.19, npm 10.8)
  • Build: n/a (no build step)
  • Tests: ✅ python3 scripts/validate_skills.py (50 skills), python3 -m unittest discover -s tests (9 tests), python3 scripts/generate_catalog.py --check, cd evals && npm test (92 pass / 0 fail)
  • Lint: n/a (no lint configured)
  • CI note (2026-10-05): Evaluate onboarding scored 2/4 (below the 75% soft threshold), which cascades to Evaluate gate / Aggregate scores. This is LLM-graded eval variance, not this change: promptfoo 0.122.0, @anthropic-ai/claude-agent-sdk 0.3.220 and @anthropic-ai/sdk 0.115.0 are identical to main, and the same suite scored 4/4 on main's scheduled run the same morning. A re-run should clear it.

Link to Devin session: https://app.devin.ai/sessions/4f4ea84353124a54bfffa201ac3a7fb4
Open in Devin Desktop: https://app.devin.ai/desktop/session/4f4ea84353124a54bfffa201ac3a7fb4?variant=devin

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration devin-ai-integration Bot added automated-security-deps Automated dependency vulnerability remediation devin-pr exempt labels Sep 14, 2026
@devin-ai-integration
devin-ai-integration Bot requested review from a team September 14, 2026 13:07
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Skill eval results

Skill Before After Δ
agentcontrol/configs-create 100/100 (4/4) 75/100 (3/4) -25
agentcontrol/configs-update 80/100 (4/5) 100/100 (5/5) +20
agentcontrol/configs-variations 80/100 (4/5) 80/100 (4/5) no change
agentcontrol/tools 75/100 (3/4) 75/100 (3/4) no change
feature-flags/flag-and-release-change - 100/100 (4/4) new
feature-flags/flag-release - 100/100 (5/5) new
feature-flags/launchdarkly-flag-command - 100/100 (3/3) new
feature-flags/launchdarkly-flag-create 100/100 (3/3) 100/100 (4/4) no change
feature-flags/launchdarkly-flag-drift - 100/100 (4/4) new
feature-flags/should-flag-change - 100/100 (17/17) new
onboarding - 50/100 (2/4) new

Only suites whose source actually changed since their last recorded score were re-run. Soft-failing while we stabilise the baseline.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: remediate fast-uri dependency vulnerabilities in evals and tests workspaces fix: remediate npm dependency vulnerabilities in evals and tests workspaces Sep 21, 2026
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: remediate npm dependency vulnerabilities in evals and tests workspaces fix: bump adm-zip, fast-uri, js-yaml, sharp, hono and csv-parse to patched versions Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated-security-deps Automated dependency vulnerability remediation devin-pr exempt

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants