Skip to content

chore(deps): apply safe security and patch upgrades - #1

Draft
MoneyPack with Copilot wants to merge 5 commits into
mainfrom
copilot/review-and-recommend-better
Draft

MoneyPack with Copilot wants to merge 5 commits into
mainfrom
copilot/review-and-recommend-better

Conversation

Copilot AI commented Oct 5, 2026

Copy link
Copy Markdown

Applies the non-breaking tier of dependency upgrades identified in the repo audit.

Security (transitive, via npm audit fix)

  • undici — clears 5 high-severity advisories (DoS via WebSocket decompression, TLS cert validation bypass in BalancedPool, cross-user cookie disclosure, response splitting/truncation)
  • brace-expansion — clears quadratic-DoS / stack-exhaustion advisories (electron-builder tree)
  • fast-uri, http-cache-semantics — clears high-severity authority-injection and cache-disclosure advisories

Direct dependency bumps

Package From To Scope
electron 44.0.0 44.5.1 Root shell; exact pin, patch release carrying Chromium security fixes
@opentui/core 0.5.9 0.5.14 TUI package; exact pin, patch
@opentui/keymap 0.5.9 0.5.14 TUI package; exact pin, patch

Lockfile refresh also resolves vitest to 3.2.7 (top of declared ^3.2.4 range) and picks up other in-range transitive updates.

Deliberately deferred

  • vitest 3 → 5 (plus coordinated vite 8 / jsdom 30): the only remaining advisories are 2 moderate @vitest/mocker path-traversal findings whose fix requires the vitest 5 breaking upgrade — warrants its own PR with config review.
  • Theia 1.75.0 → 1.76.0: per docs/upgrade-and-distribution.md, Theia+Electron pins move together on a quarterly cadence; currently one minor behind, within policy.
  • TypeScript 7: new compiler toolchain; ecosystem support immature.
  • Theia-host Electron 42.x: peer-locked to the Theia pin.

Verification

npm run typecheck, full unit suite (53 files / 693 passed / 2 skipped), and production build all green.

Copilot AI and others added 5 commits September 17, 2026 17:30
Co-authored-by: MoneyPack <254515835+MoneyPack@users.noreply.github.com>
…add electron-security-policy package, mission-kernel manifest, CI workflow, and upgrade policy

Co-authored-by: MoneyPack <254515835+MoneyPack@users.noreply.github.com>
…latform test fixes, frontend hardening, behavioral Theia tests

Co-authored-by: MoneyPack <254515835+MoneyPack@users.noreply.github.com>
Co-authored-by: MoneyPack <254515835+MoneyPack@users.noreply.github.com>
Co-authored-by: MoneyPack <254515835+MoneyPack@users.noreply.github.com>
@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 38d4202b4ae33f1d8c0bd4e0373fbcf0ae60cc97

Security scanner evidence required (action_required)

Detected 1 security-sensitive predictive risk signal(s) without scanner evidence.

Mode: enforce

Findings:

  • Security-sensitive changes may ship without scanner evidence: The PR touches billing, secrets, auth, webhooks, agent, or CI-sensitive surfaces without adding obvious security scanner, code scanning, or security-focused validation evidence. (1 security-sensitive paths changed; 0 security scanner or security-focused validation artifacts changed)

Touched security-sensitive paths:

  • electron/policy.ts

Expected evidence:

  • Security scanner, code scanning, secret scanning, dependency/security review, or focused security regression output.
  • SARIF/code-scanning upload or equivalent pass/fail gate for the changed surface.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
orrery Ready Ready Preview Oct 5, 2026 8:15pm UTC

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 38d4202b4ae33f1d8c0bd4e0373fbcf0ae60cc97

PR taxonomy review recommended (neutral)

Detected 3 PR taxonomy bucket(s): Security Evidence, Install Manifest Integrity, CI/CD Recommendation.

Scanned 53 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • Auth or permission changes may ship without security regression coverage
  • Security-sensitive changes may ship without scanner evidence
  • 4 security-sensitive path(s) changed

Paths:

  • .github/workflows/ci.yml
  • electron/policy.ts
  • packages/mission-control-daemon/src/authority-types.ts
  • scripts/authoritative-daemon-smoke.ts

Install Manifest Integrity

Install manifests, plugin metadata, and shipped skills should stay synchronized with user-facing setup guidance.

Signals:

  • 2 install or manifest path(s) changed

Paths:

  • package-lock.json
  • package.json

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • Runtime config changes may ship without example or template updates
  • User-facing UI changes may ship without browser coverage
  • CI workflow changes may ship without failure-mode evidence
  • 20 CI or workflow path(s) changed

Paths:

  • .github/workflows/ci.yml
  • electron/main.test.ts
  • electron/smoke.test.ts
  • package-lock.json
  • package.json
  • packages/electron-security-policy/src/index.test.ts
  • packages/mission-control-daemon/src/auth.test.ts
  • packages/mission-control-daemon/src/durable-store.test.ts

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 38d4202b4ae33f1d8c0bd4e0373fbcf0ae60cc97

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 53 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 38d4202b4ae33f1d8c0bd4e0373fbcf0ae60cc97

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 53 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: 38d4202b4ae33f1d8c0bd4e0373fbcf0ae60cc97

No changed-config issues detected (success)

Scanned 1 config file(s) present at this commit across 1 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/ci.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c285b61c-e2b6-4958-ab27-a44263d583e2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: 38d4202b4ae33f1d8c0bd4e0373fbcf0ae60cc97

No harness issues detected (success)

Scanned 1 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/ci.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

This branch was successfully deployed

1 active deployment
Preview — 38d4202b Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants