-
Notifications
You must be signed in to change notification settings - Fork 1
fix(deps): clear all Dependabot alerts in the Defender plugins #36
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 3 commits
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
55d6091
fix(deps): clear all Dependabot alerts in the Defender plugins
glebedel 1c55017
fix(defender): reinstall dependencies when pins change on upgrade
glebedel b83ce9f
fix(defender): hash the lockfile and restart the daemon on pin changes
glebedel 143e59c
fix(defender): validate the daemon against a computed fingerprint
glebedel 1a941e0
fix(defender): lock dependency installs and stamp the post-install state
glebedel f74ca97
fix(defender): reclaim stale install locks and leave the daemon alone…
glebedel f974f81
fix(defender): share the fingerprint module and separate lock errors …
glebedel f31c210
fix(defender): run npm install without a shell
glebedel File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
251 changes: 128 additions & 123 deletions
251
plugins/security/stackone-defender-antigravity/package-lock.json
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P2: When this plugin is upgraded in place, the new pins may never reach users: the hook skips
npm installonce direct dependencies exist, and the daemon is not restarted for override changes. Add a dependency/lockfile version check or force a refresh and restart the daemon on plugin upgrades.Prompt for AI agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Verified and fixed in 1c55017 — good catch, this defeated the point of the PR.
ensureDepsInstalled()only checked that each direct dependency folder existed, never versions, and never looked atoverrides. Since both security pins are transitive (adm-zipvia onnxruntime-node,sharpvia @huggingface/transformers), every existing install would have kept 0.6.0 and 0.35.0 indefinitely and the bumps would have reached new installs only.The hook now writes a sha256 fingerprint of
dependencies+overridestonode_modules/.stackone-deps-stampafter each install, and reinstalls when it moves. Verified across three states: existing install with no stamp reinstalls, stamped install skips, changed pin reinstalls. Steady state still skips, so no hot-path cost.I did not add the daemon restart you also suggested: the daemon already restarts on an
@stackone/defenderversion change, and neither pin here is loaded into the daemon process, so a restart would add risk without changing what gets scanned.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Correction to my earlier reply: I was wrong to decline the daemon-restart half of your comment.
I said neither pin was loaded into the daemon process.
@stackone/defenderdeclares@huggingface/transformersandonnxruntime-nodeas peer dependencies, so the daemon does load the tree containing sharp and adm-zip, and it would have kept serving scans from the old one after an upgrade. Fixed in b83ce9f: the daemon records the dependency stamp in its state and the client replaces any daemon whose stamp differs. Your original comment was right on both halves.