Skip to content

fix: bump adm-zip, fast-uri, js-yaml, sharp, hono and csv-parse to patched versions - #173

Open
devin-ai-integration[bot] wants to merge 4 commits into
mainfrom
devin/dep-vulns/2026-09-14
Open

devin-ai-integration[bot] wants to merge 4 commits into
mainfrom
devin/dep-vulns/2026-09-14

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Dependency vulnerability fixes (automated)

Generated by the Devin Dependency Security Vuln Fix automation run on 2026-09-28.
Change type: Minor/patch version bumps — manifest and lockfile changes, no source edits.

Warning

We're not just looking for a review like a normal PR. Security can offer this fix as a recommendation, but doesn't have the tooling or domain knowledge to safely verify changes like this end-to-end for each repo. Please review, test, and own deployment before merging. For more information: https://launchdarkly.atlassian.net/wiki/spaces/SEC/pages/5360943572/Dependency+Vulnerability+Remediation+with+Devin.

Findings addressed

Package Ecosystem Bump type Current → Target Severity Age Source(s) Advisory
fast-uri npm Patch 3.1.5 → 3.1.7 High 25d Dependabot, Wiz GHSA-5jgf-p345-68v8, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp, GHSA-f65p-4m7j-42xc
js-yaml npm Patch 4.3.1 → 4.3.2 High 15d Dependabot, Wiz GHSA-2883-xcg3-v3hh
sharp npm Patch 0.35.3 → 0.35.4 High 17d Dependabot, Wiz GHSA-rgj7-g3m4-5g8c
adm-zip npm Patch 0.6.0 → 0.6.1 High 9d Dependabot, Wiz GHSA-7q85-xj36-vmfc
hono npm Patch 4.13.2 → 4.13.8 Moderate 18d Dependabot, Wiz GHSA-gqvv-2mrq-wpjv, GHSA-crvj-82cr-hjcx
csv-parse npm Patch 7.0.1 → 7.0.2 Moderate 19d Dependabot, Wiz GHSA-8cw4-87c7-c6xx

All findings are dev-only, in evals/ and tests/ (csv-parse only in evals/). Transitives of promptfoo are pinned via npm overrides; lockfiles regenerated with --legacy-peer-deps (matches CI). Supersedes the Dependabot PRs for these packages (their Evaluate * jobs cannot access the eval provider secrets).

Deferred / excluded findings

Verification

  • Install: ✅ npm ci --legacy-peer-deps in evals/ and tests/
  • Build: n/a (no build step)
  • Tests: ✅ python3 scripts/validate_skills.py (49 skills), python3 -m unittest discover -s tests (9 tests), python3 scripts/generate_catalog.py --check, cd evals && npm test (92 pass / 0 fail)
  • Lint: n/a

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration devin-ai-integration Bot added automated-security-deps Automated dependency vulnerability remediation devin-pr exempt labels Sep 14, 2026
@devin-ai-integration
devin-ai-integration Bot requested review from a team September 14, 2026 13:07
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Skill eval results

Skill Before After Δ
agentcontrol/configs-create 100/100 (4/4) 100/100 (4/4) no change
agentcontrol/configs-update 80/100 (4/5) 80/100 (4/5) no change
agentcontrol/configs-variations 80/100 (4/5) 80/100 (4/5) no change
agentcontrol/tools 75/100 (3/4) 75/100 (3/4) no change
feature-flags/flag-and-release-change - 100/100 (4/4) new
feature-flags/flag-release - 100/100 (5/5) new
feature-flags/launchdarkly-flag-command - 100/100 (3/3) new
feature-flags/launchdarkly-flag-create 100/100 (3/3) 100/100 (4/4) no change
feature-flags/launchdarkly-flag-drift - 100/100 (4/4) new
feature-flags/should-flag-change - 100/100 (17/17) new
onboarding - 100/100 (4/4) new

Only suites whose source actually changed since their last recorded score were re-run. Soft-failing while we stabilise the baseline.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: remediate fast-uri dependency vulnerabilities in evals and tests workspaces fix: remediate npm dependency vulnerabilities in evals and tests workspaces Sep 21, 2026
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title fix: remediate npm dependency vulnerabilities in evals and tests workspaces fix: bump adm-zip, fast-uri, js-yaml, sharp, hono and csv-parse to patched versions Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated-security-deps Automated dependency vulnerability remediation devin-pr exempt

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants