Skip to content

build(deps): refresh clients and patch Sharp - #1202

Merged
steipete merged 1 commit into
mainfrom
round9-deps
Oct 10, 2026
Merged

steipete merged 1 commit into
mainfrom
round9-deps

Conversation

@steipete

Copy link
Copy Markdown
Collaborator

Refresh the Google API/auth, MCP, and Go networking/cryptography modules while retaining the Go 1.26 floor. Update Wrangler to 4.149.0, Workers types to 5.20261009.1, and Vite to 8.3.4 using pnpm 11 and the existing 24-hour release cooldown.

The refreshed lockfile also selects Sharp 0.35.5, fixing GHSA-wq5f-xc86-pv6w (librsvg CVE-2026-96889). Sharp install scripts remain disabled. No application version changes.

Validation: module metadata confirms Go 1.26 compatibility; full make ci and frozen-lockfile make worker-ci on AWS Crabbox; independent review through P2.

@steipete
steipete requested a review from a team as a code owner October 10, 2026 05:27
@clawsweeper

clawsweeper Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 10, 2026
@clawsweeper

clawsweeper Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge.

What this changes

This PR refreshes Go clients and worker tooling, including Sharp 0.35.5 for a published security fix.

Example: Install the tracking worker’s locked dependencies.

  • Before: The dependency graph selects Sharp 0.35.4.
  • After: The graph selects patched Sharp 0.35.5 while keeping its install scripts disabled.

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) A focused, useful refresh with no identified defect; confidence rests on source inspection and build/test evidence rather than demonstrated live behavior.
Proof confidence 🌊 off-meta tidepool Not applicable: This collaborator-authored maintenance PR is outside the ordinary contributor proof gate; reported Crabbox validation and hosted checks support compatibility but establish no live Google API or worker behavior.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Product

Kind: Maintenance · Worth it: Yes · Fix scope: Complete
User problem: The CLI and tracking-worker toolchain retain older clients and a Sharp version covered by a published advisory.
Reason: The collaborator-authored refresh addresses concrete maintenance value within the established dependency policy.

Merge readiness

✅ Ready for maintainer review

Keep open: this collaborator-authored PR provides a useful dependency and security refresh absent from current main; no actionable introduced defect was found.

Priority: P2
Reviewed head: f24af7c2ef36de33da0b8806332c1f6d3426f922

Before merge

None.

Findings

None.

Tests

  • Missing end-to-end proof: Supplied validation covers builds and tests rather than an authenticated CLI operation or live worker request using the refreshed graph.
Agent review details

How this fits together

Go dependencies support the CLI’s Google API and MCP operations; worker dependencies build, test, and deploy the email-tracking worker.

flowchart LR
  A[CLI commands] --> B[Go clients]
  B --> C[Google APIs and MCP]
  D[Worker package and lockfile] --> E[Wrangler and Vite]
  E --> F[Tracking worker]
  E --> G[Miniflare and Sharp]
Loading

Technical review

Best possible solution:

Land the focused dependency refresh through the existing validation gates while preserving the current toolchain and worker install policy.

Do we have a high-confidence way to reproduce the issue?

This is dependency maintenance; the affected Sharp version and patched replacement are established by the lockfile and published advisory.

Is this the best way to solve the issue?

The manifest and lockfile refresh is appropriately scoped and retains existing compatibility and install-policy choices.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 9762a448e120.

Provenance checked

Testing

Proof path: in-process harness.

Security

None.

Evidence

What I checked:

  • Pinned introduced changes: The introduced diff contains dependency manifests, checksums, the worker lockfile, and an Unreleased changelog entry; application code, Go floor, pnpm pin, install permissions, and release cooldown remain unchanged. (internal/tracking/worker/pnpm-workspace.yaml:1, f24af7c2ef36)
  • Current main still needs the refresh: Current main retains MCP 1.1.1, Google API 0.300.0, Wrangler 4.147.0, and the older worker graph. (go.mod:13, 9762a448e120)
  • Published security fix: GitHub’s advisory identifies versions below 0.35.5 as affected and 0.35.5 as the first patched version: GHSA-wq5f-xc86-pv6w.
  • Existing dependency direction: The merged refresh at build(deps): refresh Go modules and worker tooling #1192 explicitly preserves Go 1.26, pnpm 11, and the worker release cooldown; this PR follows that direction. (internal/tracking/worker/package.json:25, 4d7478e9b73a)
  • Validation and inspection limits: The author reports full Go and frozen worker gates on AWS Crabbox; exact-head worker and image checks passed while several platform checks remained running. No target code or second reviewer was run. Missing historical blobs limited some git inspections, and the proxy blocked one upstream module-metadata request; these are review-environment limits. (.github/workflows/ci.yml:68, f24af7c2ef36)

Likely related people:

  • Peter Steinberger: Raw commit 27c3b04 adds internal/tracking/worker/pnpm-workspace.yaml:3 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 27c3b04e00ff; files: internal/tracking/worker/pnpm-workspace.yaml)

Labels

Label changes:

  • add P2: Useful dependency maintenance includes a confirmed security patch in worker tooling, without evidence of an urgent production failure.
  • add rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR.

Label justifications:

  • P2: Useful dependency maintenance includes a confirmed security patch in worker tooling, without evidence of an urgent production failure.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR.

Rating scale

6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior.

Workflow

ClawSweeper edits this one comment on every review. Comment @clawsweeper re-review for a fresh review only; repair and merge need explicit maintainer commands such as @clawsweeper autofix or @clawsweeper automerge.

Reviewed October 10, 2026, 1:30 AM ET / 05:30 UTC.

@steipete
steipete merged commit 2e6676f into main Oct 10, 2026
14 checks passed
@steipete
steipete deleted the round9-deps branch October 10, 2026 05:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant