Repository navigation
fix(security): pin busboy 3.2.2 and web_core 0.10.2 floors - #3632
Conversation
Transitive overrides for advisories published during #3583: - @fastify/busboy 3.2.1 for CVE-2026-19481 / CVE-2026-19484 (@whatwg-node/node-fetch transitive; alerts 456, 457). - @a2ui/web_core 0.10.2 for CVE-2026-10032 (@copilotkit/a2ui-renderer transitive; alert 455).
|
@codex review |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: 755b9762-af39-4c9d-8a0c-7092ad4aa5c8) |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe workspace configuration adds exact version overrides for ChangesDependency overrides
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to The lockfile applies the advisory-fixed versions, and the inspected renderer remains compatible with the A2UI override. No concrete merge-blocking issue remains. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Muse code review (advisory)
Workflow: https://github.com/ogabasseyy/Baci/actions/runs/37356171581
Verdict
Minimal, well-scoped security follow-up: the two new workspace overrides force the vulnerable transitives to their documented fix versions, and the lockfile consistently advances both consumer snapshots (@whatwg-node/node-fetch to busboy 3.2.1, @copilotkit/a2ui-renderer to web_core 0.10.2) with no other version changes. I verified upstream that v3.2.1 is the published fix for CVE-2026-19481/CVE-2026-19484 and that the web_core 0.10.2 changelog documents the openUrl scheme-validation fix for CVE-2026-10032. No blocking issues; one low-severity note that the entries are exact pins rather than floors.
Findings
- low: Exact pins (not floors) block later patches in pnpm-workspace.yaml:328 (see inline)
Suggested next steps
- Confirm CI runs a full install from the updated lockfile plus web typecheck/lint per the repo quality gate before merge (the description claims both green but shows no output).
- Confirm whether trusted-scripts/pnpm-lock.yaml is a live install root: it still resolves @fastify/busboy 3.2.0 and @a2ui/web_core 0.9.0. If anything installs from it, apply the same bumps there.
- Re-check Dependabot alerts 455/456/457 (or run pnpm audit) after merge to confirm closure, and bump the exact pins when post-fix patches land (notably @a2ui/web_core past 0.10.2).
|
@codex review |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: c19baddf-efe5-4fed-bcfc-d8b466e9292e) |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Muse code review (advisory)
Workflow: https://github.com/ogabasseyy/Baci/actions/runs/37356584179
Verdict
Correct lockfile-only security fix. Both overrides resolve to verified patched versions (busboy 3.2.1 for CVE-2026-19481/19484, web_core 0.10.2 for CVE-2026-10032), the lockfile updates are complete with no stale 3.2.0/0.9.0 references remaining in pnpm-lock.yaml, and the change follows the existing workspace-overrides pattern with no runtime code changes. No issues found.
Findings
- No meaningful issues found.
Suggested next steps
- Confirm Dependabot alerts 455, 456, and 457 auto-close as fixed after merge
- No code follow-up needed; future patched releases will require new override bumps since pins are exact by established pattern
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: 7999b2a1-367d-4eef-b364-31a7767feaa2) |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Muse code review (advisory)
Workflow: https://github.com/ogabasseyy/Baci/actions/runs/37428362920
Verdict
Lockfile-only security-pin PR that is internally consistent (workspace overrides, lockfile packages, and both transitive snapshots agree; no stale 3.2.0/0.9.0 entries for the affected packages), follows the repo's existing overrides pattern, and touches no runtime code. The one issue is that the @fastify/busboy 3.2.1 pin is already one security release behind 3.2.2, so it should be bumped before or immediately after merge.
Findings
- medium: busboy pin already superseded by 3.2.2 security release in pnpm-workspace.yaml:328 (see inline)
Suggested next steps
- Bump the @fastify/busboy override to 3.2.2, regenerate pnpm-lock.yaml, and confirm no 3.2.1 snapshot entries remain.
- Confirm Dependabot alerts 456, 457, 455 auto-close on merge; if a new alert fires for GHSA-gxm5-99cw-xjw9, that confirms the 3.2.2 follow-up was needed.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3ce48e31c6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…on test - Bump @fastify/busboy override 3.2.1 -> 3.2.2 (GHSA-gxm5-99cw-xjw9: CRLF injection via multipart Content-Disposition filename/name affects all versions below 3.2.2) + regen lockfile. - Add apps/web/a2ui-openurl-integrity.test.ts: pins @a2ui/web_core >= 0.10.2 and behaviorally verifies openUrl rejects javascript:/ data:/vbscript:/file: URLs (CVE-2026-10032). Verified 2/2 fail on 0.10.1 and 2/2 pass on 0.10.2. Addresses Codex P1 threads on PR #3632.
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: 4ffa2a4c-318d-4c2f-b25d-23294398f927) |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Muse code review (advisory)
Workflow: https://github.com/ogabasseyy/Baci/actions/runs/37430078479
Verdict
Security bump looks correct: workspace overrides plus lockfile move @fastify/busboy 3.2.0->3.2.2 and @a2ui/web_core 0.9.0->0.10.2 with no runtime code changes, and the new openUrl regression test usefully guards the web_core floor. No blocking issues; remaining notes are a stale 3.2.1 description and minor test brittleness.
Findings
- low: PR description still says busboy 3.2.1; code pins 3.2.2 in pnpm-workspace.yaml:326 (see inline)
- low: Integrity test coupled to web_core internal file layout in apps/web/a2ui-openurl-integrity.test.ts:73 (see inline)
- low: Assertion tied to exact upstream error wording in apps/web/a2ui-openurl-integrity.test.ts:148 (see inline)
Suggested next steps
- Update PR title/description to busboy 3.2.2 and list CVE-2026-74866 so alert-closure tracking matches the lockfile.
- Confirm the new vitest file runs in CI (apps/web vitest run picks up repo-root *.test.ts with the node-environment pragma) and passes against the locked 0.10.2 tree.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9a1e293fe2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- Add apps/web/busboy-crlf-integrity.test.ts: pins @fastify/busboy >= 3.2.2 and mirrors the upstream 'rejects bare CR or LF' test (8 disposition vectors incl. RFC 5987 filename*/name* forms). Verified 2 fail + control passes on 3.2.1, 3/3 pass on 3.2.2. - A2UI test: document the deep-import coupling (fail-closed note) and assert throw + never-opened instead of exact error wording. Addresses Codex P1 + 2 low threads on PR #3632.
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: b6b170bb-e61c-48bb-8e20-0429f6940e97) |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Muse code review (advisory)
Workflow: https://github.com/ogabasseyy/Baci/actions/runs/37431106868
Verdict
Sound follow-up: exact pins (busboy 3.2.2, web_core 0.10.2) match the cited fixes, the lockfile updates are consistent across packages and snapshots, and both integrity tests follow the repo's regression-test rule with fail-closed version gates. No correctness or security defect found in the diff; remaining notes are low-severity coverage and test-strictness suggestions. Findings below are unverified by execution (read-only review).
Findings
- low: Behavioral coverage only for one of three busboy CVEs in apps/web/busboy-crlf-integrity.test.ts:115 (see inline)
- low: Any-throw counts as allowlist rejection in apps/web/a2ui-openurl-integrity.test.ts:155 (see inline)
- low: Env hook can decouple test from installed dependency in apps/web/busboy-crlf-integrity.test.ts:21 (see inline)
Suggested next steps
- Confirm advisories resolve at the pinned floors (busboy 3.2.2 covers GHSA-gxm5-99cw-xjw9 plus the 3.2.1 DoS fixes; web_core 0.10.2 for CVE-2026-10032) and that no newer patched release supersedes them
- Run lockfile-only plus full install, the two new integrity tests, and the web typecheck to corroborate the PR's verification claims
- Consider behavioral regression cases for CVE-2026-19481/19484 or document reliance on the version gate
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0945171ed7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- busboy-integrity.test.ts (renamed from -crlf-): add prototype-header case (CVE-2026-19481) and timeout-controlled child-process 252-byte boundary case (CVE-2026-19484), both mirroring upstream 3.2.1 tests; resolve the package entry via its own main field (3.2.0 uses lib/main). Matrix: 5/5 on 3.2.2; DoS pass + gate/CRLF fail on 3.2.1; gate + all behavioral fail (boundary hits the 2s kill) with control green on 3.2.0. - A2UI test: assert thrown instanceof A2uiExpressionError (precise, reword-safe) instead of any-throw. - Both suites: refuse the *_ROOT verification override under CI and warn when it is active locally. Addresses Codex P1 + 3 low threads on PR #3632.
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: dbefa253-6c94-446b-aa97-c989b2e5a57a) |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Muse code review (advisory)
Workflow: https://github.com/ogabasseyy/Baci/actions/runs/37432535058
Verdict
Security pin PR is sound: pnpm-workspace.yaml exact overrides for @fastify/busboy 3.2.2 and @a2ui/web_core 0.10.2 match the established pattern, and pnpm-lock.yaml correctly advances both packages plus the @whatwg-node/node-fetch and @copilotkit/a2ui-renderer transitive snapshots. The two new integrity tests are fail-closed regression guards with CI-safe override hooks and no auth, secrets, or data-safety concerns. No blocking issues found.
Findings
- No meaningful issues found.
Suggested next steps
- Confirm CI shows the two new integrity tests passing and Dependabot alerts 455, 456, 457 auto-closing on merge
- No code changes requested; merge once lockfile install and web typecheck are green in CI
Follow-up to #3583: three Dependabot alerts (456, 457, 455) published while that PR was in review.
@fastify/busboy→ 3.2.2 (CVE-2026-19481, CVE-2026-19484, CVE-2026-74866 CRLF injection;@whatwg-node/node-fetchtransitive)@a2ui/web_core→ 0.10.2 (CVE-2026-10032;@copilotkit/a2ui-renderertransitive)Follows the established workspace-overrides pattern. Regression coverage:
apps/web/busboy-integrity.test.ts(behavioral cases for all three busboy CVEs; verified across 3.2.0/3.2.1/3.2.2) andapps/web/a2ui-openurl-integrity.test.ts(fails on 0.10.1, passes on 0.10.2). Verified: lockfile-only + full install clean, web typecheck green.Note
Medium Risk
Touches security-sensitive multipart parsing and URL-opening behavior in transitive deps; changes are pinned upgrades plus regression tests rather than app logic, but affect upload/fetch and A2UI agent actions.
Overview
Pins two transitive dependencies to patched releases and adds Vitest integrity suites so a future override downgrade fails CI instead of silently reintroducing known issues.
pnpm-workspace.yamlnow floors@fastify/busboyat 3.2.2 (DoS + multipart CRLF injection CVEs on the@whatwg-node/node-fetchpath) and@a2ui/web_coreat 0.10.2 (CVE-2026-10032: agent-controlledopenUrlcould executejavascript:URIs via@copilotkit/a2ui-renderer).pnpm-lock.yamlreflects 3.2.0 → 3.2.2 and 0.9.0 → 0.10.2.New
apps/web/busboy-integrity.test.tsasserts minimum version 3.2.2 and mirrors upstream regressions (prototype-named headers, 252-byte boundary hang in a timeout child process, CRLF inContent-Disposition). Newapps/web/a2ui-openurl-integrity.test.tsasserts ≥0.10.2 and thatopenUrlrejects non-http(s) schemes while still opening https withnoopener,noreferrer. Both support optional local root env overrides that are refused in CI.Reviewed by Cursor Bugbot for commit 77f8f72. Bugbot is set up for automated code reviews on this repo. Configure here.