fix(deps): resolve all 187 open Dependabot security alerts - #38
Merged
Merged
Conversation
Consolidated security update across both ecosystems. Every open Dependabot alert (76 npm / 111 pip) was verified resolved against its advisory's vulnerable version range, not just bumped by hand. frontend (npm, 76 alerts) - axios 1.7.9 -> 1.19.0, react-router-dom 7.1.0 -> 7.18.2, postcss 8.4.49 -> 8.5.25, vite 6.0.1 -> 6.4.3 - `npm update` lifted the remaining transitives (@babel/core, brace-expansion, esbuild, flatted, follow-redirects, form-data, js-yaml, minimatch, picomatch, rollup, yaml); glob and turbo-stream dropped out of the tree entirely. No `overrides` needed. backend (pip, 111 alerts across requirements.txt + poetry.lock) - pillow 11.0.0 -> 12.3.0, torch 2.0.0 -> 2.13.0, torchvision 0.20.1 -> 0.28.0, urllib3 2.3.0 -> 2.7.0, idna 3.10 -> 3.18, requests 2.32.3 -> 2.34.2, jinja2 3.1.5 -> 3.1.6, h11 0.14.0 -> 0.16.0, filelock, fonttools, python-multipart, setuptools, wheel, python-dotenv, pytest - starlette 0.41.3 -> 1.4.1 forces fastapi 0.115.6 -> 0.141.1 (0.115 caps starlette <0.42). Pulls in fastapi's new annotated-doc / typing-inspection deps, and torch 2.13 requires sympy >=1.13.3 and setuptools >=77. - Transitive-only packages get explicit floors in pyproject.toml so poetry cannot resolve back below the patched versions. required knock-on changes - requires-python ^3.9 -> >=3.11,<3.14: pillow 12.3, torch 2.13, starlette 1.4 and fastapi 0.141 all require >=3.10. Upper bound excludes 3.14 because torchvision 0.28 declares `!=3.14.1`, which otherwise makes poetry backtrack to torchvision 0.12.0 for python >=3.12. CI already runs 3.11/3.12. - Dockerfile: python 3.9 -> 3.12-bookworm, poetry 1.7.1 -> 2.4.1 + poetry-plugin-export (lock is now lock-version 2.1, and poetry 2.x moved `export` into a plugin), pre-installed torch pin 2.0.0 -> 2.13.0. verification - npm: every one of the 76 alerts re-checked with semver against the new package-lock.json - all outside their vulnerable ranges. `npm ci` + `tsc -b && vite build` pass. - pip: all 111 alerts re-checked against poetry.lock and requirements.txt. `poetry check --lock` passes; requirements.txt resolves cleanly under uv for py3.11 and py3.12 on linux/x86_64. - runtime: fastapi 0.141 + starlette 1.4 smoke-tested over the exact surface app/ uses (CORSMiddleware, APIRouter prefix, UploadFile/File/Form multipart, HTTPException, pydantic body, OpenAPI). ultralytics 8.3.55 runs a forward pass and loads a .pt checkpoint on torch 2.13. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Member
|
큰일 하셨네요 ㅋㅋ 저는 옛날에 dependabot을 써보다가, 빌드에 손대는 것이 얼마나 위험한지 깨닫고 이제는 안쓰고 있어요. 무엇보다 봇이 pr을 너무 많이 만드니 알람이 계속 울리고 피곤하더라고요. 실제로 버전 업데이트 한 뒤에 오류도 몇번 경험하니 신뢰도도 떨어져서 ㅎ 오픈소스들 보면 GitHub Action로 빌드 테스트하는 방식이 많은거 같아요~ 찾아보니까 긱뉴스에도 비슷한 글이 있네요 — https://news.hada.io/topic?id=26873 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
요약
/security/dependabot에 열려 있던 187건 전부를 한 브랜치에서 정리했습니다.(critical 5 / high 83 / moderate 80 / low 19 — npm 76건, pip 111건)
손으로 버전만 올린 게 아니라, 각 alert의 advisory vulnerable range에 새 버전이 걸리는지 187건 전부 재검증했습니다.
변경 내용
frontend (npm, 76건)
직접 의존성:
나머지 transitive(
@babel/core,brace-expansion,esbuild,flatted,follow-redirects,form-data,js-yaml,minimatch,picomatch,rollup,yaml)는npm update로 전부 해소됐고,glob·turbo-stream은 트리에서 아예 빠졌습니다.overrides강제 주입은 필요 없었습니다.backend (pip, 111건 —
requirements.txt+poetry.lock)starlette <0.42로 상한을 걸어둬서, starlette만 올릴 수 없습니다. fastapi 0.141.1로 올리면서 신규 의존성annotated-doc,typing-inspection이 추가됐고, torch 2.13이 요구하는sympy>=1.13.3·setuptools>=77도 함께 맞췄습니다.pyproject.toml에 security floor를 명시해서 poetry가 다시 취약 버전으로 내려가지 못하게 막았습니다.딸려온 필수 변경
requires-python^3.9→>=3.11,<3.14pillow 12.3 / torch 2.13 / starlette 1.4 / fastapi 0.141이 전부
>=3.10을 요구합니다.상한을 3.14로 막은 이유: torchvision 0.28이
!=3.14.1을 선언해서, 상한이 없으면 poetry가python >= 3.12구간에 대해 torchvision 0.12.0(2022년 버전) 으로 백트래킹합니다. CI는 이미 3.11/3.12라 영향 없습니다.app/Dockerfilepython:3.9→python:3.12-bookworm/python:3.12-slim-bookworm(apt 패키지명 유지를 위해 Debian suite 고정)poetry 1.7.1→poetry 2.4.1+poetry-plugin-export(lock이
lock-version 2.1이라 1.7.1은 읽지 못하고, poetry 2.x는export가 플러그인으로 분리됨)2.0.0→2.13.0검증
package-lock.json에 대조 → 전부 vulnerable range 바깥.npm ci+tsc -b && vite build통과.poetry.lock/requirements.txt에 대조 → 전부 해소.poetry check --lock통과.requirements.txt는 uv로 py3.11·py3.12 / linux-x86_64 양쪽 모두 충돌 없이 resolve..pt)가 레포에 없어main.py직접 import는 원래 불가하므로,app/이 실제로 쓰는 프레임워크 표면(CORSMiddleware, prefix 붙은 APIRouter,UploadFile/File/Formmultipart,HTTPException, pydantic body, OpenAPI 스키마)을 fastapi 0.141 + starlette 1.4에서 그대로 재현해 전부 통과 확인. ultralytics 8.3.55도 torch 2.13에서 forward pass +.pt체크포인트 로드 정상.남는 이슈 (이 PR 범위 밖)
npm audit이 7.18.2에 대해 advisory 하나를 더 띄웁니다(RSC Mode CSRF Bypass, 취약 범위 7.12.0–8.2.0). 제안되는 유일한 수정이 7.11.0으로 다운그레이드인데, 그러면 이번에 닫은 alert 3건이 되살아납니다. 게다가 이 프로젝트는 Vite SPA로 RSC 모드를 쓰지 않아 해당 경로가 없습니다. 7.18.2 유지가 맞다고 판단했습니다..github/workflows/ci.yml— 41번째 줄- name: Validate Poetry Configuration의 들여쓰기가 어긋나 YAML이 깨져 있습니다(기존 문제, 이 PR과 무관). 별도로 고치는 게 좋겠습니다.🤖 Generated with Claude Code