Skip to content

fix(deps): resolve all 187 open Dependabot security alerts - #38

Merged
taehan79-kim merged 1 commit into
mainfrom
fix/dependabot-security-updates
Aug 5, 2026
Merged

taehan79-kim merged 1 commit into
mainfrom
fix/dependabot-security-updates

Conversation

@taehan79-kim

Copy link
Copy Markdown
Member

요약

/security/dependabot에 열려 있던 187건 전부를 한 브랜치에서 정리했습니다.
(critical 5 / high 83 / moderate 80 / low 19 — npm 76건, pip 111건)

손으로 버전만 올린 게 아니라, 각 alert의 advisory vulnerable range에 새 버전이 걸리는지 187건 전부 재검증했습니다.

변경 내용

frontend (npm, 76건)

직접 의존성:

패키지 이전 이후
axios 1.7.9 1.19.0
react-router-dom 7.1.0 7.18.2
postcss 8.4.49 8.5.25
vite 6.0.1 6.4.3

나머지 transitive(@babel/core, brace-expansion, esbuild, flatted, follow-redirects, form-data, js-yaml, minimatch, picomatch, rollup, yaml)는 npm update로 전부 해소됐고, glob·turbo-stream은 트리에서 아예 빠졌습니다. overrides 강제 주입은 필요 없었습니다.

backend (pip, 111건 — requirements.txt + poetry.lock)

패키지 이전 이후
pillow 11.0.0 12.3.0
torch 2.0.0 2.13.0
torchvision 0.20.1 0.28.0
starlette 0.41.3 1.4.1
fastapi 0.115.6 0.141.1
urllib3 2.3.0 2.7.0
requests 2.32.3 2.34.2
idna 3.10 3.18
jinja2 3.1.5 3.1.6
h11 0.14.0 0.16.0
filelock / fonttools / python-multipart / setuptools / wheel / python-dotenv / pytest — 패치 버전
  • starlette 1.x가 fastapi 상향을 강제합니다. fastapi 0.115.6이 starlette <0.42로 상한을 걸어둬서, starlette만 올릴 수 없습니다. fastapi 0.141.1로 올리면서 신규 의존성 annotated-doc, typing-inspection이 추가됐고, torch 2.13이 요구하는 sympy>=1.13.3·setuptools>=77도 함께 맞췄습니다.
  • transitive로만 들어오는 패키지들은 pyproject.toml에 security floor를 명시해서 poetry가 다시 취약 버전으로 내려가지 못하게 막았습니다.

딸려온 필수 변경

  • requires-python ^3.9 → >=3.11,<3.14
    pillow 12.3 / torch 2.13 / starlette 1.4 / fastapi 0.141이 전부 >=3.10을 요구합니다.
    상한을 3.14로 막은 이유: torchvision 0.28이 !=3.14.1을 선언해서, 상한이 없으면 poetry가 python >= 3.12 구간에 대해 torchvision 0.12.0(2022년 버전) 으로 백트래킹합니다. CI는 이미 3.11/3.12라 영향 없습니다.
  • app/Dockerfile
    • python:3.9 → python:3.12-bookworm / python:3.12-slim-bookworm (apt 패키지명 유지를 위해 Debian suite 고정)
    • poetry 1.7.1 → poetry 2.4.1 + poetry-plugin-export
      (lock이 lock-version 2.1이라 1.7.1은 읽지 못하고, poetry 2.x는 export가 플러그인으로 분리됨)
    • 사전 설치 torch 핀 2.0.0 → 2.13.0

검증

  • npm — 76건 각각을 semver로 새 package-lock.json에 대조 → 전부 vulnerable range 바깥. npm ci + tsc -b && vite build 통과.
  • pip — 111건을 poetry.lock/requirements.txt에 대조 → 전부 해소. poetry check --lock 통과. requirements.txt는 uv로 py3.11·py3.12 / linux-x86_64 양쪽 모두 충돌 없이 resolve.
  • 런타임 — 모델 가중치(.pt)가 레포에 없어 main.py 직접 import는 원래 불가하므로, app/이 실제로 쓰는 프레임워크 표면(CORSMiddleware, prefix 붙은 APIRouter, UploadFile/File/Form multipart, HTTPException, pydantic body, OpenAPI 스키마)을 fastapi 0.141 + starlette 1.4에서 그대로 재현해 전부 통과 확인. ultralytics 8.3.55도 torch 2.13에서 forward pass + .pt 체크포인트 로드 정상.

남는 이슈 (이 PR 범위 밖)

  1. react-router — npm audit이 7.18.2에 대해 advisory 하나를 더 띄웁니다(RSC Mode CSRF Bypass, 취약 범위 7.12.0–8.2.0). 제안되는 유일한 수정이 7.11.0으로 다운그레이드인데, 그러면 이번에 닫은 alert 3건이 되살아납니다. 게다가 이 프로젝트는 Vite SPA로 RSC 모드를 쓰지 않아 해당 경로가 없습니다. 7.18.2 유지가 맞다고 판단했습니다.
  2. .github/workflows/ci.yml — 41번째 줄 - name: Validate Poetry Configuration의 들여쓰기가 어긋나 YAML이 깨져 있습니다(기존 문제, 이 PR과 무관). 별도로 고치는 게 좋겠습니다.
  3. Docker 빌드는 CI/CD 인스턴스가 내려가 있어 실행하지 않았습니다. Dockerfile 변경은 정적 검토만 거쳤습니다.

🤖 Generated with Claude Code

Consolidated security update across both ecosystems. Every open Dependabot
alert (76 npm / 111 pip) was verified resolved against its advisory's
vulnerable version range, not just bumped by hand.

frontend (npm, 76 alerts)
- axios 1.7.9 -> 1.19.0, react-router-dom 7.1.0 -> 7.18.2,
  postcss 8.4.49 -> 8.5.25, vite 6.0.1 -> 6.4.3
- `npm update` lifted the remaining transitives (@babel/core, brace-expansion,
  esbuild, flatted, follow-redirects, form-data, js-yaml, minimatch, picomatch,
  rollup, yaml); glob and turbo-stream dropped out of the tree entirely.
  No `overrides` needed.

backend (pip, 111 alerts across requirements.txt + poetry.lock)
- pillow 11.0.0 -> 12.3.0, torch 2.0.0 -> 2.13.0, torchvision 0.20.1 -> 0.28.0,
  urllib3 2.3.0 -> 2.7.0, idna 3.10 -> 3.18, requests 2.32.3 -> 2.34.2,
  jinja2 3.1.5 -> 3.1.6, h11 0.14.0 -> 0.16.0, filelock, fonttools,
  python-multipart, setuptools, wheel, python-dotenv, pytest
- starlette 0.41.3 -> 1.4.1 forces fastapi 0.115.6 -> 0.141.1 (0.115 caps
  starlette <0.42). Pulls in fastapi's new annotated-doc / typing-inspection
  deps, and torch 2.13 requires sympy >=1.13.3 and setuptools >=77.
- Transitive-only packages get explicit floors in pyproject.toml so poetry
  cannot resolve back below the patched versions.

required knock-on changes
- requires-python ^3.9 -> >=3.11,<3.14: pillow 12.3, torch 2.13, starlette 1.4
  and fastapi 0.141 all require >=3.10. Upper bound excludes 3.14 because
  torchvision 0.28 declares `!=3.14.1`, which otherwise makes poetry backtrack
  to torchvision 0.12.0 for python >=3.12. CI already runs 3.11/3.12.
- Dockerfile: python 3.9 -> 3.12-bookworm, poetry 1.7.1 -> 2.4.1 +
  poetry-plugin-export (lock is now lock-version 2.1, and poetry 2.x moved
  `export` into a plugin), pre-installed torch pin 2.0.0 -> 2.13.0.

verification
- npm: every one of the 76 alerts re-checked with semver against the new
  package-lock.json - all outside their vulnerable ranges. `npm ci` +
  `tsc -b && vite build` pass.
- pip: all 111 alerts re-checked against poetry.lock and requirements.txt.
  `poetry check --lock` passes; requirements.txt resolves cleanly under
  uv for py3.11 and py3.12 on linux/x86_64.
- runtime: fastapi 0.141 + starlette 1.4 smoke-tested over the exact surface
  app/ uses (CORSMiddleware, APIRouter prefix, UploadFile/File/Form multipart,
  HTTPException, pydantic body, OpenAPI). ultralytics 8.3.55 runs a forward
  pass and loads a .pt checkpoint on torch 2.13.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@taehan79-kim
taehan79-kim merged commit 686e02e into main Aug 5, 2026
2 of 4 checks passed
@namgyu-youn

namgyu-youn commented Aug 7, 2026 •

Copy link
Copy Markdown
Member

큰일 하셨네요 ㅋㅋ 저는 옛날에 dependabot을 써보다가, 빌드에 손대는 것이 얼마나 위험한지 깨닫고 이제는 안쓰고 있어요. 무엇보다 봇이 pr을 너무 많이 만드니 알람이 계속 울리고 피곤하더라고요. 실제로 버전 업데이트 한 뒤에 오류도 몇번 경험하니 신뢰도도 떨어져서 ㅎ

오픈소스들 보면 GitHub Action로 빌드 테스트하는 방식이 많은거 같아요~ 찾아보니까 긱뉴스에도 비슷한 글이 있네요 — https://news.hada.io/topic?id=26873

@namgyu-youn
namgyu-youn deleted the fix/dependabot-security-updates branch August 7, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants