From f5b86a3772fab1ce1b93af0c7dc1b952ccab08ee Mon Sep 17 00:00:00 2001 From: Rebecca Hum Date: Mon, 13 Jul 2026 14:05:58 -0600 Subject: [PATCH 1/6] ci: sync shrinkwrap for Dependabot --- .github/workflows/sync-shrinkwrap.yml | 44 ++++++++++++++++ npm-shrinkwrap.json | 74 +++++++++++++++++++-------- 2 files changed, 96 insertions(+), 22 deletions(-) create mode 100644 .github/workflows/sync-shrinkwrap.yml diff --git a/.github/workflows/sync-shrinkwrap.yml b/.github/workflows/sync-shrinkwrap.yml new file mode 100644 index 000000000..6292c1081 --- /dev/null +++ b/.github/workflows/sync-shrinkwrap.yml @@ -0,0 +1,44 @@ +name: Sync npm shrinkwrap + +on: + pull_request_target: + types: + - opened + - reopened + - synchronize + paths: + - package.json + - package-lock.json + - npm-shrinkwrap.json + +permissions: + contents: write + pull-requests: read + +jobs: + sync: + name: Sync npm-shrinkwrap.json + if: github.actor == 'dependabot[bot]' && github.event.pull_request.head.repo.full_name == github.repository + runs-on: ubuntu-latest + steps: + - name: Check out pull request branch + uses: actions/checkout@v7 + with: + repository: ${{ github.event.pull_request.head.repo.full_name }} + ref: ${{ github.event.pull_request.head.ref }} + token: ${{ secrets.GITHUB_TOKEN }} + + - name: Sync npm-shrinkwrap.json + run: | + cp package-lock.json npm-shrinkwrap.json + + if git diff --quiet -- npm-shrinkwrap.json; then + echo "npm-shrinkwrap.json already matches package-lock.json" + exit 0 + fi + + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add npm-shrinkwrap.json + git commit -m "chore: sync npm shrinkwrap" + git push diff --git a/npm-shrinkwrap.json b/npm-shrinkwrap.json index 7bab6aea4..453d0b6cf 100644 --- a/npm-shrinkwrap.json +++ b/npm-shrinkwrap.json @@ -69,6 +69,10 @@ "vip-config-software-update": "dist/bin/vip-config-software-update.js", "vip-db": "dist/bin/vip-db.js", "vip-db-phpmyadmin": "dist/bin/vip-db-phpmyadmin.js", + "vip-defensive-mode": "dist/bin/vip-defensive-mode.js", + "vip-defensive-mode-configure": "dist/bin/vip-defensive-mode-configure.js", + "vip-defensive-mode-disable": "dist/bin/vip-defensive-mode-disable.js", + "vip-defensive-mode-enable": "dist/bin/vip-defensive-mode-enable.js", "vip-dev-env": "dist/bin/vip-dev-env.js", "vip-dev-env-create": "dist/bin/vip-dev-env-create.js", "vip-dev-env-destroy": "dist/bin/vip-dev-env-destroy.js", @@ -5667,16 +5671,42 @@ } }, "node_modules/axios": { - "version": "1.15.2", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.15.2.tgz", - "integrity": "sha512-wLrXxPtcrPTsNlJmKjkPnNPK2Ihe0hn0wGSaTEiHRPxwjvJwT3hKmXF4dpqxmPO9SoNb2FsYXj/xEo0gHN+D5A==", + "version": "1.18.1", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.18.1.tgz", + "integrity": "sha512-3nTvFlvpn9Zu/RkHUqtc7/+al4UpRW5az71ap5zccp6e8RAYEzhMTecX8Dz1wWDYrPpUoB1HAQEGEAEvUr7S9g==", "license": "MIT", "dependencies": { - "follow-redirects": "^1.15.11", + "follow-redirects": "^1.16.0", "form-data": "^4.0.5", + "https-proxy-agent": "^5.0.1", "proxy-from-env": "^2.1.0" } }, + "node_modules/axios/node_modules/agent-base": { + "version": "6.0.2", + "resolved": "https://registry.npmjs.org/agent-base/-/agent-base-6.0.2.tgz", + "integrity": "sha512-RZNwNclF7+MS/8bDg70amg32dyeZGZxiDuQmZxKLAlQjr3jGyLx+4Kkk58UO7D2QdgFIQCovuSuZESne6RG6XQ==", + "license": "MIT", + "dependencies": { + "debug": "4" + }, + "engines": { + "node": ">= 6.0.0" + } + }, + "node_modules/axios/node_modules/https-proxy-agent": { + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/https-proxy-agent/-/https-proxy-agent-5.0.1.tgz", + "integrity": "sha512-dFcAjpTQFgoLMzC2VwU+C/CbS7uRL0lWmxDITmqm7C+7F0Odmj6s9l6alZc6AELXhrnggM2CeWSXHGOdX2YtwA==", + "license": "MIT", + "dependencies": { + "agent-base": "6", + "debug": "4" + }, + "engines": { + "node": ">= 6" + } + }, "node_modules/axobject-query": { "version": "4.1.0", "resolved": "https://registry.npmjs.org/axobject-query/-/axobject-query-4.1.0.tgz", @@ -7034,15 +7064,15 @@ } }, "node_modules/engine.io-client": { - "version": "6.6.5", - "resolved": "https://registry.npmjs.org/engine.io-client/-/engine.io-client-6.6.5.tgz", - "integrity": "sha512-QCwxUDULPlXv8F6tqMMKx5dNkTe6OaBYRMPYeXKBlyOoKvAmE0ac6pW7fFhSscJ/5SI7666/U/B+MElbsrJlIg==", + "version": "6.6.6", + "resolved": "https://registry.npmjs.org/engine.io-client/-/engine.io-client-6.6.6.tgz", + "integrity": "sha512-iY6QdftLQ9pyiPoX082bpf/u1UewnOaJrtJIF9T0++QB34lZrj0uP+Q/bj8AlUsAxqhnkTV2BS8SBZSxOmoV5Q==", "license": "MIT", "dependencies": { "@socket.io/component-emitter": "~3.1.0", "debug": "~4.4.1", "engine.io-parser": "~5.2.1", - "ws": "~8.20.1", + "ws": "~8.21.0", "xmlhttprequest-ssl": "~2.1.1" } }, @@ -8527,16 +8557,16 @@ } }, "node_modules/form-data": { - "version": "4.0.5", - "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.5.tgz", - "integrity": "sha512-8RipRLol37bNs2bhoV67fiTEvdTrbMUYcFTiy3+wuuOnUog2QBHCZWXDRijWQfAkhBj2Uf5UnVaiWwA5vdd82w==", + "version": "4.0.6", + "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.6.tgz", + "integrity": "sha512-vKatAh4SlVfgbv+YtmhiRjhEMJsYpsG1Y2rMQtR+SVSbytsSD1YGzDIcrAJmdFec88u/+VoGmxnl+80gL1tRCQ==", "license": "MIT", "dependencies": { "asynckit": "^0.4.0", "combined-stream": "^1.0.8", "es-set-tostringtag": "^2.1.0", - "hasown": "^2.0.2", - "mime-types": "^2.1.12" + "hasown": "^2.0.4", + "mime-types": "^2.1.35" }, "engines": { "node": ">= 6" @@ -8988,9 +9018,9 @@ } }, "node_modules/hasown": { - "version": "2.0.2", - "resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.2.tgz", - "integrity": "sha512-0hJU9SCPvmMzIBdZFqNPXWa6dqh7WdH0cII9y+CyS8rG3nL48Bclra9HmKhVVUHyPWNH5Y7xDwAB7bfgSjkUMQ==", + "version": "2.0.4", + "resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.4.tgz", + "integrity": "sha512-T2UbfbBEF32wiepXIsMlTW9+dDYC6wMh/t/vYA4tuOMKqWz/n3vr1NFSxQiyP+zk2mXsoMA/i/7qV6LKut1t1A==", "license": "MIT", "dependencies": { "function-bind": "^1.1.2" @@ -14172,9 +14202,9 @@ } }, "node_modules/tar": { - "version": "7.5.19", - "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.19.tgz", - "integrity": "sha512-4LeEWl96twnS2Q7Bz4MGqgazLqO+hJN63GZxXoIqh1T3VweYD997gbU1ItNsQafqqXTXd5WFyFdReLtwvRBNiw==", + "version": "7.5.20", + "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.20.tgz", + "integrity": "sha512-9FcyK4PA6+WbzlTM9WhQm6vB5W7cP7dUiPsv1g7YDwEQnQ1CGpK3MGlKk/ITVWMk05kHZuBhmVhiv8LZoy/PFQ==", "license": "BlueOak-1.0.0", "dependencies": { "@isaacs/fs-minipass": "^4.0.0", @@ -15309,9 +15339,9 @@ } }, "node_modules/ws": { - "version": "8.20.1", - "resolved": "https://registry.npmjs.org/ws/-/ws-8.20.1.tgz", - "integrity": "sha512-It4dO0K5v//JtTXuPkfEOaI3uUN87iYPnqo/ZzqCoG3g8uhA66QUMs/SrM0YK7/NAu+r4LMh/9dq2A7k+rHs+w==", + "version": "8.21.0", + "resolved": "https://registry.npmjs.org/ws/-/ws-8.21.0.tgz", + "integrity": "sha512-Vsp28b7DRcimFQvrqu2Wek3z1iYxDCWqHYB8Qsnk/S4RfaCQzPGPyBNuVjJV3cd6UiKtUtp6sNM77gWvzcCH+g==", "license": "MIT", "engines": { "node": ">=10.0.0" From af3bcc3a6225291d16ff1b646a7cb4db6fce6188 Mon Sep 17 00:00:00 2001 From: Rebecca Hum Date: Mon, 13 Jul 2026 14:10:18 -0600 Subject: [PATCH 2/6] Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .github/workflows/sync-shrinkwrap.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sync-shrinkwrap.yml b/.github/workflows/sync-shrinkwrap.yml index 6292c1081..c1eda9c23 100644 --- a/.github/workflows/sync-shrinkwrap.yml +++ b/.github/workflows/sync-shrinkwrap.yml @@ -25,7 +25,7 @@ jobs: uses: actions/checkout@v7 with: repository: ${{ github.event.pull_request.head.repo.full_name }} - ref: ${{ github.event.pull_request.head.ref }} + ref: ${{ github.event.pull_request.head.sha }} token: ${{ secrets.GITHUB_TOKEN }} - name: Sync npm-shrinkwrap.json From 08424dee2d3d38313b44ab14e7ba56d6352867e0 Mon Sep 17 00:00:00 2001 From: Rebecca Hum Date: Mon, 13 Jul 2026 14:10:25 -0600 Subject: [PATCH 3/6] Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .github/workflows/sync-shrinkwrap.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sync-shrinkwrap.yml b/.github/workflows/sync-shrinkwrap.yml index c1eda9c23..e26913281 100644 --- a/.github/workflows/sync-shrinkwrap.yml +++ b/.github/workflows/sync-shrinkwrap.yml @@ -41,4 +41,4 @@ jobs: git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git add npm-shrinkwrap.json git commit -m "chore: sync npm shrinkwrap" - git push + git push origin HEAD:${{ github.event.pull_request.head.ref }} From 9ac41e625cad8f5bd9041b8a71b03e440a6ab2c2 Mon Sep 17 00:00:00 2001 From: Rebecca Hum Date: Mon, 13 Jul 2026 14:10:59 -0600 Subject: [PATCH 4/6] Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .github/workflows/sync-shrinkwrap.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sync-shrinkwrap.yml b/.github/workflows/sync-shrinkwrap.yml index e26913281..9c7f755ad 100644 --- a/.github/workflows/sync-shrinkwrap.yml +++ b/.github/workflows/sync-shrinkwrap.yml @@ -11,10 +11,13 @@ on: - package-lock.json - npm-shrinkwrap.json +concurrency: + group: sync-shrinkwrap-${{ github.event.pull_request.number }} + cancel-in-progress: true + permissions: contents: write pull-requests: read - jobs: sync: name: Sync npm-shrinkwrap.json From 5a20b42f5535966cf6586eaf3667bc28650acb9d Mon Sep 17 00:00:00 2001 From: Rebecca Hum Date: Mon, 13 Jul 2026 14:12:47 -0600 Subject: [PATCH 5/6] Potential fix for pull request finding 'CodeQL / Code injection' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/sync-shrinkwrap.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sync-shrinkwrap.yml b/.github/workflows/sync-shrinkwrap.yml index 9c7f755ad..a410fffeb 100644 --- a/.github/workflows/sync-shrinkwrap.yml +++ b/.github/workflows/sync-shrinkwrap.yml @@ -32,6 +32,8 @@ jobs: token: ${{ secrets.GITHUB_TOKEN }} - name: Sync npm-shrinkwrap.json + env: + PR_HEAD_REF: ${{ github.event.pull_request.head.ref }} run: | cp package-lock.json npm-shrinkwrap.json @@ -44,4 +46,4 @@ jobs: git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git add npm-shrinkwrap.json git commit -m "chore: sync npm shrinkwrap" - git push origin HEAD:${{ github.event.pull_request.head.ref }} + git push origin "HEAD:${PR_HEAD_REF}" From 20828bf070c855dd387e8c3aeff8e0f949e75c18 Mon Sep 17 00:00:00 2001 From: Rebecca Hum Date: Mon, 13 Jul 2026 14:14:14 -0600 Subject: [PATCH 6/6] Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .github/workflows/sync-shrinkwrap.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/sync-shrinkwrap.yml b/.github/workflows/sync-shrinkwrap.yml index a410fffeb..b15075bcd 100644 --- a/.github/workflows/sync-shrinkwrap.yml +++ b/.github/workflows/sync-shrinkwrap.yml @@ -35,6 +35,16 @@ jobs: env: PR_HEAD_REF: ${{ github.event.pull_request.head.ref }} run: | + set -euo pipefail + + for f in package-lock.json npm-shrinkwrap.json; do + if [ -L "$f" ]; then + echo "$f must not be a symlink" + exit 1 + fi + done + + rm -f npm-shrinkwrap.json cp package-lock.json npm-shrinkwrap.json if git diff --quiet -- npm-shrinkwrap.json; then