Skip to content

ci(deps): shipped-dependency audit fails on brace-expansion, fast-uri and axios advisories #5905

Description

@liugddx

The audit and Build immutable tarball checks fail on every PR, including unrelated ones such as #5902, #5895 and #5882. The cause is new advisories that now reach the shipped dependency closure:

Package Locked Severity Fixed in
brace-expansion 5.0.9 high 5.0.12
fast-uri 3.1.7 moderate (GHSA-hrr3-gc8f-f4qj) 3.1.8
axios (transitive, via @larksuiteoapi/node-sdk and @wecom/aibot-node-sdk) 1.18.1 high (12 advisories, e.g. GHSA-vh66-26gq-q6x8, GHSA-r4gj-5m52-g5wh) 1.20.0

scripts/audit-shipped-dependencies.mjs reports them for the product closure. The CLI tarball build fails npm audit --omit=dev --workspace maka-agent for the same reason.

Why the Dependabot PRs don't fix it. Dependabot has two open PRs: #5881 (brace-expansion) and #5882 (fast-uri). Neither can go green on its own:

  • each one fixes a single advisory, so the audit still fails on the other one (chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 #5881's audit log reports only fast-uri);
  • neither regenerates the committed third-party notices, so check:release (check:third-party-notices) fails with "production dependency notices are stale".

There is no Dependabot PR for the transitive axios.

Fix: take both bumps, move axios to 1.20.0 within the existing ^1.x ranges, and regenerate the desktop and CLI third-party notices with the pinned npm (11.19.0), all in one PR.

Activity

  1. added a commit that references this issue on Oct 2, 2026
    cf5c531
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions