Skip to content

Release 2026.10.3.1: clear 12 undici alerts, minor-and-patch group, pin ecowitt2mqtt - #68

Merged
timothybrown merged 3 commits into
mainfrom
chore/dep-remediation-2026-10-03
Oct 3, 2026
Merged

timothybrown merged 3 commits into
mainfrom
chore/dep-remediation-2026-10-03

Conversation

@timothybrown

@timothybrown timothybrown commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Supersedes #67, which CI rejected. Also pins the ecowitt2mqtt Docker image and bumps the version to 2026.10.3.1.

Three commits, meant to be rebase-merged so each stays distinct on main:

  1. chore(deps): clear 12 undici alerts + minor-and-patch group
  2. chore(docker): pin ecowitt2mqtt image to 2026.01.0
  3. chore(release): bump version to 2026.10.3.1

Why #67 could not be merged

#67 failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Dependabot regenerates pnpm-lock.yaml without the pnpm.overrides block, so pnpm install --frozen-lockfile refuses the lockfile. This is the known failure mode. The fix is to re-resolve locally with overrides intact and supersede, never to merge as-is. #67 would also have left the vulnerable undici in place.

Security alerts cleared (12 → 0)

All 12 open alerts are undici (4 high, 6 medium, 2 low), every one fixed in 7.29.1.

Alerts Severity Advisory range
#108 (new today, TLS cert validation bypass) high >= 7.24.1, < 7.29.1
#66–#70 1 high, 4 medium < 7.29.0
#30–#34, #36 2 high, 2 medium, 2 low < 7.28.0

How they came back: #63's orval 8.34 bump pulled in @scalar/json-magic 0.13.5 and 0.14.0. Both declare an exact undici: 7.24.4 dependency, so a vulnerable copy landed next to the patched 7.29.1, and the 11 old alerts reopened the day #63 merged.

Fix: a new undici: ^7.29.1 override floor. Bumping orval or scalar would not hold: the latest @scalar/json-magic (0.15.4) still pins undici exactly, at 7.29.1, so the next undici advisory would reopen this. The floor stays within 7.x, which is what json-magic's own newer releases already use. The lockfile now has a single undici@7.29.1.

Also raised (advisories published 2026-09-29, not yet alerted by GitHub)

Package Advisories Fix
brace-expansion 2 high, 1 moderate (DoS) 5.0.9 → 5.0.12 (override floor raised)
fast-uri moderate 3.1.7 → 3.1.8 (override floor raised)

pnpm audit: 27 → 1. The remaining finding is braces 3.0.3 (GHSA-vfj7-8cjw-p6xm), which has no patched release. It's reached only through eslint-config-next → fast-glob → micromatch (lint tooling, never shipped).

All overrides use caret floors, not exact pins.

minor-and-patch group (#67)

At #67's exact targets: @tanstack/react-query 5.103.2, next/eslint-config-next 16.3.6, tailwind-merge 3.7.0, orval 8.37.0.

pnpm's resolver initially picked @tanstack/react-query 5.104.1 and orval 8.39.0, which are 1–2 days old. Held them back to #67's versions to respect the 7-day cooldown. Every newly added package version in the lockfile is at least 9 days old.

Pin ecowitt2mqtt to 2026.01.0

docker/docker-compose.yml used bachya/ecowitt2mqtt:latest, which follows upstream's newest tag. Upstream dev now carries our BGT/WBGT support (bachya/ecowitt2mqtt#1401), which unit-converts those fields. Our parser's FAHRENHEIT_FIELDS also converts them, so the next upstream release would double-convert silently (30 °C stored as −1.1 °C, inside the plausibility bounds).

2026.01.0 is the current :latest (same digest), so nothing changes today. A comment on the service says to bump the tag only in the same change that removes FAHRENHEIT_FIELDS. Verified with docker compose config.

Version bump

backend/pyproject.toml, frontend/package.json and backend/uv.lock → 2026.10.3.1. Only the editable app version line changed in uv.lock: uv 0.12.22 also wanted to bump the lockfile revision 3 → 5, which I kept at 3 because the Pi deploys with uv 0.11.3. uv lock --check passes under both versions.

Verification

Ran the frontend CI gate locally:

Backend dependencies are untouched (no Python alerts open); only its version changed.

🤖 Generated with Claude Code

https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM

Supersedes #67, which CI rejected with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH:
Dependabot regenerated pnpm-lock.yaml without the `pnpm.overrides`
block. Re-resolved locally instead, keeping overrides intact.

Security alerts cleared (12 -> 0, all undici, fixed in 7.29.1):
- 11 of the 12 were reopened by #63. Its orval 8.34 bump pulled in
  @scalar/json-magic 0.13.5/0.14.0, which declare an exact
  `undici: 7.24.4` dependency, so a vulnerable copy landed beside the
  patched 7.29.1. #108 (TLS cert validation bypass) is new today.
- Added an `undici: ^7.29.1` override floor. Bumping orval/scalar would
  not hold: json-magic 0.15.4 still pins undici exactly (7.29.1), so
  the next advisory would reopen this. The floor stays within 7.x,
  which is what json-magic's own newer releases already use.

Also raised two existing floors for advisories published 2026-09-29
that GitHub has not alerted on yet: fast-uri ^3.1.8 and
brace-expansion ^5.0.12. pnpm audit: 27 -> 1. The remaining one is
braces 3.0.3 (GHSA-vfj7-8cjw-p6xm), which has no patched release; it is
reached only through eslint-config-next's lint toolchain.

minor-and-patch group (#67), at #67's exact targets:
@tanstack/react-query 5.103.2, next/eslint-config-next 16.3.6,
tailwind-merge 3.7.0, orval 8.37.0. pnpm's resolver picked
react-query 5.104.1 and orval 8.39.0 (1-2 days old); held them back to
respect the 7-day cooldown. Every newly added package version in the
lockfile is at least 9 days old.

Overrides use caret floors, not exact pins.

Verified locally: pnpm install --frozen-lockfile succeeds; generate
(byte-identical output under orval 8.37), tsc, lint and build clean;
601 tests pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
timothybrown and others added 2 commits October 3, 2026 09:45
`:latest` resolves to upstream's newest tag, so a new ecowitt2mqtt
release would be picked up with no change on our side. Upstream `dev`
now carries our BGT/WBGT support (bachya/ecowitt2mqtt#1401), which
unit-converts those fields; our parser's FAHRENHEIT_FIELDS also
converts them, so the next release would double-convert silently
(30 C stored as -1.1 C, inside the plausibility bounds).

2026.01.0 is the current `:latest` (same digest), so this changes
nothing today. Bump the tag only in the same change that removes
FAHRENHEIT_FIELDS.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
backend/uv.lock: only the editable app version line changed. Running
`uv lock` with uv 0.12.22 also bumped the lockfile `revision` 3 -> 5;
kept revision 3 because the Pi deploys with uv 0.11.3. Verified with
uv 0.11.3 and 0.12.22 that `uv lock --check` passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
@timothybrown timothybrown changed the title chore(deps): clear 12 undici alerts + minor-and-patch group (supersedes #67) Release 2026.10.3.1: clear 12 undici alerts, minor-and-patch group, pin ecowitt2mqtt Oct 3, 2026
@timothybrown
timothybrown merged commit ee0badd into main Oct 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant