[auto-sec] Consolidate aspire-samples dependency security remediations - #1782
[auto-sec] Consolidate aspire-samples dependency security remediations#1782David Pine (IEvangelist) wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
This PR consolidates multiple dependency security remediations across the aspire-samples repo by updating pinned/locked dependency versions and introducing npm overrides to enforce patched minima in affected sample apps.
Changes:
- Add
overridesto multiple samplepackage.jsonfiles to force patched versions ofesbuildand@babel/core, plus additional overrides in the Angular sample. - Update multiple
package-lock.jsonfiles to reflect the remediated dependency graph. - Update Python
uv.lockto bumpstarletteto a patched version (transitive via FastAPI).
Reviewed changes
Copilot reviewed 9 out of 19 changed files in this pull request and generated 9 comments.
Show a summary per file
| File | Description |
|---|---|
| samples/vite-yarp-static/package.json | Adds overrides to pin esbuild to a patched version. |
| samples/vite-yarp-static/package-lock.json | Updates lockfile to reflect patched esbuild resolution. |
| samples/vite-react-fastapi/package.json | Adds overrides to pin esbuild to a patched version. |
| samples/vite-react-fastapi/package-lock.json | Updates lockfile to reflect patched esbuild resolution. |
| samples/rag-document-qa-svelte/api/uv.lock | Updates locked Python dependency graph (notably starlette). |
| samples/python-openai-agent/package.json | Adds overrides to pin esbuild to a patched version. |
| samples/python-openai-agent/package-lock.json | Updates lockfile to reflect patched esbuild resolution. |
| samples/python-fastapi-postgres/package.json | Adds overrides to pin esbuild to a patched version. |
| samples/python-fastapi-postgres/package-lock.json | Updates lockfile to reflect patched esbuild resolution. |
| samples/polyglot-task-queue/package.json | Adds overrides to pin esbuild to a patched version. |
| samples/polyglot-task-queue/package-lock.json | Updates lockfile to reflect patched esbuild resolution. |
| samples/node-express-redis/package.json | Adds overrides to pin esbuild to a patched version. |
| samples/node-express-redis/package-lock.json | Updates lockfile to reflect patched esbuild resolution. |
| samples/aspire-with-python/frontend/package.json | Adds overrides to pin @babel/core to a patched version. |
| samples/aspire-with-python/frontend/package-lock.json | Updates lockfile to reflect patched @babel/* resolution. |
| samples/aspire-with-javascript/AspireJavaScript.Vite/package.json | Adds overrides to pin @babel/core to a patched version. |
| samples/aspire-with-javascript/AspireJavaScript.Vite/package-lock.json | Updates lockfile to reflect patched @babel/* resolution. |
| samples/aspire-with-javascript/AspireJavaScript.Angular/package.json | Bumps @angular/core and adds multiple security-related overrides. |
| samples/aspire-with-javascript/AspireJavaScript.Angular/package-lock.json | Updates Angular lockfile to reflect remediations and dependency graph changes. |
Files not reviewed (9)
- samples/aspire-with-javascript/AspireJavaScript.Angular/package-lock.json: Generated file
- samples/aspire-with-javascript/AspireJavaScript.Vite/package-lock.json: Generated file
- samples/aspire-with-python/frontend/package-lock.json: Generated file
- samples/node-express-redis/package-lock.json: Generated file
- samples/polyglot-task-queue/package-lock.json: Generated file
- samples/python-fastapi-postgres/package-lock.json: Generated file
- samples/python-openai-agent/package-lock.json: Generated file
- samples/vite-react-fastapi/package-lock.json: Generated file
- samples/vite-yarp-static/package-lock.json: Generated file
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Responding to the automated Copilot reviewer comments about registry drift (all 9 are the same concern): The lockfiles in this PR resolve packages from the Evidence: all 3 CI jobs (Build & Test Samples ubuntu, Build & Test Samples windows, license/cla) pass cleanly, confirming the feed is accessible and packages resolve correctly. If contributors outside the Microsoft network need to install dependencies locally, they should configure their npm registry to point at |
b0e90c8 to
470ea88
Compare
|
The build failures on both ubuntu and windows are pre-existing C# package vulnerabilities, not caused by this PR:
This PR's scope: npm (JavaScript/TypeScript) and Python (Starlette) security fixes. The C# package vulnerabilities exist on npm/Python changes are verified:
Next: A separate PR should consolidate the C# vulnerabilities (MessagePack, Microsoft.OpenApi, etc.). This PR should merge once the C# blocker is lifted or independently gated. |
07b09a7 to
6300905
Compare
6300905 to
ba632d5
Compare
ba632d5 to
f9e551c
Compare
a8ef49b to
80ce692
Compare
Review feedback addressed (2026-07-29)Copilot reviewer: lockfile registry URLs (9 threads)The lockfiles were regenerated using the Microsoft internal npm proxy (ms-feed-*.pkgs.visualstudio.com), which produced non-standard resolved URLs and sha1 integrity hashes instead of Fixed in commit fc0c1eb:
Damian Edwards (@DamianEdwards): Directory.Build.props (2 threads)The central PackageVersion approach was reverted in commit e6ddef5 — no .props, .targets, or .csproj files are changed in the current diff. Replied to both threads to clarify. |
|
Fixed the ubuntu npm ERESOLVE in the Angular sample by aligning samples/aspire-with-javascript/AspireJavaScript.Angular/package.json back to ypescript@~6.0.3, which matches @angular-devkit/build-angular@22.0.9's supported peer range. This should unblock Build & Test Samples (ubuntu-latest). |
|
Fixed the Angular CI failure by aligning samples/aspire-with-javascript/AspireJavaScript.Angular/package.json back to the versions already committed in the lockfile ( ypescript@~6.0.3 and the matching Angular 22.0.7/22.0.5 ranges). The ubuntu npm ERESOLVE came from manifest/lockfile drift, not from the security remediation itself. |
|
Follow-up fix pushed in c2a7d1b: Angular package.json and package-lock.json are now realigned so the AppHost �ngular-installer |
4b3e3c7 to
a13d63b
Compare
37876a2 to
b41e197
Compare
CI status update
The security remediation itself (36/44 transitive advisories) is verified by the fully-green windows leg plus per-lockfile version checks. |
73c25bc to
84280d2
Compare
CI status — pre-existing
|
84280d2 to
1d7855c
Compare
✅ CI now green — ready for reviewRun The final blocker — the Angular Only remaining gate is an external approving review (self-approval isn't permitted). Not enabling auto-merge. |
34effae to
84bf000
Compare
…obufjs (GHSA-j3f2-48v5-ccww) Surgical transitive-dependency security bumps (lockfile-only, public-registry sha512): - brace-expansion 5.0.5 -> 5.0.7 (9 manifests) and 1.1.15 -> 1.1.16 (Angular): clears 10 HIGH ReDoS alerts (GHSA-3jxr-9vmj-r5cp) - protobufjs 7.6.4 -> 7.6.5 (polyglot-task-queue/api): clears 1 MEDIUM alert (GHSA-j3f2-48v5-ccww) Branch reset onto clean upstream/main to remove prior internal-feed (sha1) lock contamination; all integrities are public registry sha512. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
84bf000 to
62c0e8a
Compare
Canonical security remediation — aspire-samples dependency alerts
[auto-sec]canonical for the aspire-samples dependency/security cluster.Branch
dapire/security-deps/aspire-samples-lowrisk-batch, reset onto the latestmainand labeledautomated-security.✅ Remediated in this PR (verified, lockfile-only, public-registry
sha512)5.0.5 → 5.0.71.1.15 → 1.1.167.6.4 → 7.6.511 alerts cleared (10 HIGH + 1 MEDIUM) — this is every HIGH-severity alert that is
remediable against the reachable public npm registry.
Verification
package-lock.jsononly (nopackage.jsonchurn); each dependency's recorded dependency ranges remain satisfied by the
already-locked siblings, so the lockfiles stay
npm ci-consistent.sha512. Confirmed 0 internal-feed URLs and0
sha1-integrities across all locks; every lockfile re-parses as valid JSON.mainto remove prior internal-feed lock contamination.⏸️ Deferred — patched version not on the reachable public registry (environmental version skew)
These advisories'
first_patched_versionvalues do not resolve on the public npmregistry available in this environment, so they cannot be applied without pulling from
an internal feed (which would re-contaminate the public lockfiles). Left open and
tracked; the underlying Dependabot alerts remain open.
⏸️ Deferred — requires full lockfile regeneration (blocked in this environment)
Patched versions do resolve, but these packages pin exact sibling sets
(e.g.
@esbuild/*platform binaries,@babel/*helpers) that require a fullnpm installtree recompute. Full-tree regen currently fails here due to npm cachecontention (
Exit handler never called!) and public-registry TLS handshake failures.Will be applied once a healthy npm environment is available.
CI status
main, unrelated to this PR.npm ciinAspireJavaScript.Angularfails with ERESOLVE — the sample declarestypescript@~7.0.2but@angular-devkit/build-angular@22.0.8requires peertypescript@">=6.0 <6.1"(conflicttypescript@6.0.3). Theangular-installerresource exits1, failingAppHostRunsCleanlyandTestEndpointsReturnOkfor the AspireJavaScript AppHost.Aspire Samples CIrun formainat this PR's base commita768e2ffails identically (Failed: 2, Passed: 19). These transitivebrace-expansion/protobufjslockfile bumps are change-neutral w.r.t. that test (same 2-fail/19-pass on both). Fixing the unrelated Angular TypeScript peer conflict is out of scope for this security PR.Status
main).[auto-sec]PR for the cluster — one per repo.