fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq - #1147

Merged
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981
Apr 23, 2026
Merged

fix: override uuid to ^14.0.0 to patch GHSA-w5hq-g745-h8pq#1147
brendan-kellam merged 3 commits into
mainfrom
bkellam/fix-sou-981

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-981

Summary

  • Adds a resolutions entry forcing uuid@^14.0.0 across the workspace, consolidating five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0) into one patched version.
  • Vulnerable copies were pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai, @langchain/core, langchain, langsmith, @langchain/langgraph, and @langchain/langgraph-sdk.
  • GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's v3/v5/v6 APIs when a caller-provided buf is passed. A call-site audit showed no consumer in this tree passes a buf argument, so the vulnerable code path is not reachable — this is an SCA-alert cleanup, not a fix for a live runtime issue.

Notes on the upgrade

uuid@14 drops CommonJS support (since v12) and requires Node 20+ (v14). Sourcebot ships on Node 24 with require(esm) support, and named-export require('uuid') usage from the CJS consumers (bullmq, @sentry/webpack-plugin) works cleanly.

Test plan

  • yarn install succeeds and yarn.lock consolidates to a single uuid@14.0.0
  • yarn build passes
  • yarn test passes
  • BullMQ job enqueue works end-to-end (worker/queue/flow-producer all call require('uuid'))
  • @sourcebot/web production build with Sentry release upload succeeds (@sentry/webpack-plugin)
  • LangGraph / @posthog/ai agent run succeeds (exercises v5/v6 call sites in langgraph-checkpoint and langsmith)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated uuid dependency to version 14.0.0.

Fixes SOU-981
Adds a yarn resolution forcing `uuid@^14.0.0` across the workspace,
consolidating the five vulnerable copies (9.0.1, 10.0.0, 11.1.0, 13.0.0)
pulled transitively via bullmq, @sentry/webpack-plugin, @posthog/ai,
@langchain/core, langchain, langsmith, @langchain/langgraph, and
@langchain/langgraph-sdk into a single non-vulnerable version.
GHSA-w5hq-g745-h8pq describes missing buffer bounds checks in uuid's
v3/v5/v6 APIs when a caller-provided `buf` is passed. A call-site audit
showed the vulnerable code path is not reachable in this tree (no
consumer passes a `buf` argument), so the override is a cleanup to
silence SCA alerts rather than a fix for a live runtime issue.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 672d5c39-985b-42f3-9eb4-6757572aa865

📥 Commits

Reviewing files that changed from the base of the PR and between 0eb791b and 2cfd942.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Updates the transitive uuid dependency constraint to ^14.0.0 in the package.json resolutions section and documents this change in the changelog.

Changes

Cohort / File(s)Summary
UUID Dependency Resolution Update
CHANGELOG.md, package.json
Added changelog entry documenting the UUID transitive dependency update, and updated the package.json resolutions section to pin uuid to ^14.0.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/fix-sou-981

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits April 23, 2026 12:30
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 9abe2d4 into mainApr 23, 2026
6 of 7 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/fix-sou-981 branch April 23, 2026 19:32
@github-actionsgithub-actionsBot mentioned this pull request Apr 23, 2026
@github-actions

github-actionsBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

License Audit

Status: FAIL

MetricCount
Total packages2054
Resolved (non-standard)7
Unresolved4
Strong copyleft0
Weak copyleft39

Fail Reasons

  • 4 packages have unresolvable licenses: @react-grab/cli@0.1.23, @react-grab/cli@0.1.29, @react-grab/mcp@0.1.29, element-source@0.0.3

Unresolved Packages

PackageVersionLicenseReason
@react-grab/cli0.1.23UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/cli0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
@react-grab/mcp0.1.29UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation
element-source0.0.3UNKNOWNNo license field on npm registry; no repository or homepage URL available for further investigation

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (7)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/codemirror-lang-elixir)
lezer-elixir1.1.2UNKNOWNApache-2.0npm page / GitHub repo (https://github.com/livebook-dev/lezer-elixir)
map-stream0.1.0UNKNOWNMITnpm page / GitHub repo (https://github.com/dominictarr/map-stream)
memorystream0.3.1UNKNOWNMITnpm page / GitHub repo (https://github.com/JSBizon/node-memorystream)
pause-stream0.0.11["MIT","Apache2"]MIT OR Apache-2.0GitHub repo (https://github.com/dominictarr/pause-stream) - dual licensed, users may choose either
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (https://github.com/PostHog/posthog-js) - LICENSE file confirms Apache-2.0
valid-url1.0.9UNKNOWNMITGitHub repo (https://github.com/ogt/valid-url) - LICENSE file confirms MIT

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam