Skip to content

Commit 63031f5

Browse files
Include the fully audited Pi dependency fix in PR 242
2 parents fe63768 + dc8c513 commit 63031f5

4 files changed

Lines changed: 25 additions & 26 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 7 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -241,30 +241,15 @@ jobs:
241241
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
242242
run: |
243243
npm ci --ignore-scripts
244+
# The test host's published shrinkwrap overrides this package's nested pin.
245+
# Repair that exact leaf in the installed host, preserving its other locked deps.
246+
# --omit=dev excludes the host's own authoring tools, not this package's test tools.
247+
npm install --prefix node_modules/@earendil-works/pi-coding-agent --ignore-scripts --no-save --omit=dev brace-expansion@5.0.12
248+
node -e "require('node:assert/strict').equal(require('./node_modules/@earendil-works/pi-coding-agent/node_modules/brace-expansion/package.json').version, '5.0.12')"
244249
npm run verify
245250
npm run test:integration
246-
npm audit --omit=dev
247-
# Development advisories fail too, except inside the Pi test host: it ships its own
248-
# npm-shrinkwrap.json, which npm overrides cannot change. Those stay visible as
249-
# warnings until a host release with a fixed lockfile is adopted.
250-
npm audit --json > "$RUNNER_TEMP/pi-audit.json" || true
251-
python - "$RUNNER_TEMP/pi-audit.json" <<'PY'
252-
import json
253-
import sys
254-
255-
with open(sys.argv[1], encoding="utf-8") as handle:
256-
report = json.load(handle)
257-
host = "node_modules/@earendil-works/pi-coding-agent"
258-
blocking = []
259-
for name, vulnerability in sorted(report.get("vulnerabilities", {}).items()):
260-
nodes = vulnerability.get("nodes") or []
261-
if nodes and all(node == host or node.startswith(host + "/") for node in nodes):
262-
print(f"::warning::{name} ({vulnerability.get('severity')}) is pinned by the Pi test host")
263-
else:
264-
blocking.append(f"{name} ({vulnerability.get('severity')})")
265-
if blocking or "vulnerabilities" not in report:
266-
sys.exit("npm audit found development advisories: " + (", ".join(blocking) or "no report"))
267-
PY
251+
npm audit
252+
npm audit --no-package-lock --include=dev
268253
269254
browser-accessibility:
270255
name: browser accessibility smoke

‎CHANGELOG.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,11 @@ All notable changes to Engraphis are documented here. Format loosely follows
1414
- Retire consumed refresh credentials when a successful response has an invalid
1515
token subject, and keep empty graph-layer selections separate from all-layer cache entries.
1616

17+
- Updated the Pi extension's locked `fast-uri` to 3.1.8, `ip-address` to 10.7.2 and
18+
`brace-expansion` to 5.0.12. CI repairs the Pi test host's embedded vulnerable leaf with
19+
that exact pin, verifies the installed version, and audits both the full dependency lock
20+
and installed tree. Pi checks use bash on Windows, so every install, build, test and audit
21+
failure stops the job.
1722
- Provide a valid offline decision example in Smart MCP action discovery.
1823
- Reject coerced numeric/string remote consent before Classic MCP can select a Jev backend.
1924
- Retain global entities referenced by workspace edges during secure erasure,

‎integrations/pi/README.md‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,10 +112,19 @@ in normal recall. This behavior is intentional and unchanged by the Pi extension
112112
## Development
113113

114114
```bash
115-
npm install --ignore-scripts
115+
npm ci --ignore-scripts
116+
npm install --prefix node_modules/@earendil-works/pi-coding-agent --ignore-scripts --no-save --omit=dev brace-expansion@5.0.12
116117
npm run verify
118+
npm audit
119+
npm audit --no-package-lock --include=dev
117120
```
118121

122+
The pinned Pi test host includes its own shrinkwrap, which reinstalls an older
123+
`brace-expansion` despite this package's fixed nested pin. The scoped install repairs
124+
that exact dependency while retaining the host's other locked dependencies. Its
125+
`--omit=dev` excludes the host's own authoring tools; the extension's development
126+
dependencies remain installed and audited. CI also verifies the installed version.
127+
119128
`npm run verify` type-checks the package, runs its configuration tests, and previews
120129
the publish tarball. The package pins the MCP SDK; update it only with a compatibility
121130
test against the supported Pi and Engraphis releases.

‎integrations/pi/npm-shrinkwrap.json‎

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)