Skip to content

Commit 5d2d19f

Browse files
authored
ENG-5629 Fix workflow-use dependency vulnerabilities (#170)
* Fix workflow-use dependency vulnerabilities * Address dependency review feedback
1 parent 891267b commit 5d2d19f

13 files changed

Lines changed: 1212 additions & 4485 deletions

File tree

‎.github/workflows/lint.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ jobs:
8787
- name: Setup Node.js
8888
uses: actions/setup-node@v4
8989
with:
90-
node-version: '20'
90+
node-version: '22'
9191
cache: 'npm'
9292
cache-dependency-path: extension/package-lock.json
9393

@@ -157,7 +157,7 @@ jobs:
157157
# - name: Setup Node.js
158158
# uses: actions/setup-node@v4
159159
# with:
160-
# node-version: '20'
160+
# node-version: '22'
161161
# cache: 'npm'
162162
# cache-dependency-path: extension/package-lock.json
163163
#

‎.github/workflows/publish.yml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,4 +55,8 @@ jobs:
5555
- uses: astral-sh/setup-uv@v5
5656
- run: uv run ruff check --no-fix --select PLE # check only for syntax errors
5757
- run: uv build
58+
# Use pip intentionally: unlike uv, it cannot apply this project's local
59+
# dependency overrides and therefore validates the published wheel graph.
60+
- name: Verify wheel dependencies resolve without uv overrides
61+
run: uvx --from pip pip install --dry-run --ignore-installed dist/*.whl
5862
- run: uv publish --token ${{ secrets.PYPI_API_TOKEN }}

‎extension/package-lock.json‎

Lines changed: 841 additions & 4234 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎extension/package.json‎

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -41,14 +41,19 @@
4141
"eslint-plugin-react-refresh": "0.4.24",
4242
"tw-animate-css": "1.3.4",
4343
"typescript": "5.8.3",
44-
"wxt": "0.20.7"
44+
"wxt": "0.21.4"
4545
},
4646
"overrides": {
4747
"shell-quote": "1.10.0",
4848
"node-forge": "1.4.0",
49-
"tar": "7.5.20",
49+
"tar": "7.5.21",
5050
"rollup": "4.62.2",
51-
"js-yaml": "4.3.0",
51+
"@babel/core": "7.29.6",
52+
"ajv@6": "6.14.0",
53+
"brace-expansion@1": "1.1.18",
54+
"brace-expansion@2": "2.1.4",
55+
"brace-expansion@5": "5.0.9",
56+
"js-yaml": "4.3.1",
5257
"minimatch@3": "3.1.5",
5358
"minimatch@9": "9.0.9",
5459
"minimatch@10": "10.2.5",
@@ -59,6 +64,7 @@
5964
"tmp": "0.2.7",
6065
"uuid": "11.1.1",
6166
"vite": "6.4.3",
67+
"nanoid": "3.3.18",
6268
"postcss": "8.5.24",
6369
"ws": "8.21.0"
6470
}

‎extension/src/entrypoints/background.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
// import { eventWithTime } from 'rrweb'; // Type not directly available
22
import { EventType, IncrementalSource } from "@rrweb/types";
3-
import {
3+
import type {
44
StoredCustomClickEvent,
55
StoredCustomInputEvent,
66
StoredCustomKeyEvent,
77
StoredEvent,
88
StoredRrwebEvent,
99
StoredExtractionEvent,
1010
} from "../lib/types";
11-
import {
11+
import type {
1212
ClickStep,
1313
InputStep,
1414
KeyPressStep,
@@ -18,7 +18,7 @@ import {
1818
Workflow,
1919
ExtractStep,
2020
} from "../lib/workflow-types";
21-
import {
21+
import type {
2222
HttpEvent,
2323
HttpRecordingStartedEvent,
2424
HttpRecordingStoppedEvent,

‎extension/src/entrypoints/content.ts‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,7 @@ function getXPath(element: HTMLElement): string {
2222
if (siblings) {
2323
for (let i = 0; i < siblings.length; i++) {
2424
const sibling = siblings[i];
25+
if (!sibling) continue;
2526
if (sibling === element) {
2627
return `${getXPath(
2728
element.parentElement as HTMLElement
@@ -744,6 +745,7 @@ function handleSelectChange(event: Event) {
744745
const allOptions: Array<{text: string, value: string}> = [];
745746
for (let i = 0; i < targetElement.options.length; i++) {
746747
const option = targetElement.options[i];
748+
if (!option) continue;
747749
allOptions.push({
748750
text: option.text.trim(),
749751
value: option.value

‎extension/src/entrypoints/sidepanel/components/event-viewer.tsx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
import React, { useEffect, useRef } from "react";
2-
import {
2+
import type {
33
ClickStep,
44
InputStep,
55
KeyPressStep,

‎extension/src/entrypoints/sidepanel/context/workflow-provider.tsx‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
import React, {
22
createContext,
3-
ReactNode,
43
useCallback,
54
useContext,
65
useEffect,
76
useState,
87
} from "react";
9-
import { Workflow } from "../../../lib/workflow-types"; // Adjust path as needed
8+
import type { ReactNode } from "react";
9+
import type { Workflow } from "../../../lib/workflow-types";
1010

1111
type WorkflowState = {
1212
workflow: Workflow | null;

‎extension/src/lib/message-bus-types.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
import { Workflow } from "./workflow-types"; // Assuming Workflow is in this path
1+
import type { Workflow } from "./workflow-types";
22

33
// Types for events sent via HTTP to the Python server
44

0 commit comments

Comments
 (0)