Repository navigation
Repin live minimist@1.2.2 suites to republished patch 642d7f02 (#1293) - #1301
Merged
Merged
Conversation
Production withdrew free patch 80630680-4da6-45f9-bba8-b888e0ffd58c for pkg:npm/minimist@1.2.2 between 15:29Z and 15:49Z on 2026-10-09 and republished the CVE-2021-44906 fix at 15:57:30Z as 642d7f02-ebc1-4ab0-99e2-07f5dd8463cb. The new patch also touches test/proto.js, and its patched index.js hashes to ec956dca... instead of 043f04d1... (the pristine beforeHash is unchanged). Repin every suite that resolves the patch against the live proxy: e2e_hosted_production, e2e_vendored_production, e2e_npm, e2e_safety_pnpm, backtest-bun.py, backtest-vlt.py (also drives vlt-serve-watchdog) and the bun-compatibility doc. Offline fixtures and mocked tests keep the old UUID as an opaque string. Fixes #1293 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Oct 9, 2026
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
Port of #1302 (fixes #1293). Production withdrew the free minimist@1.2.2 patch 80630680-… and republished the same fix as 642d7f02-…, with a new patched index.js (afterHash ec956dca…). That turned hosted-e2e and e2e_safety_pnpm red on main and here. No-ops once main carries #1302 or #1301. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mzbk9WDZkhatFrCWUAyaNs
This was referenced Oct 9, 2026
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
Ports #1301 so this PR's CI is not blocked by #1293: production no longer serves the free minimist@1.2.2 patch 80630680, which breaks hosted-e2e and e2e_safety_pnpm on main as well. Same change as #1301; it becomes a no-op once #1301 lands on main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YRcjmQwhWGod7X58Hbe5FW
Collaborator
Author
|
Ready for review (burn-down agent).
Generated by Claude Code |
Collaborator
Author
|
[agent] Heads-up from #1290, which ports this change: once Generated by Claude Code |
This was referenced Oct 9, 2026
Wenxin Jiang (Wenxin-Jiang)
approved these changes
Oct 9, 2026
The republished minimist patch uses package-relative file keys. Strip only an optional package/ prefix so root files do not crash the native matrix and nested files retain their directories. Exercise prefixed and unprefixed records before and after patching, including corrupt and missing nested files. The regression reproduces the original IndexError and the 85-test harness suite passes with this fix.
Mikola Lysenko (mikolalysenko)
removed this pull request from the merge queue due to a manual request
Oct 9, 2026
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
hosted-e2e (and the other live minimist suites) fail on every head: production now serves minimist@1.2.2 patch 642d7f02 while the tests pin 80630680 (#1293). This is #1301's change, applied verbatim; it becomes a no-op once #1301 lands. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VrgiQoDwt3vjxG2zNfZBAA
This was referenced Oct 9, 2026
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
The production patch server withdrew the minimist@1.2.2 patch these suites pinned (#1293), so hosted-e2e, e2e_safety_pnpm and the Bun and vlt backtests are red on main and on every PR. This carries #1301's repin to the republished patch 642d7f02 unchanged; it becomes a no-op once #1301 lands on main. Assisted-by: Claude Code:claude-opus-5-5
2 tasks done
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
Port of #1301 (fixes #1293). Production withdrew the free minimist@1.2.2 patch 80630680 and republished the fix as 642d7f02, which turned hosted-e2e, e2e_safety_pnpm and every Bun native leg red here as on main. The vlt harness also now reads the republished patch's unprefixed file keys. Test-only; a no-op once main carries #1301. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mo7HM9gyRkUAMxWqi62Dxz
This was referenced Oct 9, 2026
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
Brings in #1301, which repins the live minimist@1.2.2 suites to the republished patch. That clears the hosted-e2e and e2e_safety_pnpm failures this PR inherited from main, so its CI can go green. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 9, 2026
Co-Authored-By: Claude <noreply@anthropic.com>
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1293.
Production withdrew the free
minimist@1.2.2patch80630680-4da6-45f9-bba8-b888e0ffd58cand republished the CVE-2021-44906 fix as642d7f02-ebc1-4ab0-99e2-07f5dd8463cb. The live test pins must follow the new artifact to unblock the merge queue.Changes
index.jsGit SHA-256 toec956dcafb886f14315570bf3981d44aa12c561716abb46eed8b067aaa1f6bdf. The pristine hash is unchanged.index.jsandtest/proto.jswithout apackage/prefix. Remove only that optional prefix, preserving nested paths and compatibility with older records. This fixes the nine failing native vlt jobs on the original revision.Offline mock UUIDs remain fixture identifiers. No production CLI behavior or
CHANGELOG.mdchanges.Validation
On macOS with Node 24.21.0:
python3 -B -m unittest scripts.tests.test_backtest_harnesses -q: 85 tests, OK (one platform skip). The new regression reproduced the originalIndexErrorbefore the fix.backtest-vlt.py --versions 1.2.0 --modes hosted vendored agent --jobs 3: all 36/36 live-production scenarios matched expectations, with no server-encoding blocks.cargo test --locked -p socket-patch-cli --test e2e_safety_pnpm --test e2e_hosted_production -- --include-ignored: 65 hosted + 23 pnpm tests passed. The hosted suite's Bun and pinned-vlt legs soft-skipped because their toolchains were not configured; the standalone vlt backtest above exercised vlt directly.index.jsassertions match.af6164ca7is pushed. CI, Bun compatibility, and vlt compatibility all passed: 282 successful checks, 12 conditional skips, zero failures or pending checks. Both required gates (ci-okandclippy) and all ten checks that failed on the original revision are green.The original PR validation also recorded v5 expectation drift in the on-demand
e2e_npmshortcut/global tests and the vendored Yarn Berry manifest check. Those suites are outside the CI gate and their expectations are unchanged here.Note
Low Risk
Test and documentation constant updates only; no production CLI or runtime behavior changes.
Overview
Production republished the free minimist@1.2.2 patch (same CVE-2021-44906 fix) under a new UUID after withdrawing
80630680-…. This PR repins every live-production and backtest harness that depended on the old artifact.NPM_UUID/UUIDis now642d7f02-ebc1-4ab0-99e2-07f5dd8463cbin hosted/vendored production e2e (e2e_hosted_production,e2e_vendored_production), npm e2e (e2e_npm,e2e_safety_pnpm),scripts/backtest-bun.py,scripts/backtest-vlt.py, anddocs/testing/bun-compatibility.md.Content assertions for the patched
index.jsuse the new after git-blob hash (ec956dca…); the unpatched before hash is unchanged. Offline mocks and fixtures that only used the old UUID as an opaque string were intentionally left alone.Reviewed by Cursor Bugbot for commit d344040. Configure here.