Repository navigation
chore(release): 2.10.0 step 1 — audit, audit fixes, bump to 2.10.0 - #2627
Merged
Merged
Conversation
Critical: IP spoofing via an IPv4-mapped IPv6 trust subnet. Reached via express@5.2.1 in the root install; 2.0.8 is inside express's declared range, so this is a lockfile-only bump, not an override. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
High: event-loop DoS through indexed source-map section offsets. Reached via postcss (vite / tsup) and magicast (@vitest/coverage-v8) in the root, web and tui installs - build/dev tooling only, nothing shipped. 1.2.2 is in postcss's declared range: lockfile-only in all three, one version across installs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
There was a problem hiding this comment.
🟢 Approval recommended
The version metadata and targeted dependency updates are consistent, with no identified blocking defects.
0 open findings
What changed in this PR
Prepares Inspector 2.10.0 on v2/main ahead of the separate release merge.
Changes:
- Bumps root version metadata from 2.9.0 to 2.10.0.
- Updates
proxy-addrto 2.0.8. - Aligns
source-map-jsat 1.2.2 across root, web, and TUI installs.
| File | Description |
|---|---|
| package.json | Sets the release version to 2.10.0. |
| package-lock.json | Updates release metadata and both audited dependencies. |
| clients/web/package-lock.json | Updates source-map-js to 1.2.2. |
| clients/tui/package-lock.json | Updates source-map-js to 1.2.2. |
Files not reviewed (2)
- clients/tui/package-lock.json: Generated file
- clients/web/package-lock.json: Generated file
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Member
Author
|
Copilot review loop closed: round 1 was clean (0 findings — no inline comments, nothing in the headline or a suppressed block), so no further round was requested. |
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #2622
Step 1 of the v2.10.0 release, per the
releaseskill: the audit report, the fixes it forced, and the version bump, in one PR. Step 2 (the milestone merge intomain) is #2623.npm audit --audit-level=high— reportRun across all six installs (root, web, cli, tui, launcher, mcpdo) against
origin/v2/main:proxy-addr2.0.7express@5.2.1source-map-js1.2.1postcss(vite / tsup),magicast(@vitest/coverage-v8) — build tooling onlycli, launcher and mcpdo: 0 vulnerabilities.
Fixes — one commit each
Both have an upward fix inside the declared range, so each is a targeted
npm update <pkg>— lockfile-only, nooverrides, nonpm audit fix, nothing downgraded. Each lockfile diff is exactly the one package's version/resolved/integrity.proxy-addr2.0.7 → 2.0.8 (root)source-map-js1.2.1 → 1.2.2 (root, web, tui — one version across installs)Re-audit after both: 0 vulnerabilities in all six installs.
Bump
npm version minor --no-git-tag-version: 2.9.0 → 2.10.0. No tag — the release tag goes on the merge commit onmainin step 2.Verification
npm run local:gateon the rebased branch (defaultTMPDIR, now that #2609 / #2626 landed): every stage green — DCO (3/3 signed), all test suites (web 8957, cli 581 + 2 skipped, mcpdo 490, tui 627, launcher 8), build gate, bundle externals, launcher/cli/tui/web smokes, all four Chromium web smokes — exceptsmoke:web:firefox, which cannot launch Playwright's Firefox on macOS 27 on this machine at all (unrelated to this diff; #2625). That failure stops the chain before Storybook, sonpm run local:storybookwas run separately: 123 files / 529 tests passed.Correction: an earlier version of this body said CI runs the Firefox smoke. It does not —
smoke:web:firefoxis the local gate's one local-only stage (#2086,docs/quality-gate.md), so the Firefox engine pass has not run for this PR anywhere. This diff is lockfile + version only, so the exposure is small, but it is unverified rather than covered.🤖 Generated with Claude Code