Skip to content

chore(release): 2.10.0 step 1 — audit, audit fixes, bump to 2.10.0 - #2627

Merged
cliffhall merged 3 commits into
v2/mainfrom
v2/chore/2622-bump-2-10-0
Oct 7, 2026
Merged

cliffhall merged 3 commits into
v2/mainfrom
v2/chore/2622-bump-2-10-0

Conversation

@cliffhall

@cliffhall cliffhall commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Closes #2622

Step 1 of the v2.10.0 release, per the release skill: the audit report, the fixes it forced, and the version bump, in one PR. Step 2 (the milestone merge into main) is #2623.

npm audit --audit-level=high — report

Run across all six installs (root, web, cli, tui, launcher, mcpdo) against origin/v2/main:

Advisory Package Severity Installs Reached via
GHSA-jqcg-44mw-7w3h — IP spoofing via IPv4-mapped IPv6 trust subnet proxy-addr 2.0.7 critical root express@5.2.1
GHSA-68fv-2mgg-jv7q — event-loop DoS via indexed source-map section offsets source-map-js 1.2.1 high root, web, tui postcss (vite / tsup), magicast (@vitest/coverage-v8) — build tooling only

cli, launcher and mcpdo: 0 vulnerabilities.

Fixes — one commit each

Both have an upward fix inside the declared range, so each is a targeted npm update <pkg> — lockfile-only, no overrides, no npm audit fix, nothing downgraded. Each lockfile diff is exactly the one package's version/resolved/integrity.

  1. proxy-addr 2.0.7 → 2.0.8 (root)
  2. source-map-js 1.2.1 → 1.2.2 (root, web, tui — one version across installs)

Re-audit after both: 0 vulnerabilities in all six installs.

Bump

npm version minor --no-git-tag-version: 2.9.0 → 2.10.0. No tag — the release tag goes on the merge commit on main in step 2.

Verification

npm run local:gate on the rebased branch (default TMPDIR, now that #2609 / #2626 landed): every stage green — DCO (3/3 signed), all test suites (web 8957, cli 581 + 2 skipped, mcpdo 490, tui 627, launcher 8), build gate, bundle externals, launcher/cli/tui/web smokes, all four Chromium web smokes — except smoke:web:firefox, which cannot launch Playwright's Firefox on macOS 27 on this machine at all (unrelated to this diff; #2625). That failure stops the chain before Storybook, so npm run local:storybook was run separately: 123 files / 529 tests passed.

Correction: an earlier version of this body said CI runs the Firefox smoke. It does not — smoke:web:firefox is the local gate's one local-only stage (#2086, docs/quality-gate.md), so the Firefox engine pass has not run for this PR anywhere. This diff is lockfile + version only, so the exposure is small, but it is unverified rather than covered.

🤖 Generated with Claude Code

cliffhall and others added 3 commits October 7, 2026 13:40
Critical: IP spoofing via an IPv4-mapped IPv6 trust subnet. Reached via
express@5.2.1 in the root install; 2.0.8 is inside express's declared
range, so this is a lockfile-only bump, not an override.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
High: event-loop DoS through indexed source-map section offsets. Reached
via postcss (vite / tsup) and magicast (@vitest/coverage-v8) in the root,
web and tui installs - build/dev tooling only, nothing shipped. 1.2.2 is
in postcss's declared range: lockfile-only in all three, one version
across installs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall cliffhall added the v2 Issues and PRs for v2 label Oct 7, 2026
@cliffhall cliffhall linked an issue Oct 7, 2026 that may be closed by this pull request
@cliffhall
cliffhall requested a balanced review from Copilot October 7, 2026 17:47

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The version metadata and targeted dependency updates are consistent, with no identified blocking defects.

0 open findings

What changed in this PR

Prepares Inspector 2.10.0 on v2/main ahead of the separate release merge.

Changes:

  • Bumps root version metadata from 2.9.0 to 2.10.0.
  • Updates proxy-addr to 2.0.8.
  • Aligns source-map-js at 1.2.2 across root, web, and TUI installs.
File Description
package.json Sets the release version to 2.10.0.
package-lock.json Updates release metadata and both audited dependencies.
clients/​web/​package-lock.json Updates source-map-js to 1.2.2.
clients/​tui/​package-lock.json Updates source-map-js to 1.2.2.
Files not reviewed (2)
  • clients/tui/package-lock.json: Generated file
  • clients/web/package-lock.json: Generated file

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@cliffhall

Copy link
Copy Markdown
Member Author

Copilot review loop closed: round 1 was clean (0 findings — no inline comments, nothing in the headline or a suppressed block), so no further round was requested.

@cliffhall
cliffhall merged commit 710c990 into v2/main Oct 7, 2026
10 checks passed
@cliffhall
cliffhall deleted the v2/chore/2622-bump-2-10-0 branch October 7, 2026 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release 2.10.0 step 1: bump version to 2.10.0 on v2/main

2 participants