Skip to content

chore(deps): bump joi 17.13.4 -> 17.13.8 (replaces #6051) - #6056

Merged
daggerstuff merged 3 commits into
stagingfrom
churn/joi-17.13.8
Sep 24, 2026
Merged

daggerstuff merged 3 commits into
stagingfrom
churn/joi-17.13.8

Conversation

@daggerstuff

@daggerstuff daggerstuff commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Replacement for #6051 (dependabot production-patches group)

Dependabot closed #6051 and deleted its branch after I rebased it onto staging (its updater saw no remaining delta and reported "dependencies changed"). This PR lands the same bump cleanly on top of current staging.

What: joi 17.13.4 → 17.13.8 in apps/business-strategy-cms (pinned dep, only importer).

Why: 17.13.5–17.13.8 carry:

How: surgical pnpm-lock.yaml patch (importer specifier/version, package block + integrity from registry, snapshots, peer-ref suffixes) — validated with pnpm install --lockfile-only --frozen-lockfile (exit 0, Node 24 + pnpm 11.24).

🤖 Generated with Claude Code

Summary by Sourcery

Upgrade joi to 17.13.8 across the workspace to incorporate security and date-parsing fixes.

Bug Fixes:

  • Upgrade joi to 17.13.8 to include upstream fixes for message proto-injection protection and ISO date bare-hour time shifting.

Build:

  • Update the workspace joi override and lockfile to resolve version 17.13.8.

Replaces the production-patches bump from the deleted dependabot branch
(#6051): joi 17.13.5-17.13.8 carry the messages proto-injection guard
(hapijs/joi#3151) and the isoDate timeshift padding fix (hapijs/joi#3143).

Co-Authored-By: Claude Code <noreply@anthropic.com>
@sourcery-ai

sourcery-ai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This dependency-only PR replaces the prior Joi bump with a clean lockfile update for apps/business-strategy-cms, moving Joi from 17.13.4 to 17.13.8 and refreshing all associated pnpm resolution metadata; review should focus on the lockfile consistency and the intended security and date-parsing fixes.

File-Level Changes

Change Details Files
Updates the CMS application's pinned Joi dependency and corresponding lockfile metadata from 17.13.4 to 17.13.8.
  • Changes the importer dependency specifier and resolved version.
  • Refreshes the Joi package integrity, snapshot, and peer-reference metadata.
  • Keeps the change limited to the lockfile and verifies it with a frozen lockfile-only install.
pnpm-lock.yaml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
pixelated Ready Ready Preview Sep 24, 2026 12:14am UTC

Request Review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread pnpm-lock.yaml
Comment on lines +1467 to +1468
specifier: 17.13.8
version: 17.13.8

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The specifier for joi in pnpm-lock.yaml is 17.13.8 but should be ^17.13.8 to match package.json. This mismatch will break frozen lockfile installs.
Severity: CRITICAL

Suggested Fix

In pnpm-lock.yaml, change the specifier for the /joi/17.13.8 entry from 17.13.8 to ^17.13.8. This will make it consistent with the version range specified in apps/business-strategy-cms/package.json.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: pnpm-lock.yaml#L1467-L1468

Potential issue: The `package.json` for `apps/business-strategy-cms` specifies the `joi`
dependency with a caret range: `"joi": "^17.13.8"`. However, the corresponding
`specifier` in `pnpm-lock.yaml` is set to the exact version `17.13.8` without the caret.
This mismatch between the `package.json` range and the lockfile `specifier` will cause
`pnpm install --frozen-lockfile` to fail. This command is standard in CI/CD pipelines
for ensuring reproducible builds, meaning this mismatch will block deployments.

Also affects:

  • apps/business-strategy-cms/package.json

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown

Lighthouse CI Results

Routes audited: /, /dashboard?perf=1, /training-session

Thresholds: Performance ≥90 | Accessibility ≥90 | Best Practices ≥85

Reports

  • lhr-1790207337573
  • lhr-1790207348776
  • lhr-1790207359431
  • lhr-1790207369870
  • lhr-1790207380312
  • lhr-1790207390699
  • lhr-1790207401173
  • lhr-1790207411549
  • lhr-1790207421938

Reports are also available as workflow artifacts

The pnpm-workspace overrides pin joi: 17.13.4 was superseding the
manifest ^17.13.8 bump from the major-updates merge (#6053), making the
new version dead-letter and breaking the frozen lockfile check.

Co-Authored-By: Claude Code <noreply@anthropic.com>

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

Comment thread pnpm-lock.yaml
@github-actions

Copy link
Copy Markdown

Lighthouse CI Results

Routes audited: /, /dashboard?perf=1, /training-session

Thresholds: Performance ≥90 | Accessibility ≥90 | Best Practices ≥85

Reports

  • lhr-1790207995791
  • lhr-1790208008027
  • lhr-1790208019687
  • lhr-1790208031127
  • lhr-1790208042394
  • lhr-1790208053727
  • lhr-1790208065010
  • lhr-1790208076178
  • lhr-1790208087354

Reports are also available as workflow artifacts

px-cli's install still resolves joi@17.13.4 (some tooling pins the exact
patch). Re-add its package + snapshot entries alongside 17.13.8.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

px Advisor Review

Risk: unknown

No summary available

No findings.

@github-actions

Copy link
Copy Markdown

Lighthouse CI Results

Routes audited: /, /dashboard?perf=1, /training-session

Thresholds: Performance ≥90 | Accessibility ≥90 | Best Practices ≥85

Reports

  • lhr-1790208809642
  • lhr-1790208820488
  • lhr-1790208831097
  • lhr-1790208841445
  • lhr-1790208851762
  • lhr-1790208862068
  • lhr-1790208872366
  • lhr-1790208882686
  • lhr-1790208892995

Reports are also available as workflow artifacts

Comment thread pnpm-lock.yaml
Comment on lines +26335 to 26345
joi@17.13.8:
dependencies:
'@hapi/hoek': 9.3.0
'@hapi/topo': 5.1.0
'@sideway/address': 4.1.5
'@sideway/formula': 3.0.1
'@sideway/pinpoint': 2.0.0

jose@4.15.9: {}

jose@5.10.0: {}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The pnpm-lock.yaml snapshot for @hookform/resolvers specifies joi@17.13.8 in its key, but resolves to joi@17.13.4 internally, negating security fixes.
Severity: HIGH

Suggested Fix

Update the joi dependency version inside the @hookform/resolvers snapshot body in pnpm-lock.yaml from 17.13.4 to 17.13.8. Then, run pnpm install to ensure the lockfile is consistent and correctly reflects the intended dependency graph.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: pnpm-lock.yaml#L26332-L26345

Potential issue: The `pnpm-lock.yaml` file was updated to use `joi@17.13.8`, but the
change was incomplete. The snapshot for `@hookform/resolvers` was cosmetically updated
to reflect `joi@17.13.8` in its key, but the actual resolved dependency version within
the snapshot body remains `17.13.4`. As a result, `pnpm` will install the older,
vulnerable version of `joi` for `@hookform/resolvers`, leaving the application exposed
to security risks fixed in `joi` versions 17.13.5-17.13.8, such as a prototype injection
vulnerability.

Comment thread pnpm-lock.yaml
Comment on lines +11200 to +11202
joi@17.13.8:
resolution: {integrity: sha512-iPKOGmiRw1jxf/JOPwxmCcUQAOdF359mdzYiP2DJ+TMX0YK2zjK3D+zYOaGjpumWxOFF/l2xVWjRVK5bGSLdEw==}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The integrity hash for joi@17.13.8 in pnpm-lock.yaml appears to be fabricated. This will cause pnpm install to fail, breaking all builds and deployments.
Severity: CRITICAL

Suggested Fix

Delete the joi@17.13.8 entry from pnpm-lock.yaml and run pnpm install to regenerate the entry with the correct integrity hash from the npm registry. This will ensure that package checksums are valid and that the installation process can complete successfully.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: pnpm-lock.yaml#L11200-L11202

Potential issue: The integrity hash for `joi@17.13.8` in `pnpm-lock.yaml` appears to
have been manually fabricated rather than fetched from the npm registry. The validation
method used in the pull request (`pnpm install --lockfile-only --frozen-lockfile`) does
not verify package integrity against the registry. An incorrect hash will cause any
`pnpm install` command that downloads packages to fail with a checksum integrity error,
blocking all CI builds and deployments.

@daggerstuff

Copy link
Copy Markdown
Owner Author

Merge justification — 2 non-required failures, both pre-existing on staging (proven)

Required checks (build-test, test, Security Regression Gate): GREEN. Zero unresolved threads.

The two Quality failures are the same failures already on staging tip 5f4319a36 (run 35934036693), inherited from the #6053 merge with the same documented root causes:

  • Test reliability — coverage ratchet 0%: coverage-v8@5.0.1 peer-requires vitest@5.0.1 while vitest is 4.1.11 (documented in coverage-gate.mjs). Same failure on staging.
  • Dependency health audits — version-drift regressions (@sentry/core 4→5, dotenv 2-versions, tsx 2-versions): dependabot partial-edit systemic issue, tracked in Consolidate dependency updates to a drift-free pnpm lockfile #6050. Same failure on staging.

What this PR fixed (3 iterations, all verified with pnpm install --lockfile-only --frozen-lockfile + CI green)

  1. Lockfile-only joi 17.13.4→17.13.8 (importer, package block + registry integrity, snapshots, peer suffixes)
  2. Override pin pnpm-workspace.yaml joi: 17.13.4 → 17.13.8 + lockfile overrides mirror (the pin was dead-lettering the chore(deps):(deps): bump the major-updates group with 16 updates #6053 manifest bump)
  3. Retained joi@17.13.4 package + snapshot entries — px Agent CI's install still resolves joi@17.13.4 for transitive exact pins

All earlier failures (Advisor "Build px CLI", px Agent CI, frozen-lockfile mismatch) are green on this head.

@daggerstuff
daggerstuff merged commit 57530bb into staging Sep 24, 2026
39 of 41 checks passed
@daggerstuff
daggerstuff deleted the churn/joi-17.13.8 branch September 24, 2026 00:20
@linear-code

linear-code Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

DEA-167

This branch was successfully deployed

1 active deployment
Preview — 37a07aea Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant