Repository navigation
chore(deps): bump joi 17.13.4 -> 17.13.8 (replaces #6051) - #6056
Conversation
Replaces the production-patches bump from the deleted dependabot branch (#6051): joi 17.13.5-17.13.8 carry the messages proto-injection guard (hapijs/joi#3151) and the isoDate timeshift padding fix (hapijs/joi#3143). Co-Authored-By: Claude Code <noreply@anthropic.com>
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis dependency-only PR replaces the prior Joi bump with a clean lockfile update for apps/business-strategy-cms, moving Joi from 17.13.4 to 17.13.8 and refreshing all associated pnpm resolution metadata; review should focus on the lockfile consistency and the intended security and date-parsing fixes. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
| specifier: 17.13.8 | ||
| version: 17.13.8 |
There was a problem hiding this comment.
Bug: The specifier for joi in pnpm-lock.yaml is 17.13.8 but should be ^17.13.8 to match package.json. This mismatch will break frozen lockfile installs.
Severity: CRITICAL
Suggested Fix
In pnpm-lock.yaml, change the specifier for the /joi/17.13.8 entry from 17.13.8 to ^17.13.8. This will make it consistent with the version range specified in apps/business-strategy-cms/package.json.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: pnpm-lock.yaml#L1467-L1468
Potential issue: The `package.json` for `apps/business-strategy-cms` specifies the `joi`
dependency with a caret range: `"joi": "^17.13.8"`. However, the corresponding
`specifier` in `pnpm-lock.yaml` is set to the exact version `17.13.8` without the caret.
This mismatch between the `package.json` range and the lockfile `specifier` will cause
`pnpm install --frozen-lockfile` to fail. This command is standard in CI/CD pipelines
for ensuring reproducible builds, meaning this mismatch will block deployments.
Also affects:
apps/business-strategy-cms/package.json
Did we get this right? 👍 / 👎 to inform future reviews.
Lighthouse CI ResultsRoutes audited: Thresholds: Performance ≥90 | Accessibility ≥90 | Best Practices ≥85 Reports
|
The pnpm-workspace overrides pin joi: 17.13.4 was superseding the manifest ^17.13.8 bump from the major-updates merge (#6053), making the new version dead-letter and breaking the frozen lockfile check. Co-Authored-By: Claude Code <noreply@anthropic.com>
Lighthouse CI ResultsRoutes audited: Thresholds: Performance ≥90 | Accessibility ≥90 | Best Practices ≥85 Reports
|
px-cli's install still resolves joi@17.13.4 (some tooling pins the exact patch). Re-add its package + snapshot entries alongside 17.13.8. Co-Authored-By: Claude Code <noreply@anthropic.com>
px Advisor ReviewRisk: unknown No summary available No findings. |
Lighthouse CI ResultsRoutes audited: Thresholds: Performance ≥90 | Accessibility ≥90 | Best Practices ≥85 Reports
|
| joi@17.13.8: | ||
| dependencies: | ||
| '@hapi/hoek': 9.3.0 | ||
| '@hapi/topo': 5.1.0 | ||
| '@sideway/address': 4.1.5 | ||
| '@sideway/formula': 3.0.1 | ||
| '@sideway/pinpoint': 2.0.0 | ||
|
|
||
| jose@4.15.9: {} | ||
|
|
||
| jose@5.10.0: {} |
There was a problem hiding this comment.
Bug: The pnpm-lock.yaml snapshot for @hookform/resolvers specifies joi@17.13.8 in its key, but resolves to joi@17.13.4 internally, negating security fixes.
Severity: HIGH
Suggested Fix
Update the joi dependency version inside the @hookform/resolvers snapshot body in pnpm-lock.yaml from 17.13.4 to 17.13.8. Then, run pnpm install to ensure the lockfile is consistent and correctly reflects the intended dependency graph.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: pnpm-lock.yaml#L26332-L26345
Potential issue: The `pnpm-lock.yaml` file was updated to use `joi@17.13.8`, but the
change was incomplete. The snapshot for `@hookform/resolvers` was cosmetically updated
to reflect `joi@17.13.8` in its key, but the actual resolved dependency version within
the snapshot body remains `17.13.4`. As a result, `pnpm` will install the older,
vulnerable version of `joi` for `@hookform/resolvers`, leaving the application exposed
to security risks fixed in `joi` versions 17.13.5-17.13.8, such as a prototype injection
vulnerability.
| joi@17.13.8: | ||
| resolution: {integrity: sha512-iPKOGmiRw1jxf/JOPwxmCcUQAOdF359mdzYiP2DJ+TMX0YK2zjK3D+zYOaGjpumWxOFF/l2xVWjRVK5bGSLdEw==} | ||
|
|
There was a problem hiding this comment.
Bug: The integrity hash for joi@17.13.8 in pnpm-lock.yaml appears to be fabricated. This will cause pnpm install to fail, breaking all builds and deployments.
Severity: CRITICAL
Suggested Fix
Delete the joi@17.13.8 entry from pnpm-lock.yaml and run pnpm install to regenerate the entry with the correct integrity hash from the npm registry. This will ensure that package checksums are valid and that the installation process can complete successfully.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: pnpm-lock.yaml#L11200-L11202
Potential issue: The integrity hash for `joi@17.13.8` in `pnpm-lock.yaml` appears to
have been manually fabricated rather than fetched from the npm registry. The validation
method used in the pull request (`pnpm install --lockfile-only --frozen-lockfile`) does
not verify package integrity against the registry. An incorrect hash will cause any
`pnpm install` command that downloads packages to fail with a checksum integrity error,
blocking all CI builds and deployments.
Merge justification — 2 non-required failures, both pre-existing on staging (proven)Required checks (build-test, test, Security Regression Gate): GREEN. Zero unresolved threads. The two Quality failures are the same failures already on staging tip
What this PR fixed (3 iterations, all verified with
|
Replacement for #6051 (dependabot production-patches group)
Dependabot closed #6051 and deleted its branch after I rebased it onto staging (its updater saw no remaining delta and reported "dependencies changed"). This PR lands the same bump cleanly on top of current staging.
What:
joi17.13.4 → 17.13.8 inapps/business-strategy-cms(pinned dep, only importer).Why: 17.13.5–17.13.8 carry:
How: surgical
pnpm-lock.yamlpatch (importer specifier/version, package block + integrity from registry, snapshots, peer-ref suffixes) — validated withpnpm install --lockfile-only --frozen-lockfile(exit 0, Node 24 + pnpm 11.24).🤖 Generated with Claude Code
Summary by Sourcery
Upgrade joi to 17.13.8 across the workspace to incorporate security and date-parsing fixes.
Bug Fixes:
Build: