chore(deps-dev): bump prettier-plugin-solidity from 2.3.1 to 2.4.1 - #334
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [prettier-plugin-solidity](https://github.com/prettier-solidity/prettier-plugin-solidity) from 2.3.1 to 2.4.1. - [Release notes](https://github.com/prettier-solidity/prettier-plugin-solidity/releases) - [Commits](prettier-solidity/prettier-plugin-solidity@v2.3.1...v2.4.1) --- updated-dependencies: - dependency-name: prettier-plugin-solidity dependency-version: 2.4.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
clestons
left a comment
There was a problem hiding this comment.
✅ APPROVE — #334
chore(deps-dev): bump prettier-plugin-solidity 2.3.1 → 2.4.1 · head 80ae4fb07116。
纯 devDependency 提升,不跑 Codex PK。这一个我要单独说一句,因为它顺手做了别的事:
- 它把三个包从
registry.npmmirror.com换回了registry.npmjs.org:
prettier-plugin-solidity·@nomicfoundation/slang(1.3.4→1.3.8)·@bytecodealliance/preview2-shim(0.17.9→0.19.0)。
方向是对的(镜像源 → 官方源),但这说明 base lockfile 是混源的:我数过,
base 里还剩 16 条registry.npmmirror.comvs 659 条registry.npmjs.org。
混源 lockfile 的问题不在于哪个源更好,而在于integrity的可复算性依赖于「谁在提供这个 tarball」;
剩下那 16 条值得单独一个 PR 一次性收敛掉,而不是靠 dependabot 碰到哪条换哪条。 - 新增包条目 0 个,只是版本号+源地址变化;3 条新
resolved各自都带integrity。 - 除
Security Audit/CI Success外全绿。
共同上下文(这五个 dependabot PR 我一起量的,各自单独判)
① Security Audit 这道闸门是红的,而且合了这个 PR 之后还是红的 —— 原因与本 PR 无关。
我读了失败日志,红的是 npm audit 那一步,high=4 critical=0:
high @nestjs/core >=7.6.0-next.1
high @nestjs/platform-express *
high @nestjs/swagger >=5.0.9
high multer <=2.2.0
这四个在 base lockfile 里都是生产依赖(dev=false:multer 2.2.0、@nestjs/* 12.0.1),
而这五个 PR 一行都没碰它们(我对每个 diff 都 grep 过 multer|@nestjs,命中数全是 0)。
所以「等 CI 全绿再合」在这个仓库现在做不到 —— 这是一笔独立的生产依赖欠账,值得单开一个 PR 收。
同一个 job 里还有第二处失败:Path does not exist: trivy-results.sarif(Trivy 那步没产出文件,上传步骤才报错),
这也是先于本 PR 就有的。
② 这五个 PR 的 lockfile 全部基于同一个 blob 4c6d8bb —— 谁先合,另外四个都得 rebase 重生成 lockfile。
Dependabot 会自己 rebase,但rebase 之后的那份 lockfile 没有人审过:合完第一个之后,
后面每一个都值得再看一眼「解析结果有没有变」,而不是沿用今天的读数。
clestons
left a comment
There was a problem hiding this comment.
⏸️ 补一条:本仓在 CC-115 B6 零合并冻结中 —— 上面那条 APPROVE 有效,但现在不要合。
(来自 yetanotheraa-validator-a5 会话:自 2026-09-05 起按 DSR 指令 §3 冻结,解冻条件是 DSR 发布 B6 evidence frozen。原因是论文证据链要钉在一个不动的部署上,合任何东西——包括纯 devDependency——都会让已冻结的证据失效。)
唯一的例外判据是「可外部触发 且 不可逆/涉资金密钥」。我上一条 review 里点名的那 4 条 high advisory 够不上这个例外,对方实测过:单一根因是生产依赖 multer 2.2.0,三个 @nestjs/* 只是经 platform-express 的传递效应;四条 advisory 全是 DoS 或上传限额绕过(不可逆=否、涉资金密钥=否),而且本服务全部 32 条 HTTP 路由里 FileInterceptor/FilesInterceptor/AnyFilesInterceptor/@UploadedFile/multipart 命中数全为 0,multer 从未挂到任何路由上 —— 四条 advisory 都要求攻击者发一个 multer 真正会去解析的 multipart 请求,这个前提在本 build 不成立。
同时订正我上一条 review 里一个会让人白跑一趟的暗示:这笔账 npm audit fix 修不掉。multer@latest = 2.3.0(修复版存在),但 @nestjs/platform-express@latest 已经是 12.0.1 且仍把 multer 钉在 2.2.0。上游没跟进,只能在 package.json 加 overrides 强推 2.3.0,再验 platform-express 在 2.3.0 上没有行为回归 —— 这是一个需要判断的改动,不是 dependabot 能代劳的。
另外一条补充(也来自对方实测):本机默认 registry 是 npmmirror,而它没有实现 audit 接口 —— npm audit 直接返回 [NOT_IMPLEMENTED] /-/npm/v1/security/*。所以任何人在本地跑 npm audit 会看到一个长得像「没问题」的错误输出。这让我上一条里说的「收敛混源 lockfile」从整洁问题升级成了量具问题,建议和 audit 欠账并成同一个 follow-up。
解冻之后再推进合并。
Bumps prettier-plugin-solidity from 2.3.1 to 2.4.1.
Release notes
Sourced from prettier-plugin-solidity's releases.
... (truncated)
Commits
b706a19bump version (#1668)5ebf165Bump@types/nodefrom 26.1.2 to 26.2.0 (#1672)6fd6cc3destructuringpretier.docandprettier.utilonly once (#1660)b7439bfupdating the format test framework to mirror prettier (#1669)b8c2ce1Removing GitPOAP (#1667)7414668Bump knip from 6.31.0 to 6.32.0 (#1670)d08e410Bump@nomicfoundation/slangfrom 1.3.7 to 1.3.8 (#1666)f547b84Bump@typescript-eslint/eslint-pluginfrom 8.65.0 to 8.66.0 (#1665)577e943Bump@types/semverfrom 7.7.1 to 7.8.0 (#1663)4d8cae7Bump globals from 17.8.0 to 17.9.0 (#1662)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)