Dependency Vulnerability Remediation — 2026-08-06
Trigger: GitHub reported 52 open Dependabot vulnerabilities on main
(operator-visible count, 2026-08-06). This session cannot read the Dependabot
alert API, so remediation was driven by local audits of the same manifests
(npm audit per lockfile, pip-audit per requirements file). Local counts
and the GitHub alert count are related but not identical (GitHub counts one
alert per advisory per manifest). Alert closure must be verified in the
GitHub Security tab after this merge — operator step.
All figures below are measured results from this branch (2026-08-06).
npm — all five lockfile surfaces now audit clean
| Directory | Before (high/total) | After |
|---|---|---|
/ (workspace root) |
2 → 11 surfaced | 0 |
miz-oki-command-center-ui |
2 | 0 |
services/customer-journey-system/frontend |
1 | 0 |
services/ekis |
12 | 0 |
mcp |
3 (2 high, 1 moderate) | 0 |
What was actually vulnerable (everything else was via cascade):
brace-expansionDoS advisories (GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 bypassing the CVE-2026-14257 mitigation; vulnerable<=1.1.17and>=4.0.0 <5.0.9) — every locked1.1.xnode bumped to 1.1.18 and every5.0.xnode to 5.0.9 (both inside every dependent's declared semver range, sonpm ciresolution is unchanged in shape).fast-uri,ip-address,hono,minimatch/glob/eslint-chain — cleared bynpm audit fix(semver-compatible only; no--force, no major bumps).
Verification: npm audit per directory (total: 0 in all five) and a root
npm install --package-lock-only --dry-run --legacy-peer-deps consistency
pass. node_modules were not installed; app builds were not run here.
pip — Dependabot-scoped manifests (.github/dependabot.yml alert-debt set)
| Manifest | Before | After |
|---|---|---|
src/cells/cell16/requirements.txt |
10 (8× starlette, 1× protobuf, dup ids) | 0 |
miz-oki-adk-agents/boss/requirements.v5.3.txt (deployed image) |
4 | 1 (protobuf, see residuals) |
miz-oki-adk-agents/boss/requirements.txt (legacy, no Dockerfile references it) |
10 | starlette advisories cleared; protobuf residual remains |
Changes (each combination resolver-verified with
pip install --dry-run --python-version 3.11 --only-binary=:all:):
- cell16:
fastapi 0.109.1 → 0.141.1+ explicitstarlette==1.4.1(clears PYSEC-2026-161/248/249/1941/1943/2280/2281 — fixes required starlette ≥1.3.1, impossible under fastapi 0.109's<0.36cap);google-cloud-logging 3.10.0 → 3.12.1(lifts theprotobuf<5cap) + explicitprotobuf==5.29.6(PYSEC-2026-1805; resolver selectsgrpcio-status 1.71.2). - boss legacy
requirements.txt: same fastapi/starlette lift (sse-starlette==1.8.2co-resolves — verified). This file is not used by any Dockerfile (deploys userequirements.v5.3.txt) but still generates alerts. - aiohttp
3.14.1 → 3.14.3(PYSEC-2026-3545/3546/3547, patch-level) in all 13 current manifests that pinned it (boss v5/v5.1/v5.2/v5.3, local_dev, cell29, monitoring, scripts, tests, command-center backend + orchestrator, deployment, health_monitor).archive/copies untouched.
Residuals — open findings, honestly recorded
- protobuf 4.25.9 on the boss image (PYSEC-2026-1805). The v5.x google
pins (
firestore==2.14.0,bigquery==3.17.0,pubsub==2.19.0) capprotobuf<5/ holdgrpcio-status 1.62.x— measuredResolutionImpossiblewithprotobuf==5.29.6. Fix requires bumping that google constellation together (recipe proven on cell16: logging ≥3.12 lifts the cap; grpcio-status ≥1.63 accepts protobuf 5). That is a deployed Boss image change — route through a reviewed Dependabot/operator PR with a post-deploy/healthcheck, not a blind pin edit. fastapi==0.109.1in ~50 further manifests across cells/services (each carrying the same 8 starlette advisories transitively). The cell16 recipe applies, but mass-editing 50 deployed services without per-service verification trades a DoS-class advisory for deploy risk — contrary to the production-hardening priority. Rollout path: the weekly grouped Dependabot PRs (.github/dependabot.yml, MIZ-SEC-2026-001) plus per-service deploy verification, using this document as the recipe.- Local-only verification. Everything above is
implemented+ resolver/audit-verified in this tree. No image was rebuilt, no service redeployed, no app build run from the patched lockfiles in this session. The Deploy Router rebuilds affected images on merge; treat the first post-merge deploy of boss/cell16 as the runtime verification gate (latestReady == latestCreated+ authed/health). - Pre-existing, untouched:
neo4j==5.17.0/==5.14.1in the boss requirement files are invisible to this environment's PyPI index view under--only-binary(older sdist-only releases) — measured failing on the pristine tree too; not introduced or modified here.
Re-run the audits
for d in . miz-oki-command-center-ui services/customer-journey-system/frontend services/ekis mcp; do
(cd "$d" && npm audit)
done
pip-audit -r src/cells/cell16/requirements.txt --no-deps
pip-audit -r miz-oki-adk-agents/boss/requirements.v5.3.txt --no-deps