Skip to content

chore: upgrade thrift and @tiptap/* to resolve Dependabot alerts - #9874

Merged
nishantmonu51 merged 3 commits into
mainfrom
hsingh/dependabot-thrift-tiptap
Sep 21, 2026
Merged

nishantmonu51 merged 3 commits into
mainfrom
hsingh/dependabot-thrift-tiptap

Conversation

@himadrisingh

@himadrisingh himadrisingh commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Resolves three open Dependabot security alerts:

  • github.com/apache/thrift 0.22.0 → 0.24.0 — GHSA-8wv5-x4w7-5gww (high): infinite loop in the Go bindings. Transitive via databricks-sql-go → runtime/drivers/databricks; a clean one-line bump with no cascade.
  • @tiptap/* (8 packages) 3.20.1 → 3.31.3 — GHSA-j95f-988m-3j2f (high): quadratic ReDoS in Markdown attribute parsing, and GHSA-cp6q-959q-f8rh (medium): mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes. All @tiptap/* packages move together since the library requires matching versions across the family.

Verified: go build ./... passes, npm run build passes for both web-local and web-admin, and svelte-check reports no errors at the three @tiptap call sites under web-common/src/features/chat/core/.

The grpc alert is handled separately in #9873, since that one cascades a large set of transitive upgrades. The two PRs overlap on go.mod, so whichever merges second needs a rebase.

Checklist:

  • Covered by tests
  • Ran it and it works as intended
  • Reviewed the diff before requesting a review
  • Checked for unhandled edge cases
  • Linked the issues it closes
  • Checked if the docs need to be updated. If so, create a separate Linear DOCS issue
  • Intend to cherry-pick into the release branch
  • I'm proud of this work!

Developed in collaboration with Claude Code

🤖 Generated with Claude Code

- `github.com/apache/thrift` 0.22.0 -> 0.24.0 (GHSA-8wv5-x4w7-5gww: infinite loop in Go bindings)
- `@tiptap/*` 3.20.1 -> 3.31.3 (GHSA-j95f-988m-3j2f: quadratic ReDoS in Markdown attribute parsing; GHSA-cp6q-959q-f8rh: `mergeAttributes()` prototype pollution)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@nishantmonu51 nishantmonu51 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 , LGTM post CI failures are fixed.

@nishantmonu51 nishantmonu51 added dependencies Pull requests that update a dependency file Size:M Medium change: 100-499 lines labels Sep 16, 2026

@nishantmonu51 nishantmonu51 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two issues below, both on the regenerated dependency files.

The failing Test Go code job is TestClickhouseCluster in admin/provisioner/clickhousestatic dying at testclickhouse.go:106 with compose up: Error response from daemon: No such container, a testcontainers/Docker error unrelated to thrift or @tiptap; it needs a rerun, not a code change.

One behaviour change worth a manual check: @tiptap/suggestion 3.31 handles Escape itself (dist/index.js:129), closing the picker via onExit and keeping that trigger dismissed until the cursor leaves the @ range, and with allowSpaces: true (web-common/src/features/chat/core/context/editor-plugins.svelte.ts:246) the dismissal is sticky across spaces. The picker previously ignored Escape.

Comment thread package-lock.json Outdated
"prosemirror-transform": "^1.0.0"
}
},
"web-common/node_modules/prosemirror-model": {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This nested prosemirror-model@1.25.11 coexists with the root prosemirror-model@1.25.4 (line 28109), because root prosemirror-state@1.4.4 and prosemirror-transform@1.12.0 only require ^1.0.0; the same split happens for prosemirror-view (nested 1.42.3 against root 1.41.8). Resolution from web-common/node_modules/@tiptap/pm therefore hands @tiptap/pm/model the nested copy while @tiptap/pm/state and @tiptap/pm/transform get the root copy, and no Vite config has resolve.dedupe or a ProseMirror alias to collapse them. Rebuilding this layout under jsdom with the chat editor's extension set, @tiptap/core logs [tiptap warn]: prosemirror-model is loaded more than once and editor.commands.enter() — what EditorSubmitExtension calls on Shift-Enter (web-common/src/features/chat/core/context/editor-plugins.svelte.ts:76) — throws RangeError: Can not convert <> to a Fragment whenever the cursor is at the end of a line or the editor is empty, so no line break is inserted. npm dedupe on this lockfile collapses both packages to single root copies (1.25.11 and 1.42.4) and the same run then passes every step.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked the merged lockfile directly — @tiptap/* is consistently 3.31.3 root-wide with a single copy each of prosemirror-model/prosemirror-view, so the predicted root-hoisted 3.22.1 duplicate didn't materialize on this merge. Ran npm dedupe as a check anyway; it only touched unrelated packages (lodash/ajv/protobufjs, etc.), so left the lockfile as-is.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correction to my earlier reply: I was wrong — checking more carefully, the nested web-common/node_modules/prosemirror-model@1.25.11 and prosemirror-view@1.42.3 duplicates you flagged were in fact present in the merged lockfile alongside the root 1.25.4/1.41.8 copies. Ran npm dedupe (pushed as ac62169), which collapses both to single root copies. Reran the web-common unit suite after — 3015 tests pass.

Comment thread go.mod
github.com/andybalholm/brotli v1.2.0 // indirect
github.com/apache/arrow/go/v15 v15.0.2 // indirect
github.com/apache/thrift v0.22.0 // indirect
github.com/apache/thrift v0.24.0 // indirect

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

main has since moved thrift to v0.23.0 and databricks-sql-go to v1.15.1 (#9852), and git merge-tree reports content conflicts in both go.mod and go.sum. Keep v0.24.0 when resolving: GHSA-8wv5-x4w7-5gww's first patched version is 0.24.0, so main's 0.23.0 is still vulnerable, and databricks-sql-go v1.15.1 builds cleanly against v0.24.0. package-lock.json auto-merges textually, but main now has @tiptap/*@3.22.1 hoisted at the root, so a text merge leaves both those entries and this PR's nested 3.31.3 ones; regenerate the lockfile after rebasing rather than accepting the merged text, and run npm dedupe at that point.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Kept thrift at v0.24.0 when resolving — confirmed GHSA-8wv5-x4w7-5gww requires 0.24.0, and databricks-sql-go v1.15.1 builds cleanly against it.

himadrisingh and others added 2 commits September 21, 2026 13:47
Merging main pulled in root prosemirror-model@1.25.4 while this
branch's @tiptap/pm@3.31.3 resolved a nested web-common copy at
1.25.11 (and prosemirror-view similarly at root 1.41.8 vs nested
1.42.3), so the editor loaded two copies of each package.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nishantmonu51
nishantmonu51 merged commit fce0b24 into main Sep 21, 2026
14 checks passed
@nishantmonu51
nishantmonu51 deleted the hsingh/dependabot-thrift-tiptap branch September 21, 2026 15:59
nishantmonu51 pushed a commit that referenced this pull request Sep 23, 2026
…9874)

* chore: upgrade `thrift` and `@tiptap/*` to resolve Dependabot alerts

- `github.com/apache/thrift` 0.22.0 -> 0.24.0 (GHSA-8wv5-x4w7-5gww: infinite loop in Go bindings)
- `@tiptap/*` 3.20.1 -> 3.31.3 (GHSA-j95f-988m-3j2f: quadratic ReDoS in Markdown attribute parsing; GHSA-cp6q-959q-f8rh: `mergeAttributes()` prototype pollution)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Dedupe nested prosemirror-model/prosemirror-view copies

Merging main pulled in root prosemirror-model@1.25.4 while this
branch's @tiptap/pm@3.31.3 resolved a nested web-common copy at
1.25.11 (and prosemirror-view similarly at root 1.41.8 vs nested
1.42.3), so the editor loaded two copies of each package.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit fce0b24)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Size:M Medium change: 100-499 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants