chore: upgrade thrift and @tiptap/* to resolve Dependabot alerts - #9874
Conversation
- `github.com/apache/thrift` 0.22.0 -> 0.24.0 (GHSA-8wv5-x4w7-5gww: infinite loop in Go bindings) - `@tiptap/*` 3.20.1 -> 3.31.3 (GHSA-j95f-988m-3j2f: quadratic ReDoS in Markdown attribute parsing; GHSA-cp6q-959q-f8rh: `mergeAttributes()` prototype pollution) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
nishantmonu51
left a comment
There was a problem hiding this comment.
👍 , LGTM post CI failures are fixed.
nishantmonu51
left a comment
There was a problem hiding this comment.
Two issues below, both on the regenerated dependency files.
The failing Test Go code job is TestClickhouseCluster in admin/provisioner/clickhousestatic dying at testclickhouse.go:106 with compose up: Error response from daemon: No such container, a testcontainers/Docker error unrelated to thrift or @tiptap; it needs a rerun, not a code change.
One behaviour change worth a manual check: @tiptap/suggestion 3.31 handles Escape itself (dist/index.js:129), closing the picker via onExit and keeping that trigger dismissed until the cursor leaves the @ range, and with allowSpaces: true (web-common/src/features/chat/core/context/editor-plugins.svelte.ts:246) the dismissal is sticky across spaces. The picker previously ignored Escape.
| "prosemirror-transform": "^1.0.0" | ||
| } | ||
| }, | ||
| "web-common/node_modules/prosemirror-model": { |
There was a problem hiding this comment.
This nested prosemirror-model@1.25.11 coexists with the root prosemirror-model@1.25.4 (line 28109), because root prosemirror-state@1.4.4 and prosemirror-transform@1.12.0 only require ^1.0.0; the same split happens for prosemirror-view (nested 1.42.3 against root 1.41.8). Resolution from web-common/node_modules/@tiptap/pm therefore hands @tiptap/pm/model the nested copy while @tiptap/pm/state and @tiptap/pm/transform get the root copy, and no Vite config has resolve.dedupe or a ProseMirror alias to collapse them. Rebuilding this layout under jsdom with the chat editor's extension set, @tiptap/core logs [tiptap warn]: prosemirror-model is loaded more than once and editor.commands.enter() — what EditorSubmitExtension calls on Shift-Enter (web-common/src/features/chat/core/context/editor-plugins.svelte.ts:76) — throws RangeError: Can not convert <> to a Fragment whenever the cursor is at the end of a line or the editor is empty, so no line break is inserted. npm dedupe on this lockfile collapses both packages to single root copies (1.25.11 and 1.42.4) and the same run then passes every step.
There was a problem hiding this comment.
Checked the merged lockfile directly — @tiptap/* is consistently 3.31.3 root-wide with a single copy each of prosemirror-model/prosemirror-view, so the predicted root-hoisted 3.22.1 duplicate didn't materialize on this merge. Ran npm dedupe as a check anyway; it only touched unrelated packages (lodash/ajv/protobufjs, etc.), so left the lockfile as-is.
There was a problem hiding this comment.
Correction to my earlier reply: I was wrong — checking more carefully, the nested web-common/node_modules/prosemirror-model@1.25.11 and prosemirror-view@1.42.3 duplicates you flagged were in fact present in the merged lockfile alongside the root 1.25.4/1.41.8 copies. Ran npm dedupe (pushed as ac62169), which collapses both to single root copies. Reran the web-common unit suite after — 3015 tests pass.
| github.com/andybalholm/brotli v1.2.0 // indirect | ||
| github.com/apache/arrow/go/v15 v15.0.2 // indirect | ||
| github.com/apache/thrift v0.22.0 // indirect | ||
| github.com/apache/thrift v0.24.0 // indirect |
There was a problem hiding this comment.
main has since moved thrift to v0.23.0 and databricks-sql-go to v1.15.1 (#9852), and git merge-tree reports content conflicts in both go.mod and go.sum. Keep v0.24.0 when resolving: GHSA-8wv5-x4w7-5gww's first patched version is 0.24.0, so main's 0.23.0 is still vulnerable, and databricks-sql-go v1.15.1 builds cleanly against v0.24.0. package-lock.json auto-merges textually, but main now has @tiptap/*@3.22.1 hoisted at the root, so a text merge leaves both those entries and this PR's nested 3.31.3 ones; regenerate the lockfile after rebasing rather than accepting the merged text, and run npm dedupe at that point.
There was a problem hiding this comment.
Kept thrift at v0.24.0 when resolving — confirmed GHSA-8wv5-x4w7-5gww requires 0.24.0, and databricks-sql-go v1.15.1 builds cleanly against it.
…ift-tiptap # Conflicts: # go.mod # go.sum
Merging main pulled in root prosemirror-model@1.25.4 while this branch's @tiptap/pm@3.31.3 resolved a nested web-common copy at 1.25.11 (and prosemirror-view similarly at root 1.41.8 vs nested 1.42.3), so the editor loaded two copies of each package. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…9874) * chore: upgrade `thrift` and `@tiptap/*` to resolve Dependabot alerts - `github.com/apache/thrift` 0.22.0 -> 0.24.0 (GHSA-8wv5-x4w7-5gww: infinite loop in Go bindings) - `@tiptap/*` 3.20.1 -> 3.31.3 (GHSA-j95f-988m-3j2f: quadratic ReDoS in Markdown attribute parsing; GHSA-cp6q-959q-f8rh: `mergeAttributes()` prototype pollution) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Dedupe nested prosemirror-model/prosemirror-view copies Merging main pulled in root prosemirror-model@1.25.4 while this branch's @tiptap/pm@3.31.3 resolved a nested web-common copy at 1.25.11 (and prosemirror-view similarly at root 1.41.8 vs nested 1.42.3), so the editor loaded two copies of each package. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> (cherry picked from commit fce0b24)
Resolves three open Dependabot security alerts:
github.com/apache/thrift0.22.0 → 0.24.0 — GHSA-8wv5-x4w7-5gww (high): infinite loop in the Go bindings. Transitive viadatabricks-sql-go→runtime/drivers/databricks; a clean one-line bump with no cascade.@tiptap/*(8 packages) 3.20.1 → 3.31.3 — GHSA-j95f-988m-3j2f (high): quadratic ReDoS in Markdown attribute parsing, and GHSA-cp6q-959q-f8rh (medium):mergeAttributes()turns an own__proto__key into inherited executable DOM attributes. All@tiptap/*packages move together since the library requires matching versions across the family.Verified:
go build ./...passes,npm run buildpasses for bothweb-localandweb-admin, andsvelte-checkreports no errors at the three@tiptapcall sites underweb-common/src/features/chat/core/.The
grpcalert is handled separately in #9873, since that one cascades a large set of transitive upgrades. The two PRs overlap ongo.mod, so whichever merges second needs a rebase.Checklist:
Developed in collaboration with Claude Code
🤖 Generated with Claude Code