Skip to content

fix(deps): patch Undici across managed OpenClaw runtimes - #12506

Closed
ericksoa wants to merge 1 commit into
mainfrom
fix/undici-security-update
Closed

ericksoa wants to merge 1 commit into
mainfrom
fix/undici-security-update

Conversation

@ericksoa

Copy link
Copy Markdown
Contributor

Outcome

Replace vulnerable Undici copies in the CLI, managed OpenClaw runtime, and bundled Discord/Slack plugins. Use 8.10.2 for existing 8.x consumers and 7.29.1 for Slack, preserving their supported major versions and offline installation.

Reason

The September 29 Undici advisories made the existing production dependency audit fail, including on Spark PR #12502. Updating the root dependency alone leaves vulnerable copies bundled in published OpenClaw plugins. Maintainer Aaron Erickson requested this dependency update as the prerequisite to getting that PR green.

Changes

  • Pin the CLI and managed OpenClaw graphs to Undici 8.10.2, update the reviewed lock digest, and seed both patched versions in the offline image cache with verified archive checksums.
  • Extend the existing reviewed-archive remediation for OpenClaw 2026.9.1 core metadata and Discord/Slack bundles. Verify publisher identity, original dependency/bundle layout, replacement integrity, Node requirements, and the complete resulting package tree. Reject drift before changing metadata; the rejection regression verifies that the entire package tree remains unchanged. Retire these entries when a reviewed OpenClaw release includes the patched dependencies and bundles.
  • Use the immutable PR base commit for the independent audit action and managed-image receipt verifier. The current frozen action revision otherwise continues using the old approved lock and archive remediation after the dependency fix lands. Candidate code still cannot supply its own audit policy, and severity thresholds and exceptions are unchanged.
  • Extend existing remediation tests for the three package layouts and rejection of dependency/bundle drift. Preserve historical audit fixtures with their own lock identity, and verify producer/consumer audit provenance in the existing workflow tests.

Verification

  • Pinned Node 24.18.1/npm 12.0.2: node scripts/audit-reviewed-npm-graph.mts — all six production graphs pass the existing policy; zero high or critical findings. Reports retained locally. The reviewed archive graph includes the remediated bundles.
  • vitest run --project integration --project package-contract test/agents/openclaw/openclaw-locked-install.test.ts test/agents/openclaw/openclaw-managed-messaging-offline-build.test.ts test/agents/openclaw/openclaw-npm-remediation.test.ts test/automation/releases/reviewed-npm-audit-entrypoint.test.ts test/automation/releases/reviewed-npm-audit-cache-key.test.ts test/automation/releases/reviewed-npm-audit-handoff.test.ts test/package-contract/managed-image-registry-transport.test.ts — 7 files, 72 tests pass.
  • vitest run --project integration test/inference/managed/managed-image-publication-workflow.test.ts test/automation/pull-requests/growth-guardrails.test.ts — 2 files, 43 tests pass.
  • Existing audit policy, workflow, and receipt tests pass. No budget or assertion was weakened.
  • vitest run --project cli src/lib/onboard/managed-image-registry-fetch.test.ts — 9 tests pass on Node 22.23.2 and Node 24.18.1, including real proxy/TLS handling.
  • npm run build:cli and npm run typecheck:cli — pass.
  • Clean offline messaging install using the Dockerfile's --ignore-scripts --omit=dev --legacy-peer-deps contract resolves shared Undici 8.10.2.
  • Verified replacement archive integrity and repacked package-tree pins. Controlled npm 12 repack comparisons restrict changes to intended package metadata and Undici bytes. Real local WebSocket probes against both patched bundles reject unsolicited subprotocols without crashing.
  • Reviewed source and changed-path inventories for 8.10.0→8.10.1→8.10.2 and 7.29.0→7.29.1, including proxy/TLS, BalancedPool, cache-origin, and WebSocket changes. No consumer API migration is required.
  • git diff --check passes. The diff contains no secrets, API keys, or credentials.

Review notes

Self-review of NVIDIA/NemoClaw at b0af4ef covers all changed files, including the sensitive workflow, package graph, and archive remediation paths. Archive byte checks, package-tree pins, regression tests, and base-versus-candidate provenance were inspected. No independent review or merge approval is claimed; this PR starts as a draft.

The security audit intentionally takes its policy and remediation code from the base branch. This first dependency update therefore cannot pass that independent gate until its approved lock and remediation are available in the trusted base. Local audits pass with the proposed policy, but are not a substitute for that independent CI result. This PR does not bypass or weaken the gate. A maintainer decision is required for the initial policy transition; then #12502 can consume the merged fix and be checked normally.

The first signed commit and push skip only the repository-checks hook to allow CI to produce the required Pi receipts. Its other 17 repository checks were run separately and pass; all other hooks remain enabled. Fresh AMD64 and ARM64 receipts from one CI run will be committed with normal validation restored. No receipt is fabricated or carried forward from different image inputs.

Managed-image CI and physical Spark validation remain pending. This PR does not qualify the Spark serving recipe on hardware.


Signed-off-by: Aaron Erickson aerickson@nvidia.com

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@ericksoa ericksoa self-assigned this Sep 30, 2026
@copy-pr-bot

copy-pr-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

@github-code-quality

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit b0af4ef in the fix/undici-security-... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/undici-security-... b0af4ef +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

@ericksoa ericksoa closed this Sep 30, 2026
@ericksoa
ericksoa deleted the fix/undici-security-update branch September 30, 2026 00:24
@wscurran wscurran added area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior platform: container Affects Docker, containerd, Podman, or images labels Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior platform: container Affects Docker, containerd, Podman, or images

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants