Repository navigation
Conversation
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueComment |
Contributor
|
🌿 Preview your docs: https://nvidia-preview-pr-12506.docs.buildwithfern.com/nemoclaw |
Contributor
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit b0af4ef in the Show a line coverage summary of the most impacted files.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Replace vulnerable Undici copies in the CLI, managed OpenClaw runtime, and bundled Discord/Slack plugins. Use 8.10.2 for existing 8.x consumers and 7.29.1 for Slack, preserving their supported major versions and offline installation.
Reason
The September 29 Undici advisories made the existing production dependency audit fail, including on Spark PR #12502. Updating the root dependency alone leaves vulnerable copies bundled in published OpenClaw plugins. Maintainer Aaron Erickson requested this dependency update as the prerequisite to getting that PR green.
Changes
Verification
node scripts/audit-reviewed-npm-graph.mts— all six production graphs pass the existing policy; zero high or critical findings. Reports retained locally. The reviewed archive graph includes the remediated bundles.vitest run --project integration --project package-contract test/agents/openclaw/openclaw-locked-install.test.ts test/agents/openclaw/openclaw-managed-messaging-offline-build.test.ts test/agents/openclaw/openclaw-npm-remediation.test.ts test/automation/releases/reviewed-npm-audit-entrypoint.test.ts test/automation/releases/reviewed-npm-audit-cache-key.test.ts test/automation/releases/reviewed-npm-audit-handoff.test.ts test/package-contract/managed-image-registry-transport.test.ts— 7 files, 72 tests pass.vitest run --project integration test/inference/managed/managed-image-publication-workflow.test.ts test/automation/pull-requests/growth-guardrails.test.ts— 2 files, 43 tests pass.vitest run --project cli src/lib/onboard/managed-image-registry-fetch.test.ts— 9 tests pass on Node 22.23.2 and Node 24.18.1, including real proxy/TLS handling.npm run build:cliandnpm run typecheck:cli— pass.--ignore-scripts --omit=dev --legacy-peer-depscontract resolves shared Undici 8.10.2.git diff --checkpasses. The diff contains no secrets, API keys, or credentials.Review notes
Self-review of NVIDIA/NemoClaw at b0af4ef covers all changed files, including the sensitive workflow, package graph, and archive remediation paths. Archive byte checks, package-tree pins, regression tests, and base-versus-candidate provenance were inspected. No independent review or merge approval is claimed; this PR starts as a draft.
The security audit intentionally takes its policy and remediation code from the base branch. This first dependency update therefore cannot pass that independent gate until its approved lock and remediation are available in the trusted base. Local audits pass with the proposed policy, but are not a substitute for that independent CI result. This PR does not bypass or weaken the gate. A maintainer decision is required for the initial policy transition; then #12502 can consume the merged fix and be checked normally.
The first signed commit and push skip only the
repository-checkshook to allow CI to produce the required Pi receipts. Its other 17 repository checks were run separately and pass; all other hooks remain enabled. Fresh AMD64 and ARM64 receipts from one CI run will be committed with normal validation restored. No receipt is fabricated or carried forward from different image inputs.Managed-image CI and physical Spark validation remain pending. This PR does not qualify the Spark serving recipe on hardware.
Signed-off-by: Aaron Erickson aerickson@nvidia.com