diff --git a/bun.lock b/bun.lock index 7a1833e94..90b8fddf4 100644 --- a/bun.lock +++ b/bun.lock @@ -22,6 +22,9 @@ }, }, }, + "overrides": { + "basic-ftp": "5.3.1", + }, "packages": { "@anthropic-ai/claude-agent-sdk": ["@anthropic-ai/claude-agent-sdk@0.2.117", "", { "dependencies": { "@anthropic-ai/sdk": "^0.81.0", "@modelcontextprotocol/sdk": "^1.29.0" }, "optionalDependencies": { "@anthropic-ai/claude-agent-sdk-darwin-arm64": "0.2.117", "@anthropic-ai/claude-agent-sdk-darwin-x64": "0.2.117", "@anthropic-ai/claude-agent-sdk-linux-arm64": "0.2.117", "@anthropic-ai/claude-agent-sdk-linux-arm64-musl": "0.2.117", "@anthropic-ai/claude-agent-sdk-linux-x64": "0.2.117", "@anthropic-ai/claude-agent-sdk-linux-x64-musl": "0.2.117", "@anthropic-ai/claude-agent-sdk-win32-arm64": "0.2.117", "@anthropic-ai/claude-agent-sdk-win32-x64": "0.2.117" }, "peerDependencies": { "zod": "^4.0.0" } }, "sha512-pVBss1Vu0w87nKCBhWtjMggSgCh6GVUtdRmuE58ZvXv0E2q0JcnUCQHehmn92BAW0+VCwPY8q/k7uKWkgwz/gA=="], @@ -201,7 +204,7 @@ "bare-url": ["bare-url@2.4.0", "", { "dependencies": { "bare-path": "^3.0.0" } }, "sha512-NSTU5WN+fy/L0DDenfE8SXQna4voXuW0FHM7wH8i3/q9khUSchfPbPezO4zSFMnDGIf9YE+mt/RWhZgNRKRIXA=="], - "basic-ftp": ["basic-ftp@5.2.0", "", {}, "sha512-VoMINM2rqJwJgfdHq6RiUudKt2BV+FY5ZFezP/ypmwayk68+NzzAQy4XXLlqsGD4MCzq3DrmNFD/uUmBJuGoXw=="], + "basic-ftp": ["basic-ftp@5.3.1", "", {}, "sha512-bopVNp6ugyA150DDuZfPFdt1KZ5a94ZDiwX4hMgZDzF+GttD80lEy8kj98kbyhLXnPvhtIo93mdnLIjpCAeeOw=="], "body-parser": ["body-parser@2.2.2", "", { "dependencies": { "bytes": "^3.1.2", "content-type": "^1.0.5", "debug": "^4.4.3", "http-errors": "^2.0.0", "iconv-lite": "^0.7.0", "on-finished": "^2.4.1", "qs": "^6.14.1", "raw-body": "^3.0.1", "type-is": "^2.0.1" } }, "sha512-oP5VkATKlNwcgvxi0vM0p/D3n2C3EReYVX+DNYs5TjZFn/oQt2j+4sVJtSMr18pdRr8wjTcBl6LoV+FUwzPmNA=="], diff --git a/package.json b/package.json index c5168d648..e26f5045c 100644 --- a/package.json +++ b/package.json @@ -48,6 +48,9 @@ "slop": "npx slop-scan scan . 2>/dev/null || echo 'slop-scan not available (install with: npm i -g slop-scan)'", "slop:diff": "bun run scripts/slop-diff.ts" }, + "overrides": { + "basic-ftp": "5.3.1" + }, "dependencies": { "@huggingface/transformers": "^4.1.0", "@ngrok/ngrok": "^1.7.0", diff --git a/test/audit-compliance.test.ts b/test/audit-compliance.test.ts index 80ef6dced..b0b1a306b 100644 --- a/test/audit-compliance.test.ts +++ b/test/audit-compliance.test.ts @@ -115,6 +115,22 @@ describe('Audit compliance', () => { expect(cdp).toContain('--remote-allow-origins='); }); + // CVE-2026-39983 + siblings: bun overrides must pin all copies of basic-ftp to 5.3.1 + test('bun.lock contains no basic-ftp older than 5.3.1 (override tripwire)', () => { + const lock = readFileSync(join(ROOT, 'bun.lock'), 'utf-8'); + // Match every "basic-ftp@X.Y.Z" reference in the lockfile + const matches = [...lock.matchAll(/"basic-ftp@(\d+)\.(\d+)\.(\d+)"/g)]; + expect(matches.length).toBeGreaterThan(0); + for (const m of matches) { + const [major, minor, patch] = [Number(m[1]), Number(m[2]), Number(m[3])]; + const isAtLeast531 = + major > 5 || + (major === 5 && minor > 3) || + (major === 5 && minor === 3 && patch >= 1); + expect(isAtLeast531).toBe(true); + } + }); + // Fix 2+6: All generated SKILL.md files with telemetry are conditional test('all generated SKILL.md files with telemetry calls use conditional pattern', () => { const skills = getAllSkillMds();