fix(vloer): keep the demo replay green across releases and unblock the agent image #163
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/fix/replay-version-and-agent-cve"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
Two things kept rc.33 from being a clean release.
developmentCI red after every release. The hosted demo replay recordsGET /api/health, and its body carries Vloer's version. The rc.33 release commit bumped it, soreplay:checkfailed on the next push (run 742: recorded0.4.0-rc.32, now0.4.0-rc.33). That would repeat on every release.de-vloer-agentnot signed. Run 743's CVE gate found CVE-2026-93748 / GHSA-ch52-4w7c-c8xp (High) inhttp-cache-semantics4.2.0, which npm bundles. No fixed release exists (affected through 4.2.0), so Vloer's "Verify and publish all destinations" was skipped.Change
record-replay.ts:mask()replaces the Vloer version a recording was made at with<vloer-version>. The committed side usesmanifest.vloerVersion, the fresh sidepackage.json. Otherversionfields (card themes) are still compared.not_affected/vulnerable_code_cannot_be_controlled_by_adversaryfor both ids. The flaw needs a shared cache serving several users plus attacker-chosenmax-stale; the only copy is npm's private client cache for the singlenodeuser of one session container.check-http-cache-semantics.mjs(build step, likecheck-gz-imports.mjs) fails the image build if a second copy appears anywhere, so the claim can't silently stop being true. VEX README updated.Verification
mise run verify: all gates pass./usr/lib/node_modules/npm/node_modules/http-cache-semantics(4.2.0); the check passes, and fails when a copy is planted in/workspace/node_modules.cve-gatematches npm findings by the CVE or the GHSA id, so the statement carries both. The next release's Vloer image job proves it.🤖 Generated with Claude Code