fix(vloer): keep the demo replay green across releases and unblock the agent image #163

Merged
ryangr0 merged 2 commits from ryangr0/fix/replay-version-and-agent-cve into development 2026-10-03 10:38:09 +00:00 AGit
Owner

Why

Two things kept rc.33 from being a clean release.

  1. development CI red after every release. The hosted demo replay records GET /api/health, and its body carries Vloer's version. The rc.33 release commit bumped it, so replay:check failed on the next push (run 742: recorded 0.4.0-rc.32, now 0.4.0-rc.33). That would repeat on every release.
  2. de-vloer-agent not signed. Run 743's CVE gate found CVE-2026-93748 / GHSA-ch52-4w7c-c8xp (High) in http-cache-semantics 4.2.0, which npm bundles. No fixed release exists (affected through 4.2.0), so Vloer's "Verify and publish all destinations" was skipped.

Change

  • record-replay.ts: mask() replaces the Vloer version a recording was made at with <vloer-version>. The committed side uses manifest.vloerVersion, the fresh side package.json. Other version fields (card themes) are still compared.
  • OpenVEX: not_affected / vulnerable_code_cannot_be_controlled_by_adversary for both ids. The flaw needs a shared cache serving several users plus attacker-chosen max-stale; the only copy is npm's private client cache for the single node user of one session container.
  • check-http-cache-semantics.mjs (build step, like check-gz-imports.mjs) fails the image build if a second copy appears anywhere, so the claim can't silently stop being true. VEX README updated.

Verification

  • mise run verify: all gates pass.
  • Agent image built locally (amd64): one copy at /usr/lib/node_modules/npm/node_modules/http-cache-semantics (4.2.0); the check passes, and fails when a copy is planted in /workspace/node_modules.
  • Not verified locally: that the Harbor cve-gate matches npm findings by the CVE or the GHSA id, so the statement carries both. The next release's Vloer image job proves it.

🤖 Generated with Claude Code

## Why Two things kept rc.33 from being a clean release. 1. **`development` CI red after every release.** The hosted demo replay records `GET /api/health`, and its body carries Vloer's version. The rc.33 release commit bumped it, so `replay:check` failed on the next push (run 742: recorded `0.4.0-rc.32`, now `0.4.0-rc.33`). That would repeat on every release. 2. **`de-vloer-agent` not signed.** Run 743's CVE gate found CVE-2026-93748 / GHSA-ch52-4w7c-c8xp (High) in `http-cache-semantics` 4.2.0, which npm bundles. No fixed release exists (affected through 4.2.0), so Vloer's "Verify and publish all destinations" was skipped. ## Change - `record-replay.ts`: `mask()` replaces the Vloer version a recording was made at with `<vloer-version>`. The committed side uses `manifest.vloerVersion`, the fresh side `package.json`. Other `version` fields (card themes) are still compared. - OpenVEX: `not_affected` / `vulnerable_code_cannot_be_controlled_by_adversary` for both ids. The flaw needs a **shared** cache serving several users plus attacker-chosen `max-stale`; the only copy is npm's private client cache for the single `node` user of one session container. - `check-http-cache-semantics.mjs` (build step, like `check-gz-imports.mjs`) fails the image build if a second copy appears anywhere, so the claim can't silently stop being true. VEX README updated. ## Verification - `mise run verify`: all gates pass. - Agent image built locally (amd64): one copy at `/usr/lib/node_modules/npm/node_modules/http-cache-semantics` (4.2.0); the check passes, and fails when a copy is planted in `/workspace/node_modules`. - Not verified locally: that the Harbor `cve-gate` matches npm findings by the CVE or the GHSA id, so the statement carries both. The next release's Vloer image job proves it. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
The replay records GET /api/health, whose body carries Vloer's version,
so each release commit made replay:check fail on development (run 742,
rc.32 recorded, rc.33 now). The check now masks each side's own version.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
fix(vloer): record CVE-2026-93748 as not affecting the agent image
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
211e857e40
rc.33's de-vloer-agent failed its CVE budget on http-cache-semantics
4.2.0, bundled by npm. No fixed release exists. The flaw needs a shared
cache serving several users; npm's private cache in one session's
container serves only npm. The OpenVEX statement covers the CVE and GHSA
ids, and a build check fails if any other copy of the package appears.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit 89452dd4fd into development 2026-10-03 10:38:09 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!163
No description provided.