Skip to content

fix(deps): align CLI Bridge dependency cohort - #119

Merged
drewstone merged 2 commits into
mainfrom
fix/braid034-cli-bridge-undici-20260930
Sep 30, 2026
Merged

drewstone merged 2 commits into
mainfrom
fix/braid034-cli-bridge-undici-20260930

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Problem

The required dependency audit on PR #118 found three high Undici advisories through Braid's CLI Bridge 1.1.0 pin.
That pin resolves Undici 8.10.1; the maintained bridge release 1.1.1 requires agent-interface ^2.13.1.
The new interface schema also accepts workspace checkpoint restores that Braid previously dropped before request identity and provider dispatch.

Change

  • Pin CLI Bridge 1.1.1, agent-interface 2.13.1, and Undici 8.11.2 in package manifests and the lockfile.
  • Update the runtime contract's installed package evidence and override record.
  • Reject checkpoint-bearing workspace requests until Braid preserves the field through request identity and provider dispatch.
  • Add schema-backed coverage for checkpoint-only and environment-plus-checkpoint requests.

Why this direction

Braid now consumes the published bridge release that carries the patched Undici version.
One exact interface cohort keeps the Runtime, Tangle provider, and Bridge peers aligned.
Rejecting the request at the shared boundary prevents Braid from creating an identity for input it would silently discard.
Workspace branching checkpoints remain a separate supported operation.

Verification

  • pnpm install --frozen-lockfile passed with pnpm 11.24.0.
  • Installed manifests resolve Bridge 1.1.1, interface 2.13.1, and Undici 8.11.2; the production graph audit reports 96 packages and no known vulnerabilities.
  • Targeted Node 22 workspace request tests passed 8/8.
  • Credential-stripped test:live:required:self passed 170/170 after a successful build.
  • Credential-stripped test:live:bridge:matrix passed against its fake localhost server.
  • pnpm run check:release passed all four registry-collision tests and verified 26 release scripts and 12 required artifacts.
  • Post-edit pnpm run format:check passed for 867 files.
  • Local full pnpm check remains red only in the performance suite: 911 standard tests passed, 2 skipped, and the 10k-worker changed-revision p90 was 658.2 ms against 250 ms. The same test measured 659.1 ms in the prior run; buildBraidViewModel and the performance gate are unchanged. Host contention is a hypothesis, not a proven cause. Required CI will run on this PR.

Release boundary

This PR does not claim protected provider success or exact-candidate release proof.
The protected LIVE-06..10 gate still lacks a named provider-account log owner and an identified authorized bounded route.
No provider request or publication was made for this PR.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — b3dc7f81

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-30T03:31:08Z

@drewstone
drewstone merged commit 88a0fcf into main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants