Skip to content

chore(ci): fix Dependency Audit and Contract Fuzz jobs failing on main - #1392

Merged
wheval merged 2 commits into
mainfrom
chore/fix-ci-dependency-audit
Sep 26, 2026
Merged

wheval merged 2 commits into
mainfrom
chore/fix-ci-dependency-audit

Conversation

@wheval

@wheval wheval commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Two independent CI jobs were failing on every push to main:

Dependency Audit — two new image-size advisories (DoS in JXL/HEIF and ICNS parsers) weren't allowlisted. Tried overriding to the patched version first; reverted after confirming by direct require() test that it breaks metro's asset pipeline at runtime (image-size@2.x's CJS export isn't callable the way metro expects). Allowlisted instead, with the incompatibility documented. Also dropped 8 stale allowlist entries the checker itself flagged as no longer reported by pnpm audit.

Contract Fuzz — contracts/account/fuzz/ (added in #1218) was never excluded from the parent contracts/ workspace, so every fuzz target failed to build in CI with "current package believes it's in a workspace when it's not". Fixed with the standard cargo-fuzz convention (empty [workspace] table on the fuzz crate). Verified with a real cargo build, not just cargo check.

Also generalized .prettierignore's contract test-snapshot exclusion from account only to all four contract crates — upgrade and validation-modules have the same generated JSON snapshots and were never covered, so touching either failed Format Check on unrelated files.

🤖 Generated with Claude Code

wheval and others added 2 commits September 26, 2026 10:26
Two new image-size advisories (1239765, 1239766 — JXL/HEIF and ICNS
parser DoS) were failing the allowlist check unallowlisted, breaking
CI on every push to main.

Tried the obvious fix first: pnpm.overrides to the patched version
(>=2.0.3). Reverted it — confirmed by direct require() test that
image-size@2.x's CJS export is `{ imageSize, disableTypes, default,
types }`, not a callable, while metro (the transitive consumer, RN's
bundler) does `const getImageSize = require('image-size')` and calls
it directly. Forcing the override breaks metro's asset pipeline at
runtime (getImageSize is not a function). Allowlisted instead, with
that incompatibility documented so the next person doesn't repeat the
attempt.

Also dropped 8 allowlist entries the checker itself flagged as no
longer reported by pnpm audit at all (stale brace-expansion/js-yaml/
axios/postcss/opentelemetry entries from #1085, plus the two
image-size entries these replace) — pure cleanup, nothing to verify.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…zz job

contracts/account/fuzz/ was added in #1218 without excluding it from
the parent contracts/ workspace, so every 'Fuzz account (*)' CI job
failed at the build step: 'current package believes it's in a
workspace when it's not'. Fixed the standard cargo-fuzz way (empty
[workspace] table on the fuzz crate itself) plus a belt-and-suspenders
exclude on the parent, in case the empty-table convention isn't
followed by a future fuzz target added a different way. Verified with
a real `cargo build` on the fuzz crate (not just cargo check).

Also generalized .prettierignore's contracts/account/test_snapshots/
entry to contracts/*/test_snapshots/ — upgrade/ and validation-modules/
have the same generated JSON snapshot files and were never covered,
so touching either one and running the pre-push hook failed Format
Check on 39 files that have nothing to do with the actual change.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@wheval
wheval merged commit 37fffda into main Sep 26, 2026
8 checks passed
@wheval
wheval deleted the chore/fix-ci-dependency-audit branch September 26, 2026 09:34
@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: fe6cd682-ae54-4bc6-9bd4-1b79958783e5

📥 Commits

Reviewing files that changed from the base of the PR and between a79d22c and 569199c.

📒 Files selected for processing (4)
  • .pnpm-audit-allowlist.json
  • .prettierignore
  • contracts/Cargo.toml
  • contracts/account/fuzz/Cargo.toml
 _____________________________________________________
< The fifth dentist recommends we all floss our code. >
 -----------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant