chore: reconcile published packages and infrastructure consumers - #567
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
ty-everett
left a comment
There was a problem hiding this comment.
Critical maintainer review of exact head 6b5b0570131278509129ce60498b359b872ee466: no remaining blocking finding.
The bot synchronization is preserved. Reviewed all eight standalone consumer graphs, integrity/lock changes, seven OCI patch versions, generated documentation and the published-ledger transition. The only third-party delta is the reviewed proxy-addr 2.0.8 security patch; all 34 public package trees are unchanged from the immutable npm release source. Release summaries and migration instructions remain intact. The Overlay runtime fixture now supplies an independent callback credential required by the actual published server, with a regression guard; authentication was not weakened.
Local required health/lint/format/typecheck, documentation, all standalone consumer installs/builds/audits/tests and publication reconciliation pass. Exact-head hosted CI 35826664644, CodeQL 35826664539 and all seven runtime containers 35826664538 pass. Direct Sonar gate reports quality OK, zero new findings and zero unreviewed hotspots. GitHub PR CodeQL alerts and review threads are empty. Expected scope skips were accepted by the strict final CI gate.
One qualified maintainer review is sufficient under repository policy; recording COMMENT because this account authored the follow-up commits. Ready for administrator-assisted merge. Main must pass before protected infrastructure publication; live migrations and deployments remain separate acceptance steps.



Program and scope
6b5b0570131278509129ce60498b359b872ee466.Impact
Intended OCI versions: Chaintracks 1.1.21; Message Box 1.1.44; Overlay 2.1.39; UHRP Basic 0.1.40; UHRP Cloud 0.2.41; WAB 1.8.4; Wallet Infra 2.0.43. The separately deployed private UHRP notifier becomes 1.0.1. Publication remains the protected infrastructure workflow after merge.
Verification
pnpm health:check,pnpm lint,pnpm format:check,pnpm typecheck. Build and audit passed in preparation; no public package bytes changed.npm ci --ignore-scripts, explicitly allowlisted native rebuilds where needed, high/critical audit, build, lint and available tests.Security and dependency evidence
The lock delta is the coordinated first-party versions plus
proxy-addr2.0.7 → 2.0.8 under Overlay's Express dependency. The latter is the upstream GHSA-jqcg-44mw-7w3h security patch, retains the same Node/runtime contract and dependency versions, and passes the consumer audit/tests. No unrelated dependency cohort, new override, suppression, skipped test or advisory dismissal is introduced. Package release summaries and migration instructions are preserved exactly;releaseType: nonenow correctly records source/published parity.Release and operations
After accepted merge and green main, the protected infrastructure workflow must build Linux/amd64 images, reject high/critical findings, publish immutable GHCR tags, and verify signatures, provenance and SBOMs. Staging-first operators must follow the WAB/Message Box coordinated schema cutovers; these services are not eligible for image-only rollback after their schema advances. No live deployment is performed by this PR.
Completion evidence