Skip to content

Tests: Patch basic-ftp in AI development dependencies - #84000

Merged
ciampo merged 1 commit into
trunkfrom
codex/patch-ai-basic-ftp
Oct 2, 2026
Merged

ciampo merged 1 commit into
trunkfrom
codex/patch-ai-basic-ftp

Conversation

@ciampo

@ciampo ciampo commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Follow-up to the unrelated AI dependency audit failure observed in #83996. See GHSA-c475-qrg2-pj4r.

What?

Update the standalone AI development package's transitive basic-ftp dependency to 6.2.1.

Why?

The new advisory affects the Unix directory-listing parser and fails the AI development CI audit. This dependency belongs to Promptfoo's separate lockfile and is unrelated to the Vitest and Storybook update.

How?

Add a scoped get-uri override and update its lockfile. get-uri@8.0.1 still requests version 5, while the security fix is in 6.2.1. Keep Promptfoo at 0.123.1 and document the override.

Testing Instructions

  1. Run PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1 npm ci --prefix test/ai-development.
  2. Run npm --prefix test/ai-development audit --audit-level=high. Expect zero vulnerabilities.
  3. Run npm --prefix test/ai-development run test:utils and npm --prefix test/ai-development run validate.
Verification

A clean install, dependency resolution, configuration validation, and all 24 offline utility tests pass. Two live model tests remain skipped. A local FTP server probe verifies get-uri listing and download compatibility with 6.2.1. The same probe confirms that the advisory's malicious directory listing completes promptly. The repository build, formatting, package-manifest lint, and lockfile checks pass. The root lockfile is unchanged.

Use of AI Tools

Codex investigated the advisory, updated the dependency override and lockfile, and ran verification.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🤖 PR meta 🤖

🎉 Props

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: ciampo <mciampini@git.wordpress.org>
Co-authored-by: jeryj <jeryj@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

Updated as activity occurs, without notifying anyone named here. Add the props-bot label to refresh.

📦 Bundle size

Size Change: 0 B

Total Size: 8.25 MB

c9eebea Run

⚡ Performance

Show the results

Client side metrics exclude the server response time.

front-end-block-theme

Metric 78e3d5e trunk % Change
timeToFirstByte 55.4 ms +11.82% -2.8% 57.6 ms +10.42% -5.73% -3.82%
largestContentfulPaint 96 ms +2.08% -8.33% 96 ms +6.25% -4.17% 0%
lcpMinusTtfb 34.1 ms +23.46% -3.52% 38.35 ms +10.56% -9.13% -11.08%
wpBeforeTemplate 27.71 ms +17.5% -1.44% 27.92 ms +20.34% -2.72% -0.75%
wpTemplate 23.56 ms +4.63% -3.23% 24.4 ms +1.72% -3.52% -3.44%
wpTotal 51.89 ms +12.35% -3.08% 53.79 ms +10.02% -5.37% -3.53%
wpMemoryUsage 7.62 MB +0% -0% 7.59 MB +0% -0% 0.46%
wpDbQueries 17 +0% -0% 17 +0% -0% 0%

front-end-classic-theme

Metric 78e3d5e trunk % Change
timeToFirstByte 46.45 ms +7.32% -3.23% 46.25 ms +6.7% -1.3% 0.43%
largestContentfulPaint 102 ms +1.96% -1.96% 100 ms +2% -2% 2%
lcpMinusTtfb 55.05 ms +3.45% -2.18% 53.25 ms +2.07% -5.07% 3.38%
wpBeforeTemplate 25.93 ms +5.94% -3.59% 25.93 ms +3.12% -3.24% 0%
wpTemplate 17.38 ms +2.53% -2.01% 17.56 ms +3.42% -1.88% -1.03%
wpTotal 43.64 ms +6.87% -3.6% 43.17 ms +6.97% -1.07% 1.09%
wpMemoryUsage 6.25 MB +0% -0% 6.20 MB +0% -0% 0.71%
wpDbQueries 14 +0% -0% 14 +0% -0% 0%

media-processing

Metric 78e3d5e trunk % Change
mediaProcessingJpeg 398.2 ms +0.36% -0.2% 398.86 ms +0.81% -1% -0.17%
mediaProcessingAvif 6029 ms +0.42% -0.33% 6013.85 ms +0.08% -0.09% 0.25%
mediaProcessingJpegToAvif 4160.29 ms +0.08% -0.17% 4146.97 ms +0.15% -0.37% 0.32%

media-upload

Metric 78e3d5e trunk % Change
jpegUploadProcessing 1413.46 ms +35.58% -0.57% 1407.93 ms +0.29% -0.25% 0.39%
pngUploadProcessing 176.53 ms +5.5% -5.9% 173.68 ms +1.67% -5.92% 1.64%
largeJpegUploadProcessing 1407.87 ms +0.52% -0.8% 1396.88 ms +0.82% -0.48% 0.79%
multipleImageUploadProcessing 1548.99 ms +9.86% -1.27% 1558.89 ms +1.52% -0.72% -0.64%

post-editor

Metric 78e3d5e trunk % Change
serverResponse 507.72 ms +5.55% -6.74% 515.28 ms +2.04% -5.46% -1.47%
firstPaint 230.46 ms +15.07% -4.89% 243.37 ms +22.67% -9.89% -5.3%
domContentLoaded 1094.64 ms +1.3% -0.77% 1081.76 ms +1.48% -0.42% 1.19%
loaded 1096.03 ms +1.29% -0.76% 1083.21 ms +1.48% -0.43% 1.18%
firstContentfulPaint 456.04 ms +2.31% -2.52% 449.78 ms +1.35% -2.92% 1.39%
firstBlock 3263.52 ms +2.2% -1.83% 3247.37 ms +0.52% -0.06% 0.5%
type 17.02 ms +1.29% -3.88% 17.41 ms +10.57% -3.1% -2.24%
typeWithoutInspector 17.8 ms +7.87% -4.83% 18.69 ms +1.28% -9.04% -4.76%
typeWithTopToolbar 22.21 ms +5.85% -1.04% 22.11 ms +1.67% -2.89% 0.45%
typeContainer 8.01 ms +6.99% -1.75% 8.33 ms +6.72% -9% -3.84%
focus 69.56 ms +9.72% -3.39% 73.83 ms +3.1% -4.93% -5.78%
firstFocus 202.06 ms +0% -0% 210.46 ms +0% -0% -3.99%
selectAll 540.47 ms +2.42% -3.25% 555.76 ms +5.8% -4.61% -2.75%
listViewOpen 63.57 ms +12.77% -7.85% 64.46 ms +4.7% -11.4% -1.38%
inserterOpen 24.71 ms +9.83% -12.75% 21.97 ms +25.22% -10.83% 12.47%
inserterHover 2.17 ms +11.06% -9.22% 2.12 ms +20.28% -11.32% 2.36%
inserterSearch 8.19 ms +5.49% -5.49% 7.77 ms +8.62% -8.37% 5.41%
loadPatterns 639.49 ms +0.6% -3.49% 619.33 ms +2.29% -2.04% 3.26%
wpTotal 497.56 ms +5.61% -6.84% 505.14 ms +2.08% -5.48% -1.5%
wpMemoryUsage 13.17 MB +0% -0% 13.13 MB +0% -0% 0.28%
wpDbQueries 54 +0% -1.85% 54 +0% -0% 0%

site-editor

Metric 78e3d5e trunk % Change
serverResponse 478.96 ms +5.45% -2.63% 505.18 ms +4.26% -5.37% -5.19%
firstPaint 285.91 ms +74.73% -15.88% 262.11 ms +11.79% -19% 9.08%
domContentLoaded 1152.3 ms +1.43% -0.71% 1151.95 ms +1.46% -1.34% 0.03%
loaded 1153.38 ms +1.46% -0.71% 1153.29 ms +1.46% -1.36% 0.01%
firstContentfulPaint 464.08 ms +7.65% -3.02% 453.17 ms +4.36% -1.73% 2.41%
firstBlock 4228.05 ms +2.2% -0.99% 4199.79 ms +0.48% -0.62% 0.67%
type 17.79 ms +12.31% -4.5% 17.93 ms +5.58% -5.47% -0.78%
navigate 106.05 ms +7.86% -7.41% 120.03 ms +27.11% -20.9% -11.65%
loadPatterns 1329.26 ms +9.26% -3.11% 1361.92 ms +14.56% -6.79% -2.4%
loadPages 1059.09 ms +1.67% -1.47% 1086.16 ms +2% -1.89% -2.49%
wpTotal 469.67 ms +5.53% -2.76% 495.19 ms +4.3% -5.43% -5.15%
wpMemoryUsage 12.14 MB +0% -0% 12.09 MB +0% -0% 0.41%
wpDbQueries 43.5 +1.15% -1.15% 43.5 +1.15% -1.15% 0%

c9eebea Run

🏁 Flaky tests

Some tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information.

applies the filtered form to the Quick Edit DataForm in /test/e2e/specs/site-editor/view-config-extensibility.spec.js, passed after 1 failed attempt.
Error: apiRequestContext.fetch: socket hang up
Call log:
  - → PUT http://localhost:8889/wp-json/wp/v2/users/me
    - user-agent: Playwright/1.63.0 (x64; ubuntu 24.04) node/24.18 CI/1
    - accept: */*
    - accept-encoding: gzip,deflate,br
    - X-WP-Nonce: c6e36df00a
    - content-type: application/json
    - content-length: 37
    - cookie: wordpress_test_cookie=WP%20Cookie%20check; wordpress_logged_in_23778236db82f19306f247e20a353a99=admin%7C1791047491%7CrXMqmFDjASm9dZvlabugmWZ5Xhgl5SvRmQo8TpscvtK%7C1f166971c0cfab55f2cacd4c4038480073d46b5d0fb82714a307252049e582b9; wp-settings-time-1=1790875241

    at RequestUtils.rest (/home/runner/work/gutenberg/gutenberg/packages/e2e-test-utils-playwright/src/request-utils/rest.ts:112:39)
    at RequestUtils.resetPreferences (/home/runner/work/gutenberg/gutenberg/packages/e2e-test-utils-playwright/src/request-utils/preferences.ts:9:13)
    at /home/runner/work/gutenberg/gutenberg/test/e2e/specs/site-editor/view-config-extensibility.spec.js:59:17

c9eebea Run

@ciampo ciampo self-assigned this Oct 1, 2026
@ciampo
ciampo requested review from Mamaduka, jeryj, manzoorwanijk and ramonjd and removed request for ramonjd October 1, 2026 21:21
@ciampo ciampo added the [Type] Enhancement A suggestion for improvement. label Oct 1, 2026
@ciampo
ciampo marked this pull request as ready for review October 1, 2026 21:21
@ciampo
ciampo merged commit 7e63d3d into trunk Oct 2, 2026
105 of 107 checks passed
@ciampo
ciampo deleted the codex/patch-ai-basic-ftp branch October 2, 2026 05:46
@github-actions github-actions Bot added this to the Gutenberg 24.2 milestone Oct 2, 2026
widoz pushed a commit to widoz/gutenberg that referenced this pull request Oct 2, 2026
Co-authored-by: ciampo <mciampini@git.wordpress.org>
Co-authored-by: jeryj <jeryj@git.wordpress.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

[Type] Enhancement A suggestion for improvement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants