Tests: Patch basic-ftp in AI development dependencies - #84000
Conversation
🤖 PR meta 🤖🎉 PropsIf you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. Updated as activity occurs, without notifying anyone named here. Add the 📦 Bundle sizeSize Change: 0 B Total Size: 8.25 MB
⚡ PerformanceShow the resultsClient side metrics exclude the server response time. front-end-block-theme
front-end-classic-theme
media-processing
media-upload
post-editor
site-editor
🏁 Flaky testsSome tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information. applies the filtered form to the Quick Edit DataForm in
|
Co-authored-by: ciampo <mciampini@git.wordpress.org> Co-authored-by: jeryj <jeryj@git.wordpress.org>
Follow-up to the unrelated AI dependency audit failure observed in #83996. See GHSA-c475-qrg2-pj4r.
What?
Update the standalone AI development package's transitive
basic-ftpdependency to 6.2.1.Why?
The new advisory affects the Unix directory-listing parser and fails the AI development CI audit. This dependency belongs to Promptfoo's separate lockfile and is unrelated to the Vitest and Storybook update.
How?
Add a scoped
get-urioverride and update its lockfile.get-uri@8.0.1still requests version 5, while the security fix is in 6.2.1. Keep Promptfoo at 0.123.1 and document the override.Testing Instructions
PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1 npm ci --prefix test/ai-development.npm --prefix test/ai-development audit --audit-level=high. Expect zero vulnerabilities.npm --prefix test/ai-development run test:utilsandnpm --prefix test/ai-development run validate.Verification
A clean install, dependency resolution, configuration validation, and all 24 offline utility tests pass. Two live model tests remain skipped. A local FTP server probe verifies
get-urilisting and download compatibility with 6.2.1. The same probe confirms that the advisory's malicious directory listing completes promptly. The repository build, formatting, package-manifest lint, and lockfile checks pass. The root lockfile is unchanged.Use of AI Tools
Codex investigated the advisory, updated the dependency override and lockfile, and ran verification.