chore(deps): bump ip-address from 10.5.0 to 10.7.2 - #991
Conversation
Lockfile-only bump of the one package the security advisory names. Dependabot's regenerated lockfile also moved hono, shell-quote, rollup, esbuild, postcss and others to versions younger than the 7-day minimumReleaseAge, which --frozen-lockfile CI never re-checks. express-rate-limit 8.6.2 already accepts ip-address ^10.2.0, so no other entry needs to move.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
freshtonic
left a comment
There was a problem hiding this comment.
Approved. The diff is four lines in pnpm-lock.yaml, and it agrees with the description:
ip-addressoccurs in three places in the lockfile at this head: the package entry (line 2519), theexpress-rate-limitsnapshot (line 4951), and its own snapshot (line 5179). All three now say 10.7.2. No 10.5.0 reference remains.- The integrity hash is the one value here that a reader cannot check by eye. The CI test jobs passed, and they install with
--frozen-lockfile. A wrong hash would make that install fail, so CI has checked it. - 10.7.2 is in the
^10.2.0range thatexpress-rate-limitdeclares, so the parent stays where it is. - No changeset is correct. The lockfile is not in a published tarball, and the
stash-supply-chain-securityskill has no rule that this change affects.
I agree with the reason for the hand edit. A --frozen-lockfile install does not apply minimumReleaseAge, so a lockfile that Dependabot writes can bring in versions younger than the 7-day cooldown. Keeping this bump to one package is the correct approach. A general fix, such as a CI check that compares new lockfile versions against the cooldown, can go in a separate issue if you want one.
Summary
Updates
ip-addressfrom 10.5.0 to 10.7.2 in the lockfile, and changes nothing else. This replaces Dependabot's #990, which bumped the same package but also moved about 15 unrelated packages to new versions, some of them published only hours earlier.The repo has a 7-day install cooldown (
minimumReleaseAge: 10080inpnpm-workspace.yaml): pnpm refuses package versions younger than a week, so a malicious release is usually caught and pulled before we install it. pnpm only enforces that rule when it picks versions. CI installs with--frozen-lockfile, which installs whatever the lockfile says without picking anything, so versions written into the lockfile by Dependabot never meet the check.Changes
pnpm-lock.yaml:ip-address10.5.0 → 10.7.2 (package entry, integrity hash, and the one reference fromexpress-rate-limit). Four lines.Verification
pnpm install --frozen-lockfile --lockfile-onlypasses against the edited lockfile.express-rate-limit@8.6.2(already locked) declaresip-address: ^10.2.0, so 10.7.2 satisfies it and it does not need to move.ip-address@10.7.2has no dependencies and the sameenginesas 10.5.0.ip-address@10.7.2was published 2026-09-15, past the 7-day cooldown.pnpm update -r ip-address --lockfile-onlywas tried first and re-resolved hono, rollup, esbuild, postcss, jose, nanoid, picomatch and others as well, so it would have recreated the problem.Related
Review notes
No changeset: the lockfile is not shipped in any published package.