Skip to content

fix(sei-global-wallet): raise the axios override to 1.20.0 - #354

Merged
alexander-sei merged 2 commits into
mainfrom
fix/global-wallet-axios-advisories
Oct 2, 2026
Merged

alexander-sei merged 2 commits into
mainfrom
fix/global-wallet-axios-advisories

Conversation

@alexander-sei

Copy link
Copy Markdown
Collaborator

Fixes the scheduled Sei Global Wallet Consumer Smoke failure, which has been red since October 1.

Twelve Axios advisories published on 2026-09-30 (seven high, five medium) cover every release below 1.20.0, including the 1.18.0 we override Dynamic's exact axios@1.16.0 pin to. The wallet-only npm consumer, which is held to a strictly clean audit, reported axios plus the eight Dynamic packages above it in the dependency chain.

Changes

  • Move the axios override from 1.18.0 to 1.20.0 in the verifier's override set, all three README override blocks, and the workspace root override. bun.lock changes only the axios entry. 1.20.0 is the first release with no open advisory (1.19.0 still carries all twelve), and it ships the same exports and dependencies as 1.18.0 apart from a form-data floor of ^4.0.6.
  • Rewrite the README's Axios note, which described only the Node HTTP adapter issue that 1.18.0 cleared. The high-severity issues against Dynamic's pin are in Node-only transports or are prototype-pollution gadgets, and the toFormData and fetch-adapter gadgets also apply in browsers.
  • Add a @sei-js/sei-global-wallet patch changeset, since the override guidance ships in the package README.

Verification

  • bun run test:sei-global-wallet-release (full run, without the fast-check flag) passes locally: the wallet-only npm consumer audits clean, and the full npm and Bun consumers report only advisories already in the waiver.
  • bun run test:create-sei-release passes locally. The changeset makes that workflow run on this PR as well; the generated apps don't depend on axios, and the only finding is the existing moderate decode-uri-component advisory.
  • bun run check (Biome and typecheck) and bun run test:scripts (48 tests) pass.

No published dependency or peer range changes.

Twelve Axios advisories published on 2026-09-30 cover every release
below 1.20.0, including the 1.18.0 that the README override blocks and
the consumer verifier pinned, so the nightly consumer smoke went red
without any change in this repository. The wallet-only npm consumer,
which must audit clean, reported axios plus the eight Dynamic packages
above it in the dependency chain.

Dynamic still pins axios@1.16.0 exactly, so the fix stays a root
override: the verifier's override set, all three README blocks, and the
workspace override move to 1.20.0, the first release with no open
advisory. It keeps the exports and dependencies of 1.18.0 apart from a
form-data floor of ^4.0.6, which the lockfile already satisfied.

The README's Axios note described only the Node HTTP adapter issue that
1.18.0 cleared. It now covers the new set, including the toFormData and
fetch-adapter gadgets that also apply in browsers.

Co-authored-by: Cursor <cursoragent@cursor.com>
@cursor

cursor Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Dependency override and documentation alignment only; no wallet runtime or API changes, with axios 1.20.0 described as API-compatible aside from a form-data floor bump.

Overview
Bumps the root axios override from 1.18.0 to 1.20.0 so consumer smoke/audit jobs pass after September 2026 advisories that affect every release below 1.20.0. Dynamic still pins axios@1.16.0, so the fix stays a documented root override only—updated in the workspace package.json, bun.lock, all three Required consumer overrides blocks in packages/sei-global-wallet/README.md, and the baseSafeOverrides set in scripts/check-sei-global-wallet.ts.

The README Axios security note is rewritten to reflect the current advisory set (Node-only transports vs browser-relevant toFormData/fetch-adapter issues), not just the older Node HTTP adapter wording tied to 1.18.0.

A @sei-js/sei-global-wallet patch changeset records the README guidance change. No published dependency or peer range changes.

Reviewed by Cursor Bugbot for commit 503f10b. Bugbot is set up for automated code reviews on this repo. Configure here.

@codecov-commenter

codecov-commenter commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.82%. Comparing base (b7f4e54) to head (503f10b).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #354   +/-   ##
=======================================
  Coverage   97.82%   97.82%           
=======================================
  Files          81       81           
  Lines        5652     5652           
=======================================
  Hits         5529     5529           
  Misses        123      123           
Flag Coverage Δ
mcp-server 96.92% <ø> (ø)
precompiles 100.00% <ø> (ø)
registry 100.00% <ø> (ø)
sei-global-wallet 100.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR raises the axios override from 1.18.0 to 1.20.0 everywhere it appears: the root override, bun.lock, the verifier's base overrides and all three README override blocks. It also includes a patch changeset. The changes are consistent and I found no correctness or security problems. My only notes are non-blocking.

Findings: 0 blocking | 3 non-blocking | 0 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • The Cursor review file was empty, so that second-opinion pass gave no output. Codex reported no material issues.
  • scripts/documented-overrides.test.ts and scripts/dynamic-package-lock.test.ts still use axios: '1.18.0' in their fixtures. These are synthetic parser inputs, so nothing is functionally wrong. Bumping them to 1.20.0 is optional and would stop future greps for stale pins from matching them.
  • The advisory claims can't be checked from the diff: twelve advisories, 1.20.0 being the first clean release, and 1.19.0 still affected. Linking the GHSA IDs in the changeset or README would let readers verify the override choice and make it easier to tell when the override can be removed later.

Co-authored-by: Cursor <cursoragent@cursor.com>

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR moves the axios override from 1.18.0 to 1.20.0 in five places: the root package.json, bun.lock, the verifier's base override set, and all three README override blocks. It also includes a patch changeset as REVIEW_GUIDELINES §3 asks. The change is consistent across all of them and I found no correctness or security problems.

Findings: 0 blocking | 3 non-blocking | 0 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • The Cursor review file (cursor-review.md) was empty, so that pass produced no output. Codex reported no material issues, and I agree.
  • scripts/documented-overrides.test.ts still uses axios: '1.18.0' in its README fixture. That fixture is self-contained and only tests the parser, not the real README, so it is correct as written. Updating it to 1.20.0 is optional and would only stop a future grep for stale pins from matching it.
  • I could not check the advisory IDs or the claim that 1.20.0 is the first clean release against the GitHub advisory database from the diff alone. The PR's verification steps (a clean wallet-only npm audit, plus the Bun and full npm consumer runs) are the evidence for that claim. The lockfile entry's form-data ^4.0.6 floor matches the description.

@alexander-sei
alexander-sei merged commit 54c991f into main Oct 2, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants