Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

@agentos-software/pi bundles @mariozechner/pi-coding-agent 0.60.0, affected by GHSA-jfgx-wxx8-mp94 (fixed only in @earendil-works/pi-coding-agent 0.78.1+)

オープン
#2,008 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
45/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
javascript
領域
backend, security

調査の方向性

Start with dist/adapter.js and dist/sdk-snapshot.js, then inspect the current adapter imports and package references. Build the package against @earendil-works/pi-coding-agent and @earendil-works/pi-ai at 0.78.1 or newer, update the changed async auth APIs, and verify the published bundle no longer runs the vulnerable @mariozechner packages.

索引モデルが issue の本文から書いたものです。

説明

Summary

@agentos-software/pi (checked 0.2.7 and the latest, 0.3.2) depends on and bundles @mariozechner/[email protected] (and @mariozechner/[email protected]) into dist/sdk-snapshot.js. That package line stopped at 0.73.1: Pi moved to @earendil-works/pi-coding-agent, and these advisories list no fix for the @mariozechner name:

Advisory Severity Affected @mariozechner/pi-coding-agent Fixed
GHSA-jfgx-wxx8-mp94 (CVE-2026-54328) — predictable temporary extension install paths, local privilege escalation on shared Linux hosts High >= 0.50.0, <= 0.73.1 @earendil-works/pi-coding-agent 0.78.1
GHSA-7v5m-pr3q-6453 (CVE-2026-54326) — XSS in HTML session exports Low >= 0.27.5, <= 0.73.1 same
GHSA-r95r-rj6r-c39x (CVE-2026-54327) — auth.json write race Low >= 0.28.0, <= 0.73.1 same

Downstream scanners flag every consumer, and an npm overrides entry is not a workaround: the adapter prefers the bundled snapshot (if (snapshotRuntime) in dist/adapter.js), so overriding the dependency changes only the lockfile, not what runs.

Request

Publish an @agentos-software/pi built on @earendil-works/pi-coding-agent / @earendil-works/pi-ai >= 0.78.1. Note the adapter imports internal paths (dist/core/sdk.js, session-manager.js, model-registry.js, ...) and @mariozechner/pi-agent-core; those still exist under the new package names, but the auth APIs changed (e.g. AuthStorage is no longer exported from the package root and credential operations are async).

Related: #1903.

主要言語
Rust
スター
4.7k
フォーク
263
平均マージ
9時間 43分
マージ済み PR(30日)
27

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

rivet-dev/agentos のほかの issue

rivet-dev/agentos の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。