Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

@agentos-software/pi bundles @mariozechner/pi-coding-agent 0.60.0, affected by GHSA-jfgx-wxx8-mp94 (fixed only in @earendil-works/pi-coding-agent 0.78.1+)

未关闭
#2,008 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
45/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
javascript
领域
backend, security

调研方向

Start with dist/adapter.js and dist/sdk-snapshot.js, then inspect the current adapter imports and package references. Build the package against @earendil-works/pi-coding-agent and @earendil-works/pi-ai at 0.78.1 or newer, update the changed async auth APIs, and verify the published bundle no longer runs the vulnerable @mariozechner packages.

由索引模型根据 Issue 内容生成。

描述

Summary

@agentos-software/pi (checked 0.2.7 and the latest, 0.3.2) depends on and bundles @mariozechner/[email protected] (and @mariozechner/[email protected]) into dist/sdk-snapshot.js. That package line stopped at 0.73.1: Pi moved to @earendil-works/pi-coding-agent, and these advisories list no fix for the @mariozechner name:

Advisory Severity Affected @mariozechner/pi-coding-agent Fixed
GHSA-jfgx-wxx8-mp94 (CVE-2026-54328) — predictable temporary extension install paths, local privilege escalation on shared Linux hosts High >= 0.50.0, <= 0.73.1 @earendil-works/pi-coding-agent 0.78.1
GHSA-7v5m-pr3q-6453 (CVE-2026-54326) — XSS in HTML session exports Low >= 0.27.5, <= 0.73.1 same
GHSA-r95r-rj6r-c39x (CVE-2026-54327) — auth.json write race Low >= 0.28.0, <= 0.73.1 same

Downstream scanners flag every consumer, and an npm overrides entry is not a workaround: the adapter prefers the bundled snapshot (if (snapshotRuntime) in dist/adapter.js), so overriding the dependency changes only the lockfile, not what runs.

Request

Publish an @agentos-software/pi built on @earendil-works/pi-coding-agent / @earendil-works/pi-ai >= 0.78.1. Note the adapter imports internal paths (dist/core/sdk.js, session-manager.js, model-registry.js, ...) and @mariozechner/pi-agent-core; those still exist under the new package names, but the auth APIs changed (e.g. AuthStorage is no longer exported from the package root and credential operations are async).

Related: #1903.

主要语言
Rust
星标
4.7k
派生
263
平均合并
9 小时 43 分钟
30 天内合并 PR
27

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

rivet-dev/agentos 的其他 Issue

查看 rivet-dev/agentos 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。