fleet-memory/hindsight-integration-tests
Nicolò Boschi ea27ef95ec
fix: resolve all Dependabot security vulnerabilities (#486)
* fix: resolve all Dependabot security vulnerabilities

npm (package-lock.json):
- fast-xml-parser: 4.5.3 → 4.5.4 (critical entity encoding bypass + DoS)
- serialize-javascript: 6.0.2 → 7.0.4 (high RCE via RegExp/Date)
- minimatch: 3.1.2 → 3.1.5, 5.1.6 → 5.1.9, 9.0.5 → 9.0.9 (high ReDoS)
- ajv: 6.12.6 → 6.14.0, 8.17.1 → 8.18.0 (medium ReDoS with $data option)
- qs: 6.14.1 → 6.15.0 (low arrayLimit bypass DoS)
- rollup: 4.57.x → 4.59.0 in ai-sdk and openclaw integrations (high path traversal)

Python (uv.lock / pyproject.toml):
- cryptography: 46.0.3 → 46.0.5 (high subgroup attack on SECT curves)
- pillow: 12.0.0 → 12.1.1 (high out-of-bounds write in PSD loading)
- langchain-core: 1.2.7 → 1.2.17 (low SSRF in ChatOpenAI token counting)
- langsmith: 0.4.42 → 0.7.11 (medium SSRF via tracing header injection)
- protobuf: 6.33.1 → 6.33.5 (high JSON recursion depth bypass)

Rust (Cargo.lock):
- bytes: 1.11.0 → 1.11.1 in hindsight-clients/rust (medium integer overflow)

Remaining unfixable: diskcache <= 5.6.3 (no patched version available)

* fix: remove over-broad schema-utils ajv override that broke docs build

The 'schema-utils': {'ajv': '^8.18.0'} override was forcing schema-utils@3.x
(used by url-loader/file-loader with ajv-keywords@3.x) to use ajv@8.18.0.
In 8.18.0, internal property _formats was renamed to formats, breaking
ajv-keywords@3.x's _formatLimit.js which accesses ajv._formats.date.

Removing the broad override: schema-utils@4.3.3 (root level) already has
ajv@8.18.0 in its nested install from the prior npm update, while
schema-utils@3.x correctly falls back to the hoisted root ajv@6.14.0.
2026-03-04 13:14:50 +01:00
..
tests feat: add reverse proxy support (#346) 2026-02-12 10:09:53 +01:00
pyproject.toml fix: resolve all Dependabot security vulnerabilities (#486) 2026-03-04 13:14:50 +01:00
README.md feat: add reverse proxy support (#346) 2026-02-12 10:09:53 +01:00
uv.lock fix: resolve all Dependabot security vulnerabilities (#486) 2026-03-04 13:14:50 +01:00

Hindsight Integration Tests

E2E and integration tests for Hindsight API that require a running server.

Test Types

1. Tests with External Server

Tests like test_mcp_e2e.py expect a server to already be running.

Running:

# Start the API server
./scripts/dev/start-api.sh

# Run tests
cd hindsight-integration-tests
HINDSIGHT_API_URL=http://localhost:8888 uv run pytest tests/test_mcp_e2e.py -v

2. Self-Contained Tests

Tests like test_base_path_deployment.py manage their own server lifecycle and use docker-compose.

Running:

cd hindsight-integration-tests

# Run with pytest
uv run pytest tests/test_base_path_deployment.py -v

# Or run directly for nice output
uv run python tests/test_base_path_deployment.py

Requirements:

  • Docker and docker-compose installed (for reverse proxy test)
  • No nginx required on host!

What it tests:

  • API with base path (direct server)
  • Full reverse proxy via docker-compose + Nginx
  • Regression: API without base path
  • Full retain/recall workflow

These tests:

  • Start their own API servers on dedicated ports (18888-18891)
  • Use docker-compose to test actual deployment scenarios
  • Run in parallel with other tests (no port conflicts)
  • Clean up automatically

Running All Tests

cd hindsight-integration-tests
uv run pytest tests/ -v

This runs both types. Self-contained tests won't conflict with the external server.

Environment Variables

  • HINDSIGHT_API_URL - Base URL for external-server tests (default: http://localhost:8888)