Skip to content

chore(deps): 29 npm audit advisories → 4, critical cleared; add LICENSE + SECURITY.md - #3

Merged
Shailesh93602 merged 2 commits into
mainfrom
chore/audit-clean
Sep 6, 2026
Merged

Shailesh93602 merged 2 commits into
mainfrom
chore/audit-clean

Conversation

@Shailesh93602

Copy link
Copy Markdown
Owner

Security/hygiene pass only — no features, no restructuring. Closes the long-open LIB-9 (no LICENSE) alongside the audit work.

Before → after

full npm audit --omit=dev
before 29 (1 critical, 16 high, 9 moderate, 3 low) 23
after 4 (0 critical, 4 high) 4

The tracker said 23; the real number on main today was 29. Three clusters, handled differently.

1. Lockfile-only — npm audit fix, no package.json change, no major (29 → 12)

@babel/core, @humanfs/node, body-parser, brace-expansion, browserslist, express-rate-limit, fast-uri, hono, ip-address, js-yaml, nanoid, postcss-selector-parser, qs, ws.

2. next 16.2.1 → 16.3.4 — a minor (npm reports isSemVerMajor: false)

Clears next (DoS with Server Components; App Router middleware/proxy bypass via segment-prefetch routes), postcss (arbitrary .map file read via attacker-controlled sourceMappingURL) and sharp (libvips CVEs). Kept the exact pin the repo already used rather than loosening it to a caret, and moved eslint-config-next in lockstep.

3. vitest ^2.1.9 → ^3.2.7 — clears the critical

Arbitrary file read/execute while the Vitest UI server is listening, plus vite, vite-node, @vitest/mocker, esbuild. 3.2.7 is the first release outside the <=3.2.5 range. Not vitest 5.0.0 — it needs Node ^22.12 and CI here is node-version: 20.

What is deliberately NOT fixed — the 4 remaining

The whole residue is the prisma CLI cluster: prisma, @prisma/config, deepmerge-ts, mysql2.

🔴 npm audit fix --force proposes prisma@6.19.3 — a major downgrade from the 7.10.0 installed here, incompatible with @prisma/client@^7.5.0. The advisory range is >=6.13.0-dev.1 with no upper bound, so no patched 7.x exists yet. Downgrading a working, current ORM one whole major to silence a CLI-only advisory would make this app less safe, not more.

None of the four is reachable at runtime, and that is verified rather than assumed:

  • the app is PostgreSQL (provider = "postgresql", @prisma/adapter-pg), so the mysql2 the Prisma CLI bundles for MySQL support is never loaded — zero mysql references in app/, lib/ or prisma/
  • deepmerge-ts is reached only when the CLI parses prisma.config.ts at build/dev time, over a file committed to this repo — not attacker-controlled
  • zero application imports of the prisma package; production runs @prisma/client + @prisma/adapter-pg, neither of which carries an advisory

Written up in SECURITY.md rather than left for a reader to guess.

Also in this PR

  • LICENSE (MIT) — this was the only one of the four library/portfolio repos without one, so a public repo linked from the portfolio read as all-rights-reserved. Same text and holder as grounded / promptproof / idempotency-kit. Also set "license": "MIT" in package.json.
  • SECURITY.md — reporting channel plus the residue above.

Gate — unchanged and green

before after
type-check clean clean
lint 0 errors 0 errors (see below)
test:unit 37 passed 37 passed

Two honest notes:

  • next 16.3.4 adds one new lint warning (0 errors — eslint exits 0, CI stays green) on the pre-existing location.href navigation in the dashboard error boundary. Left alone deliberately: a hard reload there is defensible for clearing broken client state, and changing error-recovery behaviour is not a dependency-hygiene change.
  • format:check fails on 17 files — pre-existing on main, not caused by this PR, and not part of CI. Flagged, not fixed here.

Playwright e2e was not run: it needs a live Supabase project (the standing LIB-11 blocker).

Measured on main today: 29 advisories (1 critical, 16 high, 9 moderate, 3 low);
23 of them present with `--omit=dev`. Three clusters, handled differently.

1. Lockfile-only (`npm audit fix`, no package.json change, no major): 29 -> 12.
   @babel/core, @humanfs/node, body-parser, brace-expansion, browserslist,
   express-rate-limit, fast-uri, hono, ip-address, js-yaml, nanoid,
   postcss-selector-parser, qs, ws.

2. next 16.2.1 -> 16.3.4 (a minor -- npm reports isSemVerMajor: false).
   Clears next (DoS with Server Components; App Router middleware/proxy bypass
   via segment-prefetch routes), postcss (arbitrary .map file read via
   attacker-controlled sourceMappingURL) and sharp (libvips CVEs). Kept the
   exact pin the repo already used rather than loosening it to a caret, and
   moved eslint-config-next to 16.3.4 in lockstep.

3. vitest ^2.1.9 -> ^3.2.7 clears the critical (arbitrary file read/execute
   while the Vitest UI server is listening) plus vite, vite-node,
   @vitest/mocker, esbuild. 3.2.7 is the first release outside the <=3.2.5
   range; not vitest 5.0.0, which needs Node ^22.12 while CI here is node 20.

Deliberately NOT applied: the `prisma` cluster (4 high). npm proposes
prisma@6.19.3, which is a major DOWNGRADE from the 7.10.0 installed here and
incompatible with @prisma/client@^7.5.0 -- the advisory range is >=6.13.0-dev.1
with no upper bound, so no patched 7.x exists yet. Documented in SECURITY.md
with the reachability analysis; none of the four is reachable at runtime.

npm audit: 29 -> 4 (0 critical, 4 high, all in the prisma CLI).
Gate before and after, both green: type-check clean, lint 0 errors,
37 unit tests passing.

next 16.3.4 adds one new lint WARNING (0 errors, CI still green) on the
pre-existing `location.href` navigation in the dashboard error boundary. Left
alone: a hard reload there is deliberate, and changing error-recovery behaviour
is not a dependency-hygiene change.
LICENSE: this was the only one of the four library/portfolio repos without one,
so it read as all-rights-reserved on a public repo linked from the portfolio.
MIT, same text and copyright holder as grounded / promptproof / idempotency-kit.
Also set "license": "MIT" in package.json, which had no license field.

SECURITY.md: states the 4 advisories that remain after the dependency pass, why
each is not fixed (no patched prisma 7.x exists; npm's only proposal is a major
downgrade to 6.19.3 that breaks @prisma/client@^7.5.0), and whether each is
reachable at runtime. None is: the app is PostgreSQL via @prisma/adapter-pg, so
the bundled mysql2 is never loaded, and @prisma/config parses a committed config
file at build time. Verified -- zero mysql references in app/, lib/ or prisma/,
and no application import of the `prisma` CLI package.
@vercel

vercel Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
dev-track Ready Ready Preview Sep 6, 2026 10:41am UTC

@Shailesh93602
Shailesh93602 merged commit 63a2fcb into main Sep 6, 2026
4 checks passed
@Shailesh93602
Shailesh93602 deleted the chore/audit-clean branch September 6, 2026 10:43

This branch was successfully deployed

1 active deployment
Preview — 660b73e2 Deployed Sep 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant