Repository navigation
chore(deps): 29 npm audit advisories → 4, critical cleared; add LICENSE + SECURITY.md - #3
Merged
Merged
Conversation
Measured on main today: 29 advisories (1 critical, 16 high, 9 moderate, 3 low); 23 of them present with `--omit=dev`. Three clusters, handled differently. 1. Lockfile-only (`npm audit fix`, no package.json change, no major): 29 -> 12. @babel/core, @humanfs/node, body-parser, brace-expansion, browserslist, express-rate-limit, fast-uri, hono, ip-address, js-yaml, nanoid, postcss-selector-parser, qs, ws. 2. next 16.2.1 -> 16.3.4 (a minor -- npm reports isSemVerMajor: false). Clears next (DoS with Server Components; App Router middleware/proxy bypass via segment-prefetch routes), postcss (arbitrary .map file read via attacker-controlled sourceMappingURL) and sharp (libvips CVEs). Kept the exact pin the repo already used rather than loosening it to a caret, and moved eslint-config-next to 16.3.4 in lockstep. 3. vitest ^2.1.9 -> ^3.2.7 clears the critical (arbitrary file read/execute while the Vitest UI server is listening) plus vite, vite-node, @vitest/mocker, esbuild. 3.2.7 is the first release outside the <=3.2.5 range; not vitest 5.0.0, which needs Node ^22.12 while CI here is node 20. Deliberately NOT applied: the `prisma` cluster (4 high). npm proposes prisma@6.19.3, which is a major DOWNGRADE from the 7.10.0 installed here and incompatible with @prisma/client@^7.5.0 -- the advisory range is >=6.13.0-dev.1 with no upper bound, so no patched 7.x exists yet. Documented in SECURITY.md with the reachability analysis; none of the four is reachable at runtime. npm audit: 29 -> 4 (0 critical, 4 high, all in the prisma CLI). Gate before and after, both green: type-check clean, lint 0 errors, 37 unit tests passing. next 16.3.4 adds one new lint WARNING (0 errors, CI still green) on the pre-existing `location.href` navigation in the dashboard error boundary. Left alone: a hard reload there is deliberate, and changing error-recovery behaviour is not a dependency-hygiene change.
LICENSE: this was the only one of the four library/portfolio repos without one, so it read as all-rights-reserved on a public repo linked from the portfolio. MIT, same text and copyright holder as grounded / promptproof / idempotency-kit. Also set "license": "MIT" in package.json, which had no license field. SECURITY.md: states the 4 advisories that remain after the dependency pass, why each is not fixed (no patched prisma 7.x exists; npm's only proposal is a major downgrade to 6.19.3 that breaks @prisma/client@^7.5.0), and whether each is reachable at runtime. None is: the app is PostgreSQL via @prisma/adapter-pg, so the bundled mysql2 is never loaded, and @prisma/config parses a committed config file at build time. Verified -- zero mysql references in app/, lib/ or prisma/, and no application import of the `prisma` CLI package.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security/hygiene pass only — no features, no restructuring. Closes the long-open LIB-9 (no LICENSE) alongside the audit work.
Before → after
npm audit--omit=devThe tracker said 23; the real number on
maintoday was 29. Three clusters, handled differently.1. Lockfile-only —
npm audit fix, nopackage.jsonchange, no major (29 → 12)@babel/core,@humanfs/node,body-parser,brace-expansion,browserslist,express-rate-limit,fast-uri,hono,ip-address,js-yaml,nanoid,postcss-selector-parser,qs,ws.2.
next 16.2.1 → 16.3.4— a minor (npm reportsisSemVerMajor: false)Clears
next(DoS with Server Components; App Router middleware/proxy bypass via segment-prefetch routes),postcss(arbitrary.mapfile read via attacker-controlledsourceMappingURL) andsharp(libvips CVEs). Kept the exact pin the repo already used rather than loosening it to a caret, and movedeslint-config-nextin lockstep.3.
vitest ^2.1.9 → ^3.2.7— clears the criticalArbitrary file read/execute while the Vitest UI server is listening, plus
vite,vite-node,@vitest/mocker,esbuild. 3.2.7 is the first release outside the<=3.2.5range. Not vitest 5.0.0 — it needs Node^22.12and CI here isnode-version: 20.What is deliberately NOT fixed — the 4 remaining
The whole residue is the
prismaCLI cluster:prisma,@prisma/config,deepmerge-ts,mysql2.🔴
npm audit fix --forceproposesprisma@6.19.3— a major downgrade from the7.10.0installed here, incompatible with@prisma/client@^7.5.0. The advisory range is>=6.13.0-dev.1with no upper bound, so no patched 7.x exists yet. Downgrading a working, current ORM one whole major to silence a CLI-only advisory would make this app less safe, not more.None of the four is reachable at runtime, and that is verified rather than assumed:
provider = "postgresql",@prisma/adapter-pg), so themysql2the Prisma CLI bundles for MySQL support is never loaded — zero mysql references inapp/,lib/orprisma/deepmerge-tsis reached only when the CLI parsesprisma.config.tsat build/dev time, over a file committed to this repo — not attacker-controlledprismapackage; production runs@prisma/client+@prisma/adapter-pg, neither of which carries an advisoryWritten up in
SECURITY.mdrather than left for a reader to guess.Also in this PR
LICENSE(MIT) — this was the only one of the four library/portfolio repos without one, so a public repo linked from the portfolio read as all-rights-reserved. Same text and holder as grounded / promptproof / idempotency-kit. Also set"license": "MIT"inpackage.json.SECURITY.md— reporting channel plus the residue above.Gate — unchanged and green
type-checklinttest:unitTwo honest notes:
eslintexits 0, CI stays green) on the pre-existinglocation.hrefnavigation in the dashboard error boundary. Left alone deliberately: a hard reload there is defensible for clearing broken client state, and changing error-recovery behaviour is not a dependency-hygiene change.format:checkfails on 17 files — pre-existing onmain, not caused by this PR, and not part of CI. Flagged, not fixed here.Playwright e2e was not run: it needs a live Supabase project (the standing LIB-11 blocker).