Skip to content

build: resolve npm audit advisories - #7

Open
antobinary wants to merge 1 commit into
node-24from
npm-audit
Open

antobinary wants to merge 1 commit into
node-24from
npm-audit

Conversation

@antobinary

Copy link
Copy Markdown
Member

What

Npm audit fixes

Applied in two passes:

  1. npm audit fix — every non-breaking resolution. This alone cleared both
    criticals (shell-quote, websocket-driver) and most highs.
  2. The two major upgrades npm could not apply on its own:
    • copy-webpack-plugin ^12.0.2 -> ^14.0.0 (clears serialize-javascript)
    • webpack-dev-server ^4.15.1 -> ^6.0.0 (clears sockjs, uuid, and the
      webpack-dev-server source-disclosure advisory)

Scope

Everything changed here is build tooling. None of it ships in the bundle — the
plugin deploys a single bundled JS file, and these packages exist only to
produce it. The value is build-time supply-chain integrity rather than a runtime
exposure.

Testing

Against Node 24.20.0:

  • npm ci — PASS
  • npx tsc — PASS
  • npm run lint — PASS
  • npm run build-bundle — PASS
  • npm audit — 0 vulnerabilities

webpack-dev-server 6 is a major bump with breaking config changes, and a
successful production build does not exercise the dev-server path at all. It was
verified separately by starting the dev server and confirming the custom
setupMiddlewares / devServer.app.get('/manifest.json') route still answers
200 with the correct body. That API survived the major unchanged, so
npm run start still works as before.

Notes for review

The package-lock.json diff is large because the whole dev dependency tree was
re-resolved. package.json is the meaningful diff: two version bumps.

Run npm audit fix, then take the two major upgrades it could not apply
on its own: copy-webpack-plugin 12 -> 14 and webpack-dev-server 4 -> 6.
Between them these clear the shell-quote and websocket-driver criticals
and the serialize-javascript, sockjs and uuid advisories.

Everything changed here is build tooling; none of it ships in the
bundle. webpack-dev-server 6 was verified beyond a successful build by
starting the dev server and confirming the custom devServer.app route
for /manifest.json still answers 200.
Pin watch back to ^0.13.0, the version the other repos already use. Its
1.x line pulls exec-sh and a prototype-pollution advisory in merge, and
npm's own resolution for those advisories is 0.13.0. It only backs the
lint:watch helper script.
@antobinary
antobinary requested a review from GuiLeme September 11, 2026 01:03

@imdt-claudiop imdt-claudiop left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting one change before this merges.

The webpack-dev-server 4 to 6 upgrade needs the matching webpack.config.js migration that went into bigbluebutton/bbb-plugin-picture-in-picture#45. onBeforeSetupMiddleware was removed in webpack-dev-server 5, so on 6.0.0 the dev server refuses to start:

[webpack-cli] Invalid options object. Dev Server has been initialized using an options object that does not match the API schema.
 - options has an unknown property 'onBeforeSetupMiddleware'. These properties are valid:
   object { allowedHosts?, bonjour?, client?, compress?, devMiddleware?, headers?, historyApiFallback?, host?, hot?, ipc?, liveReload?, onListening?, open?, port?, proxy?, server?, app?, setupExitSignals?, setupMiddlewares?, static?, watchFiles?, webSocketServer? }

Reproduced on Node 24.9.0: npm start exits with code 2 on this branch, while the same command on the base branch (webpack-dev-server 4.15.2) starts and stays up. Only the dev server path is affected, so CI stays green and npm run build-bundle is unaffected, which is why this is easy to miss.

The fix is the one already applied in the reference PR:

setupMiddlewares: (middlewares, devServer) => {
  if (!devServer) {
    throw new Error('webpack-dev-server is not defined');
  }
  // ... existing routes ...

  return middlewares;
},

Everything else checks out: npm audit goes from 38 vulnerabilities (21 high, 2 critical) on the base branch to 0, npm install is clean with no lockfile drift, and npx tsc, npm run lint and npm run build-bundle (producing dist/BbbPluginReactionStack.js) all pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants