build: resolve npm audit advisories - #7
antobinary wants to merge 1 commit into
Conversation
Run npm audit fix, then take the two major upgrades it could not apply on its own: copy-webpack-plugin 12 -> 14 and webpack-dev-server 4 -> 6. Between them these clear the shell-quote and websocket-driver criticals and the serialize-javascript, sockjs and uuid advisories. Everything changed here is build tooling; none of it ships in the bundle. webpack-dev-server 6 was verified beyond a successful build by starting the dev server and confirming the custom devServer.app route for /manifest.json still answers 200. Pin watch back to ^0.13.0, the version the other repos already use. Its 1.x line pulls exec-sh and a prototype-pollution advisory in merge, and npm's own resolution for those advisories is 0.13.0. It only backs the lint:watch helper script.
imdt-claudiop
left a comment
There was a problem hiding this comment.
Requesting one change before this merges.
The webpack-dev-server 4 to 6 upgrade needs the matching webpack.config.js migration that went into bigbluebutton/bbb-plugin-picture-in-picture#45. onBeforeSetupMiddleware was removed in webpack-dev-server 5, so on 6.0.0 the dev server refuses to start:
[webpack-cli] Invalid options object. Dev Server has been initialized using an options object that does not match the API schema.
- options has an unknown property 'onBeforeSetupMiddleware'. These properties are valid:
object { allowedHosts?, bonjour?, client?, compress?, devMiddleware?, headers?, historyApiFallback?, host?, hot?, ipc?, liveReload?, onListening?, open?, port?, proxy?, server?, app?, setupExitSignals?, setupMiddlewares?, static?, watchFiles?, webSocketServer? }
Reproduced on Node 24.9.0: npm start exits with code 2 on this branch, while the same command on the base branch (webpack-dev-server 4.15.2) starts and stays up. Only the dev server path is affected, so CI stays green and npm run build-bundle is unaffected, which is why this is easy to miss.
The fix is the one already applied in the reference PR:
setupMiddlewares: (middlewares, devServer) => {
if (!devServer) {
throw new Error('webpack-dev-server is not defined');
}
// ... existing routes ...
return middlewares;
},Everything else checks out: npm audit goes from 38 vulnerabilities (21 high, 2 critical) on the base branch to 0, npm install is clean with no lockfile drift, and npx tsc, npm run lint and npm run build-bundle (producing dist/BbbPluginReactionStack.js) all pass.
What
Npm audit fixes
Applied in two passes:
npm audit fix— every non-breaking resolution. This alone cleared bothcriticals (
shell-quote,websocket-driver) and most highs.copy-webpack-plugin^12.0.2->^14.0.0(clearsserialize-javascript)webpack-dev-server^4.15.1->^6.0.0(clearssockjs,uuid, and thewebpack-dev-server source-disclosure advisory)
Scope
Everything changed here is build tooling. None of it ships in the bundle — the
plugin deploys a single bundled JS file, and these packages exist only to
produce it. The value is build-time supply-chain integrity rather than a runtime
exposure.
Testing
Against Node 24.20.0:
npm ci— PASSnpx tsc— PASSnpm run lint— PASSnpm run build-bundle— PASSnpm audit— 0 vulnerabilitieswebpack-dev-server6 is a major bump with breaking config changes, and asuccessful production build does not exercise the dev-server path at all. It was
verified separately by starting the dev server and confirming the custom
setupMiddlewares/devServer.app.get('/manifest.json')route still answers200 with the correct body. That API survived the major unchanged, so
npm run startstill works as before.Notes for review
The
package-lock.jsondiff is large because the whole dev dependency tree wasre-resolved.
package.jsonis the meaningful diff: two version bumps.